Total CVEs

150,798

Critical Severity

4,991

High Severity

17,614

Last 7 Days

2,022
Quick preset (or use dates below)
Clear Filters
Showing 2,001 - 2,020 of 150,798 CVEs
CVE-2026-15100 MEDIUM - 6.4

The Post Grid Gutenberg Blocks โ€“ PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnoresult' Block Attribute in all versions up to, and including, 5.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at...

Vendor: wpxpo
Product: Post Grid Gutenberg Blocks โ€“ PostX
Published: Jul 24, 2026
Source: NVD
CVE-2026-13464 MEDIUM - 5.3

The Kirki โ€“ Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0.14 via the 'context' parameter due to missing validation on a user controlled key. This makes it possible for...

Vendor: themeum
Product: Kirki โ€“ Freeform Page Builder, Website Builder & Customizer
Published: Jul 24, 2026
Source: NVD
CVE-2026-12736 HIGH - 8.0

The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::save_option() REST route (POST /wp-json/wpify-woo/v1/option) passing the request-supplied 'option' and 'data' parameters directly to ...

Vendor: wpify
Product: WPify Woo โ€“ Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce
Published: Jul 24, 2026
Source: NVD
CVE-2026-11922 MEDIUM - 6.5

A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST /api/v1/login` and self password-change endpoints by rotating the `X-Forwarded-For` header. The rate limiter keys requests by `request.client.host`, which is derived from the `X-F...

Vendor: zenml-io
Product: zenml-io/zenml
Published: Jul 24, 2026
Source: NVD
CVE-2026-11354 MEDIUM - 5.3

The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect th...

Vendor: xnau
Product: Participants Database
Published: Jul 24, 2026
Source: NVD
CVE-2025-9205 MEDIUM - 6.4

The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.0. This is due to insufficient input sanitization and output escaping on user supplied attributes within the map options. This makes it possible for authenticated attackers, with c...

Published: Jul 24, 2026
Source: NVD
CVE-2026-62825 CRITICAL - 10.0

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

Published: Jul 24, 2026
Source: NVD
CVE-2026-58275 CRITICAL - 10.0

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

Published: Jul 24, 2026
Source: NVD
CVE-2026-56191 CRITICAL - 10.0

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

Vendor: microsoft
Product: exchange_online
Published: Jul 24, 2026
Source: NVD
CVE-2026-56167 HIGH - 8.5

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_ai_search
Published: Jul 24, 2026
Source: NVD
CVE-2026-56165 CRITICAL - 9.8

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: account
Published: Jul 24, 2026
Source: NVD
CVE-2026-56160 CRITICAL - 9.1

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

Published: Jul 24, 2026
Source: NVD
CVE-2026-54120 CRITICAL - 9.9

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

Published: Jul 24, 2026
Source: NVD
CVE-2026-50517 CRITICAL - 9.9

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

Vendor: microsoft
Product: 365_copilot
Published: Jul 24, 2026
Source: NVD
CVE-2026-49159 MEDIUM - 6.5

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

Vendor: microsoft
Product: graph
Published: Jul 24, 2026
Source: NVD
CVE-2026-35425 HIGH - 8.0

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

Published: Jul 24, 2026
Source: NVD
CVE-2026-50044 MEDIUM - 6.8

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash or a pass-the-hash attack.

Vendor: Pronetiqs
Product: Panduit Intravue
Published: Jul 23, 2026
Source: NVD
CVE-2026-44955 MEDIUM - 5.3

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discovery by unauthenticated users.

Vendor: Pronetiqs
Product: Panduit Intravue
Published: Jul 23, 2026
Source: NVD
CVE-2026-42933 CRITICAL - 10.0

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.

Vendor: Pronetiqs
Product: Panduit Intravue
Published: Jul 23, 2026
Source: NVD
CVE-2026-40430 HIGH - 7.5

Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.

Vendor: Pronetiqs
Product: Panduit Intravue
Published: Jul 23, 2026
Source: NVD