CVE search

401,023 results
CVE-2026-103338HIGHWordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - SQL Injection vulnerabilityEPSS 0.2%CVE-2026-103067HIGHWordPress Memberful - Membership Plugin plugin <= 1.81.0 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.1%CVE-2026-103754MEDIUMAnsible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows file write outside the target directoryEPSS 0.3%CVE-2026-103336MEDIUMWordPress WP Ultimate CSV Importer plugin <= 9.1 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2026-103680LOWTnef: heap buffer overflow in find_free_number() via numbered-backup suffix generationEPSS 0.3%CVE-2026-103679MEDIUMTnef: use-after-free and double-free in get_body_files() via multi-value body extractionEPSS 0.3%CVE-2026-103678MEDIUMTnef: heap out-of-bounds read in get_rtf_data_from_buf() via uncompressed rtf mapi valueEPSS 0.2%CVE-2026-103858MEDIUMMISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to DiscussionsEPSS 0.2%CVE-2026-94276MEDIUMApache APISIX: Openid-connect introspection validation issueEPSS 0.5%CVE-2026-94269MEDIUMApache APISIX: Servlet-style normalization creates a route/upstream authorization mismatchEPSS 0.4%CVE-2026-94250HIGHApache APISIX: Batch response aggregation can exhaust worker memoryEPSS 0.3%CVE-2026-94220LOWApache APISIX: session fixation issue in feishu-auth and dingtalk-auth pluginEPSS 0.2%CVE-2026-94212MEDIUMApache APISIX: unauthenticated impersonation issue in saml-authEPSS 0.3%CVE-2026-82806MEDIUMApache APISIX: cross-request permission pollution via static permission list mutationEPSS 0.4%CVE-2026-78242MEDIUMApache APISIX: data-mask may fail to redact request headers in logger outputEPSS 0.2%CVE-2026-88789HIGHApache Camel Quarkus: Camel Quarkus: Forced Xalan TransformerFactory drops upstream external-DTD/stylesheet hardeningEPSS 0.5%CVE-2026-103353MEDIUMWordPress FluentForm plugin <= 6.2.14 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-103758HIGHObot 0.21.1 through 0.24.1 Authorization Bypass via /mcp-connect-composite/ RouteEPSS 0.2%CVE-2026-103757HIGHBudibase before 3.41.0 SSRF via uploadUrl in AI Table GenerationEPSS 0.3%CVE-2026-103292HIGHGhost 0.5.3 before 6.50.0 Cross-Site Scripting via ghost_headEPSS 0.2%