Search

Search Results (377843 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-84803 2 B3log, Siyuan 2 Siyuan, Siyuan 2026-09-02 9 Critical
SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. Attackers can upload files with extensions like .xht, .ehtml, .xsl, .xbl, or .rdf that resolve to executable media types and execute JavaScript to steal API tokens and compromise workspaces.
CVE-2026-81289 2 Sonaar, Wordpress 2 Mp3 Audio Player For Music, Radio & Podcast, Wordpress 2026-09-02 7.1 High
Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions.
CVE-2026-73474 1 Drupal 1 Entity Share 2026-09-02 5.3 Medium
Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2.
CVE-2026-48521 1 Envoyproxy 1 Envoy 2026-09-02 5.9 Medium
No description is available for this CVE.
CVE-2026-50572 1 Envoyproxy 1 Envoy 2026-09-02 5.9 Medium
No description is available for this CVE.
CVE-2026-73511 1 Envoyproxy 1 Envoy 2026-09-02 5.3 Medium
No description is available for this CVE.
CVE-2026-73512 1 Envoyproxy 1 Envoy 2026-09-02 7.5 High
No description is available for this CVE.
CVE-2026-73513 1 Envoyproxy 1 Envoy 2026-09-02 7.5 High
No description is available for this CVE.
CVE-2026-73546 1 Envoyproxy 1 Envoy 2026-09-02 7.4 High
No description is available for this CVE.
CVE-2026-73547 1 Envoyproxy 1 Envoy 2026-09-02 7.5 High
No description is available for this CVE.
CVE-2026-73548 1 Envoyproxy 1 Envoy 2026-09-02 7.5 High
No description is available for this CVE.
CVE-2026-73549 1 Envoyproxy 1 Envoy 2026-09-02 5.3 Medium
No description is available for this CVE.
CVE-2026-73550 1 Envoyproxy 1 Envoy 2026-09-02 7.5 High
No description is available for this CVE.
CVE-2026-73551 1 Envoyproxy 1 Envoy 2026-09-02 5.3 Medium
No description is available for this CVE.
CVE-2026-73552 1 Envoyproxy 1 Envoy 2026-09-02 7.5 High
No description is available for this CVE.
CVE-2026-73553 1 Envoyproxy 1 Envoy 2026-09-02 7.5 High
No description is available for this CVE.
CVE-2026-18765 1 Teracity 1 E-osb 2026-09-02 9.8 Critical
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects E-OSB: before V02.26.07.08.01.
CVE-2026-84149 1 Manacle Technologies 1 Multi-tenant Erp System 2026-09-02 N/A
This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit this vulnerability by accessing the exposed .git directory and retrieving repository metadata and associated files, which could allow reconstruction of the application's source code.
CVE-2026-18808 1 Klemsan Electrical Electronics 1 Kio (klemsan Internet Objects) 2026-09-02 9.8 Critical
Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO (Klemsan Internet Objects): before v1.9.
CVE-2026-18210 1 Trtek 1 Products Store 2026-09-02 9.8 Critical
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection. This issue affects Products's Store: before 030631b2.