IM
IronMonkey Threat Research

CVE Dashboard

Explore and analyze Common Vulnerabilities and Exposures

CVE DATABASE
|
Total CVEs 366,691
|
Page 1 of 36670
|
Showing 10 per page

CVE Listing

366691 results
Loading...
CVE-2026-84175 MEDIUM 2026-09-02 · Received
In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs supplied by API users in the definition field of a Thing or Feature, without va...
CVE-2026-53683 MEDIUM 2026-09-02 · Received
reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No vali...
CVE-2026-75528 HIGH 2026-09-02 · Received
The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author URL / Link Log in all versions up to, and including, 2.4.13 due to insufficient input sanit...
CVE-2026-14828 HIGH 2026-09-02 · Received
Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerabili...
CVE-2025-7963 MEDIUM 2026-09-02 · Received
The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer() function in all versions up to, and including, 1.2.2 due to insufficie...
CVE-2026-82883 HIGH 2026-09-02 · Received
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS. This issue affects Login With Ajax: from n/a through...
CVE-2026-3850 MEDIUM 2026-09-02 · Received
The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_contact_form` shortcode in all versions up to, and including, 4.27.6. This is d...
CVE-2026-82183 N/A 2026-09-02 · Received
The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary n...
CVE-2026-82182 N/A 2026-09-02 · Received
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied list of identifiers before using it in a SQL query, allowing administrators to perform SQL i...
CVE-2026-81807 N/A 2026-09-02 · Received
The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and ru...