All vulnerabilities
The full catalogue, newest first. Filter, sort and page through it. Searching for a specific product is still done from the search page.
Quick views: Newest Actively exploited Critical Most likely exploited
121 577 vulnerabilities · page 1 of 40
| CVE | Title | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-19802 | Checkout Custom Fields Builder for WooCommerce <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+… | Medium 4.3 | Not available | 2026-09-09 |
| CVE-2026-86804 | A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the funct… | Medium 5.3 | Not available | 2026-09-08 |
| CVE-2026-86716 | A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments o… | Medium 5.5 | Not available | 2026-09-08 |
| CVE-2026-86675 | A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown part o… | Medium 6.3 | Not available | 2026-09-08 |
| CVE-2026-86674 | A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02… | Medium 6.3 | Not available | 2026-09-08 |
| CVE-2026-82537 | Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability that allows attackers to execute denied… | High 8.8 | Not available | 2026-09-08 |
| CVE-2026-82536 | Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that… | High 8.8 | Not available | 2026-09-08 |
| CVE-2026-82004 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Comm… | Critical 10.0 | Not available | 2026-09-08 |
| CVE-2026-77774 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security featur… | High 8.6 | Not available | 2026-09-08 |
| CVE-2026-77111 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security featur… | High 8.7 | Not available | 2026-09-08 |
| CVE-2026-77110 | Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal… | High 7.6 | Not available | 2026-09-08 |
| CVE-2026-77108 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalat… | High 7.5 | Not available | 2026-09-08 |
| CVE-2026-76202 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalat… | High 8.2 | Not available | 2026-09-08 |
| CVE-2026-77109 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalat… | High 8.6 | Not available | 2026-09-08 |
| CVE-2026-76201 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an at… | Critical 9.3 | Not available | 2026-09-08 |
| CVE-2026-76200 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an at… | Critical 9.3 | Not available | 2026-09-08 |
| CVE-2026-69646 | Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to per… | High 8.3 | Not available | 2026-09-08 |
| CVE-2026-69642 | Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business al… | Medium 6.5 | Not available | 2026-09-08 |
| CVE-2026-66308 | Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. | Medium 6.5 | Not available | 2026-09-08 |
| CVE-2026-66307 | Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service … | High 7.5 | Not available | 2026-09-08 |
| CVE-2026-66305 | Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing ove… | High 7.1 | Not available | 2026-09-08 |
| CVE-2026-66306 | Generation of error message containing sensitive information in Skype for Business allows an unauthorized att… | Medium 6.5 | Not available | 2026-09-08 |
| CVE-2026-66304 | Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose informat… | High 7.5 | Not available | 2026-09-08 |
| CVE-2026-66303 | Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. | Medium 6.5 | Not available | 2026-09-08 |
| CVE-2026-66302 | External control of file name or path in Skype for Business allows an unauthorized attacker to execute code o… | Critical 9.8 | Not available | 2026-09-08 |
| CVE-2026-63523 | Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business al… | Medium 6.5 | Not available | 2026-09-08 |
| CVE-2026-58941 | In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validati… | High 7.8 | Not available | 2026-09-08 |
| CVE-2026-58874 | In multiple functions of SmsController.java, there is a possible escalation of privilege due to a missing per… | High 7.8 | Not available | 2026-09-08 |
| CVE-2026-58848 | In multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition.… | High 7.0 | Not available | 2026-09-08 |
| CVE-2026-58846 | In kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check. This co… | High 7.8 | Not available | 2026-09-08 |
| CVE-2026-58839 | In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This co… | High 7.8 | Not available | 2026-09-08 |
| CVE-2026-58823 | In stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds… | High 7.8 | Not available | 2026-09-08 |
| CVE-2026-58822 | In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This co… | Critical 9.8 | Not available | 2026-09-08 |
| CVE-2026-55294 | In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap buffer ov… | High 7.8 | Not available | 2026-09-08 |
| CVE-2026-55285 | In openLogicalChannel of multiple files, there is a possible out-of-bounds write due to a missing bounds chec… | High 7.8 | Not available | 2026-09-08 |
| CVE-2026-55277 | In checkUiccListenConfigNeeded of RoutingManager.cpp, there is a possible out of bounds write due to a missin… | High 8.0 | Not available | 2026-09-08 |
| CVE-2026-55273 | In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input … | High 7.8 | Not available | 2026-09-08 |
| CVE-2026-49932 | In parseParts of PduParser.java, there is a possible out of bounds read due to a heap buffer overflow. This c… | High 7.8 | Not available | 2026-09-08 |
| CVE-2026-49927 | In multiple locations, there is a possible out of bounds write due to an integer overflow. This could lead to… | High 7.8 | Not available | 2026-09-08 |
| CVE-2026-49921 | In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead… | Critical 9.8 | Not available | 2026-09-08 |
A dash under EPSS means the score has not been published yet. EPSS is calculated after a vulnerability is registered, so the very newest entries normally lack it for a day or two.
Paging stops here. Narrow the filters to reach older entries: browsing thousands of pages is slower than filtering, and less useful.