CVE search
398,693 resultsCVE-2026-82300MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-82294MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.4%CVE-2026-78582MEDIUMMissing Authorization in Kibana Leading to Unauthorized Deletion of DataEPSS 0.2%CVE-2026-72662MEDIUMAuthorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of DataEPSS 0.2%CVE-2026-72668HIGHUnintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege EscalationEPSS 0.2%CVE-2026-82901CRITICALUltra Addons for Contact Form 7 <= 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Form FieldEPSS 1.1%CVE-2026-77203HIGHGroups <= 4.6.0 - Authenticated (Subscriber+) Privilege Escalation via 'groups_join' ShortcodeEPSS 0.3%CVE-2026-85984CRITICALminiOrange OTP Login, Verification and SMS Notifications <= 5.5.5 - Unauthenticated Authentication Bypass via 'mo_wp_login_intent' ParameterEPSS 0.7%CVE-2026-97161CRITICALJoomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29EPSS 0.4%CVE-2026-97163CRITICALJoomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29EPSS 0.4%CVE-2026-97162HIGHJoomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29EPSS 0.3%CVE-2026-97160CRITICALJoomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29EPSS 1.3%CVE-2026-94131HIGHJoomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0EPSS 0.3%CVE-2026-94132CRITICALJoomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0EPSS 0.6%CVE-2026-94130CRITICALJoomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3EPSS 0.4%CVE-2026-100626MEDIUMcapgo through 12.128.2 IDOR via PUT /app icon endpointEPSS 0.2%CVE-2026-100720CRITICALFroxlor before 2.3.12 Stored XSS via SSL certificate issuerEPSS 0.2%CVE-2026-100719HIGHFroxlor before 2.3.12 Credential Disclosure via DirProtections APIEPSS 0.2%CVE-2026-100718HIGHFroxlor before 2.3.12 Authentication Bypass via EmailSender.addEPSS 0.2%CVE-2026-100717HIGHfroxlor before 2.3.12 CRLF Injection via validateUrl userinfoEPSS 0.3%