Vulnerabilities

All vulnerabilities

The full catalogue, newest first. Filter, sort and page through it. Searching for a specific product is still done from the search page.

Reset

Quick views: Newest Actively exploited Critical Most likely exploited

121 577 vulnerabilities · page 1 of 40

Vulnerabilities matching the filters
CVE Title Severity EPSS Published
CVE-2026-19802 Checkout Custom Fields Builder for WooCommerce <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+… Medium 4.3 Not available 2026-09-09
CVE-2026-86804 A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the funct… Medium 5.3 Not available 2026-09-08
CVE-2026-86716 A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments o… Medium 5.5 Not available 2026-09-08
CVE-2026-86675 A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown part o… Medium 6.3 Not available 2026-09-08
CVE-2026-86674 A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02… Medium 6.3 Not available 2026-09-08
CVE-2026-82537 Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability that allows attackers to execute denied… High 8.8 Not available 2026-09-08
CVE-2026-82536 Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that… High 8.8 Not available 2026-09-08
CVE-2026-82004 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Comm… Critical 10.0 Not available 2026-09-08
CVE-2026-77774 Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security featur… High 8.6 Not available 2026-09-08
CVE-2026-77111 Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security featur… High 8.7 Not available 2026-09-08
CVE-2026-77110 Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal… High 7.6 Not available 2026-09-08
CVE-2026-77108 Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalat… High 7.5 Not available 2026-09-08
CVE-2026-76202 Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalat… High 8.2 Not available 2026-09-08
CVE-2026-77109 Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalat… High 8.6 Not available 2026-09-08
CVE-2026-76201 Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an at… Critical 9.3 Not available 2026-09-08
CVE-2026-76200 Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an at… Critical 9.3 Not available 2026-09-08
CVE-2026-69646 Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to per… High 8.3 Not available 2026-09-08
CVE-2026-69642 Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business al… Medium 6.5 Not available 2026-09-08
CVE-2026-66308 Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. Medium 6.5 Not available 2026-09-08
CVE-2026-66307 Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service … High 7.5 Not available 2026-09-08
CVE-2026-66305 Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing ove… High 7.1 Not available 2026-09-08
CVE-2026-66306 Generation of error message containing sensitive information in Skype for Business allows an unauthorized att… Medium 6.5 Not available 2026-09-08
CVE-2026-66304 Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose informat… High 7.5 Not available 2026-09-08
CVE-2026-66303 Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. Medium 6.5 Not available 2026-09-08
CVE-2026-66302 External control of file name or path in Skype for Business allows an unauthorized attacker to execute code o… Critical 9.8 Not available 2026-09-08
CVE-2026-63523 Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business al… Medium 6.5 Not available 2026-09-08
CVE-2026-58941 In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validati… High 7.8 Not available 2026-09-08
CVE-2026-58874 In multiple functions of SmsController.java, there is a possible escalation of privilege due to a missing per… High 7.8 Not available 2026-09-08
CVE-2026-58848 In multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition.… High 7.0 Not available 2026-09-08
CVE-2026-58846 In kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check. This co… High 7.8 Not available 2026-09-08
CVE-2026-58839 In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This co… High 7.8 Not available 2026-09-08
CVE-2026-58823 In stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds… High 7.8 Not available 2026-09-08
CVE-2026-58822 In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This co… Critical 9.8 Not available 2026-09-08
CVE-2026-55294 In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap buffer ov… High 7.8 Not available 2026-09-08
CVE-2026-55285 In openLogicalChannel of multiple files, there is a possible out-of-bounds write due to a missing bounds chec… High 7.8 Not available 2026-09-08
CVE-2026-55277 In checkUiccListenConfigNeeded of RoutingManager.cpp, there is a possible out of bounds write due to a missin… High 8.0 Not available 2026-09-08
CVE-2026-55273 In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input … High 7.8 Not available 2026-09-08
CVE-2026-49932 In parseParts of PduParser.java, there is a possible out of bounds read due to a heap buffer overflow. This c… High 7.8 Not available 2026-09-08
CVE-2026-49927 In multiple locations, there is a possible out of bounds write due to an integer overflow. This could lead to… High 7.8 Not available 2026-09-08
CVE-2026-49921 In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead… Critical 9.8 Not available 2026-09-08

A dash under EPSS means the score has not been published yet. EPSS is calculated after a vulnerability is registered, so the very newest entries normally lack it for a day or two.

Paging stops here. Narrow the filters to reach older entries: browsing thousands of pages is slower than filtering, and less useful.