Export limit exceeded: 374108 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (374108 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-28568 | 2 Mdmag, Wordpress | 2 Quill Forms, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. | ||||
| CVE-2026-28569 | 2 Sslzen, Wordpress | 2 Ssl Zen, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions. | ||||
| CVE-2026-32468 | 2 Duitku, Wordpress | 2 Duitku Payment Gateway, Wordpress | 2026-08-24 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. | ||||
| CVE-2026-32547 | 2 Wordplus, Wordpress | 2 Better Messages, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. | ||||
| CVE-2026-66635 | 2 10web, Wordpress | 2 Sliderby10web, Wordpress | 2026-08-24 | 7.4 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions. | ||||
| CVE-2026-66638 | 2 Shabti, Wordpress | 2 Frontend Admin By Dynamapps, Wordpress | 2026-08-24 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. | ||||
| CVE-2026-68568 | 2 Stylemixthemes, Wordpress | 2 Masterstudy Lms, Wordpress | 2026-08-24 | 6.3 Medium |
| Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions. | ||||
| CVE-2026-73190 | 2 Shahjada, Wordpress | 2 Wpdm Premium Packages, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions. | ||||
| CVE-2026-73378 | 2 Supsysticcom, Wordpress | 2 Contact Form By Supsystic, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions. | ||||
| CVE-2026-73379 | 2 Supsysticcom, Wordpress | 2 Contact Form By Supsystic, Wordpress | 2026-08-24 | 6.5 Medium |
| Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. | ||||
| CVE-2026-73395 | 2 Wordpress, Wpdevart | 3 Wordpress, Booking Calendar, Booking Calendar, Appointment Booking System | 2026-08-24 | 6.5 Medium |
| Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions. | ||||
| CVE-2026-50538 | 1 Libvncserver | 1 Libvncserver | 2026-08-24 | 8.8 High |
| LibVNCClient is a library for easy implementation of a VNC client. In versions 0.9.12 through 0.9.15, a malicious (or man-in-the-middle) VNC server can force a connecting `libvncclient` to write attacker-controlled data past the end of its framebuffer. This is an out-of-bounds heap write with attacker-controlled length, contents, and offset. It needs no authentication (the attacker is the server), works in a default build with default settings, and fires from a single `FramebufferUpdate` the moment the victim connects. It crashes any client unconditionally (denial of service); we also demonstrated it overwriting an application callback pointer and redirecting execution to attacker-chosen code (code execution) under the default configuration. Commit 540332be3e0acc566fa64da6f1b4680c72c724dd patches the issue. | ||||
| CVE-2026-53487 | 1 Kite | 1 Kite | 2026-08-24 | 4.3 Medium |
| Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request `/api/v1/overview` for a cluster that their roles do not permit by selecting that cluster with `x-cluster-name`. The overview route is registered before `middleware.RBACMiddleware()` and `GetOverview` only checks `len(user.Roles) > 0`, so it returns aggregate Kubernetes inventory and capacity data from unauthorized clusters. Version 0.12.3 fixes the issue. | ||||
| CVE-2026-18027 | 2 Webtoffee, Wordpress | 2 Woocommerce Pdf Invoices, Packing Slips, Delivery Notes And Shipping Labels, Wordpress | 2026-08-24 | 6.5 Medium |
| The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base64 function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The base64-encoded file contents are embedded into the cached invoice HTML and served directly to the attacker via the plugin's own Print/Download invoice endpoints, which require only a valid nonce and access key. | ||||
| CVE-2025-26237 | 1 D-link | 1 Di-7001 Mini | 2026-08-24 | N/A |
| D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can be exploited to run arbitrary commands. | ||||
| CVE-2026-78167 | 2 Efm, Iptime | 2 Iptime T16000m, T16000m | 2026-08-24 | 10 Critical |
| A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-19853 | 1 Cybertutor | 1 New Site Server | 2026-08-24 | 5.3 Medium |
| NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf of the school. | ||||
| CVE-2026-19852 | 1 Cybertutor | 1 New Site Server | 2026-08-24 | 6.1 Medium |
| NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, including malicious HTML files, thereby achieving effects similar to cross-site scripting. | ||||
| CVE-2026-10582 | 1 Gohugo | 1 Hugo | 2026-08-24 | 7.4 High |
| Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern list and then re-checks a canonicalised form of an integer, hex or octal IPv4 host, but it never resolves the hostname and never inspects the address the HTTP client actually connects to. The client constructed in resources/resource_factories/create/create.go installs no dial-time hook, so no check occurs at connection time either. A hostname that resolves to a loopback, private or cloud-metadata address therefore satisfies the policy, and the response body is embedded in the generated site. An attacker who can supply a URL through content, for example a front-matter field or a CMS field, can make the build fetch an internal endpoint and publish the response in the static output, so the build artifact itself carries the data out. | ||||
| CVE-2026-19568 | 1 Autodesk | 1 3ds Max | 2026-08-24 | 7.8 High |
| A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | ||||