Total CVEs

150,882

Critical Severity

5,031

High Severity

17,660

Last 7 Days

2,100
Quick preset (or use dates below)
Clear Filters
Showing 2,081 - 2,100 of 150,882 CVEs
CVE-2026-66138 HIGH - 7.2

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.

Vendor: OpenStack
Product: Ironic Python Agent
Published: Jul 24, 2026
Source: NVD
CVE-2026-54422 MEDIUM - 5.5

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

Vendor: OpenStack
Product: Ironic Python Agent
Published: Jul 24, 2026
Source: NVD
CVE-2026-6454 MEDIUM - 6.4

The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to insufficient sanitization of the href attribute value within the FancyBox V2 PDF beforeLoad JavaScript callback generated in inc/fancybox-2.php, where t...

Published: Jul 24, 2026
Source: NVD
CVE-2026-15420 MEDIUM - 4.3

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access ...

Vendor: posimyththemes
Product: Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder
Published: Jul 24, 2026
Source: NVD
CVE-2026-15100 MEDIUM - 6.4

The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnoresult' Block Attribute in all versions up to, and including, 5.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at...

Vendor: wpxpo
Product: Post Grid Gutenberg Blocks – PostX
Published: Jul 24, 2026
Source: NVD
CVE-2026-13464 MEDIUM - 5.3

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0.14 via the 'context' parameter due to missing validation on a user controlled key. This makes it possible for...

Vendor: themeum
Product: Kirki – Freeform Page Builder, Website Builder & Customizer
Published: Jul 24, 2026
Source: NVD
CVE-2026-12736 HIGH - 8.0

The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::save_option() REST route (POST /wp-json/wpify-woo/v1/option) passing the request-supplied 'option' and 'data' parameters directly to ...

Vendor: wpify
Product: WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce
Published: Jul 24, 2026
Source: NVD
CVE-2026-11922 MEDIUM - 6.5

A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST /api/v1/login` and self password-change endpoints by rotating the `X-Forwarded-For` header. The rate limiter keys requests by `request.client.host`, which is derived from the `X-F...

Vendor: zenml-io
Product: zenml-io/zenml
Published: Jul 24, 2026
Source: NVD
CVE-2026-11354 MEDIUM - 5.3

The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect th...

Vendor: xnau
Product: Participants Database
Published: Jul 24, 2026
Source: NVD
CVE-2025-9205 MEDIUM - 6.4

The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.0. This is due to insufficient input sanitization and output escaping on user supplied attributes within the map options. This makes it possible for authenticated attackers, with c...

Published: Jul 24, 2026
Source: NVD
CVE-2026-62825 CRITICAL - 10.0

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

Published: Jul 24, 2026
Source: NVD
CVE-2026-58275 CRITICAL - 10.0

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

Published: Jul 24, 2026
Source: NVD
CVE-2026-56191 CRITICAL - 10.0

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

Vendor: microsoft
Product: exchange_online
Published: Jul 24, 2026
Source: NVD
CVE-2026-56167 HIGH - 8.5

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: azure_ai_search
Published: Jul 24, 2026
Source: NVD
CVE-2026-56165 CRITICAL - 9.8

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: account
Published: Jul 24, 2026
Source: NVD
CVE-2026-56160 CRITICAL - 9.1

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

Published: Jul 24, 2026
Source: NVD
CVE-2026-54120 CRITICAL - 9.9

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

Published: Jul 24, 2026
Source: NVD
CVE-2026-50517 CRITICAL - 9.9

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

Vendor: microsoft
Product: 365_copilot
Published: Jul 24, 2026
Source: NVD
CVE-2026-49159 MEDIUM - 6.5

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

Vendor: microsoft
Product: graph
Published: Jul 24, 2026
Source: NVD
CVE-2026-35425 HIGH - 8.0

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

Published: Jul 24, 2026
Source: NVD