IM
IronMonkey Threat Research

CVE Dashboard

Explore and analyze Common Vulnerabilities and Exposures

CVE DATABASE
|
Total CVEs 349,446
|
Page 1 of 34945
|
Showing 10 per page

CVE Listing

349446 results
Loading...
CVE-2026-3182 MEDIUM 2026-07-21 · Received
Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.
CVE-2026-16266 MEDIUM 2026-07-21 · Received
Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype chain by supplying a cr...
CVE-2026-15927 MEDIUM 2026-07-21 · Received
A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, u...
CVE-2026-15812 MEDIUM 2026-07-21 · Received
A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting n...
CVE-2026-15811 MEDIUM 2026-07-21 · Received
A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to...
CVE-2026-15782 MEDIUM 2026-07-21 · Received
The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data...
CVE-2026-13439 CRITICAL 2026-07-21 · Received
The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password re...
CVE-2023-37507 MEDIUM 2026-07-21 · Received
HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.
CVE-2026-15156 MEDIUM 2026-07-21 · Received
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions ...
CVE-2023-37508 LOW 2026-07-21 · Received
HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present.