Search
Search Results (370627 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-32473 | 2026-08-18 | 7.2 High | ||
| Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions. | ||||
| CVE-2026-32472 | 2026-08-18 | 7.5 High | ||
| Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions. | ||||
| CVE-2026-32470 | 2026-08-18 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | ||||
| CVE-2026-32467 | 2026-08-18 | 6 Medium | ||
| Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. | ||||
| CVE-2026-32466 | 2026-08-18 | 8.5 High | ||
| Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. | ||||
| CVE-2026-32464 | 2026-08-18 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. | ||||
| CVE-2026-32444 | 2026-08-18 | 9.9 Critical | ||
| Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. | ||||
| CVE-2026-32333 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions. | ||||
| CVE-2026-28570 | 2026-08-18 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions. | ||||
| CVE-2026-28568 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. | ||||
| CVE-2026-28567 | 2026-08-18 | 7.5 High | ||
| Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions. | ||||
| CVE-2026-28192 | 2026-08-18 | 9.6 Critical | ||
| Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions. | ||||
| CVE-2026-60112 | 2 Nasa, Nasa-ammos | 2 Ait Gui, Ait-gui | 2026-08-18 | 9.8 Critical |
| AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward arbitrary commands directly to the AIT command bus without any authentication gate between session creation and command dispatch. | ||||
| CVE-2026-74961 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. | ||||
| CVE-2026-74970 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. | ||||
| CVE-2026-74978 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. | ||||
| CVE-2026-74979 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. | ||||
| CVE-2026-74981 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. | ||||
| CVE-2026-74985 | 2026-08-18 | N/A | ||
| Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. | ||||
| CVE-2026-74950 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. | ||||