Export limit exceeded: 375803 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (375803 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-78261 | 2 Realtyna, Wordpress | 2 Realtyna Organic Idx Plugin, Wordpress | 2026-08-27 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions. | ||||
| CVE-2026-32550 | 2026-08-27 | 8.5 High | ||
| Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions. | ||||
| CVE-2026-68569 | 1 Apache | 1 Tomcat | 2026-08-27 | 8.1 High |
| Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue. | ||||
| CVE-2026-79938 | 2026-08-27 | 7.6 High | ||
| Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | ||||
| CVE-2026-67275 | 2026-08-27 | 5.3 Medium | ||
| Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Cache poisoning. | ||||
| CVE-2026-78267 | 2 Cozmoslabs, Wordpress | 2 Translatepress, Wordpress | 2026-08-27 | 9.8 Critical |
| Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions. | ||||
| CVE-2026-78262 | 2 Wedevs, Wordpress | 2 Wp Project Manager, Wordpress | 2026-08-27 | 9.8 Critical |
| Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions. | ||||
| CVE-2026-15973 | 1 Limesurvey | 1 Limesurvey | 2026-08-27 | N/A |
| LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries administration page. An authenticated user with the global settings:read permission can create a survey menu entry containing attacker-controlled data. The value is stored in the surveymenu_entries.data field and later inserted into a single-quoted HTML title attribute without context-appropriate encoding. This issue affects LimeSurvey: 7.0.5. | ||||
| CVE-2026-69550 | 1 Microsoft | 2 Windows App, Windows App For Mac | 2026-08-27 | 6.5 Medium |
| Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-32559 | 2026-08-27 | 9.9 Critical | ||
| Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions. | ||||
| CVE-2026-45404 | 1 Opentelemetry | 1 Opentelemetry-go | 2026-08-27 | N/A |
| OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not safe for concurrent read/write access, concurrent SetBaggageItem and correlation.MapFromContext calls on the same hooked bridgeSpan can trigger a fatal runtime error—such as concurrent map read and map write or concurrent map iteration and map write—terminating the process and causing denial of service. This issue is fixed in version 1.45.0. | ||||
| CVE-2026-77573 | 2026-08-27 | 3.5 Low | ||
| Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository URLs can perform server-side request forgery against internal services through DNS rebinding during VCS operations. Weblate validates the hostname's first DNS resolution, but the external VCS clients that later connect perform a separate DNS lookup, so an attacker-controlled hostname that initially resolves to a public address can be re-pointed to an internal or private address before the connection is made. By triggering a clone, fetch, push, or similar remote operation, the attacker can cause Weblate to reach internal VCS-compatible services and potentially expose private repository contents. Installations that permit untrusted repository hostnames while using VCS_RESTRICT_PRIVATE=True are affected. This issue is fixed in version 2026.8. | ||||
| CVE-2026-47894 | 1 Spring | 1 Spring Cloud Config | 2026-08-27 | 4.9 Medium |
| Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier | ||||
| CVE-2026-77018 | 2026-08-27 | 8.8 High | ||
| The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory, allowing users with a role as low as subscriber to upload arbitrary files and achieve remote code execution. | ||||
| CVE-2026-59270 | 1 Spring | 1 Spring Security | 2026-08-27 | 9.4 Critical |
| Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25 | ||||
| CVE-2026-13416 | 2026-08-27 | 3.5 Low | ||
| The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to inject arbitrary web scripts that execute when a visitor views the page. | ||||
| CVE-2026-19454 | 2 Jetbackup, Wordpress | 2 Jetbackup, Wordpress | 2026-08-27 | 4.4 Medium |
| The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network, including every site's data and the shared webroot. | ||||
| CVE-2026-76549 | 2 Updraftplus, Wordpress | 2 Updraftplus, Wordpress | 2026-08-27 | 5.9 Medium |
| The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier state, via a crafted link. | ||||
| CVE-2026-78137 | 2026-08-27 | 7.5 High | ||
| The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout total when the BOGO offer feature is enabled. | ||||
| CVE-2026-78138 | 2026-08-27 | 4.3 Medium | ||
| The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sales-campaign's configuration for an arbitrary post ID, allowing any authenticated user (Subscriber and above) to read the Finale Lite WordPress plugin before 2.21.0's campaign configuration and scheduling data. | ||||