Export limit exceeded: 86887 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (86887 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66706 | 2 Markjaquith, Wordpress | 2 Subscribe To Comments, Wordpress | 2026-08-06 | 5.9 Medium |
| Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions. | ||||
| CVE-2026-66663 | 2 Passionate Programmer Peter, Wordpress | 2 Wp Data Access, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. | ||||
| CVE-2026-66690 | 2 Nexcess, Wordpress | 2 Givewp, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions. | ||||
| CVE-2026-66711 | 2026-08-06 | 7.1 High | ||
| Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions. | ||||
| CVE-2026-18501 | 2 Stiofansisland, Wordpress | 2 Userswp – Front-end Login Form, User Registration, User Profile & Members Directory Plugin For Wp, Wordpress | 2026-08-06 | 6.4 Medium |
| The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Badge Widget Variable Substitution in all versions up to, and including, 1.2.69 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-18325 | 2 Wordpress, Wpmudev | 2 Wordpress, Forminator Forms – Contact Form, Payment Form & Custom Form Builder | 2026-08-06 | 7.2 High |
| The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged Upload Record via Select Field in all versions up to, and including, 1.56.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit is possible because Forminator_Core::sanitize_array() skips all filtering for keys prefixed with 'select-', and set_field_data() treats a submitted 'return' member as a trusted internal flag — allowing an unauthenticated attacker to forge and persist a complete upload field record with an arbitrary file_url value without any sanitization or validation. | ||||
| CVE-2026-56211 | 2 Aomedia, Redhat | 7 Libaom, Ai Inference Server, Enterprise Linux and 4 more | 2026-08-06 | 7.1 High |
| A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In fork-based video processing services, an attacker can use this to hijack the cyclic refresh map pointer, brute-force the process base address via a crash oracle, and redirect control flow to achieve arbitrary command execution. Exploitation requires the target service to use libaom with SVC encoding enabled and accept attacker-supplied video frames. | ||||
| CVE-2026-56209 | 2 Aomedia, Redhat | 7 Libaom, Ai Inference Server, Enterprise Linux and 4 more | 2026-08-06 | 7.1 High |
| An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then writes approximately 1,200 bytes at the attacker-controlled address. This is fully deterministic and does not require a separate information leak. An attacker who can supply frames to a network-facing libaom encoder with SVC enabled could exploit this for denial of service or potential code execution. | ||||
| CVE-2026-66440 | 2 Wordpress, Xplodedthemes | 2 Wordpress, Wpide - File Manager & Code Editor | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions. | ||||
| CVE-2026-19020 | 1 Itsourcecode | 1 Hospital Management System | 2026-08-06 | 6.3 Medium |
| A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /servicetype.php. This manipulation of the argument editid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. | ||||
| CVE-2026-19036 | 1 Shibby | 1 Tomato | 2026-08-06 | 7.2 High |
| A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This project is superseded by FreshTomato. | ||||
| CVE-2026-19041 | 1 Missionsquad | 1 Mcp-api | 2026-08-06 | 6.3 Medium |
| A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageService.installPackage of the file src/controllers/packages.ts of the component NPM Package Version Handler. The manipulation leads to command injection. It is possible to initiate the attack remotely. Upgrading to version 1.11.9 is sufficient to resolve this issue. The identifier of the patch is a40f54d4533ba6618e1749383a245900eeb024c1. The affected component should be upgraded. | ||||
| CVE-2026-28143 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions. | ||||
| CVE-2025-63823 | 2026-08-06 | 9.8 Critical | ||
| My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values. | ||||
| CVE-2026-61961 | 2 Wordpress, Wpdeveloper | 2 Wordpress, Embedpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. | ||||
| CVE-2026-28178 | 2 Codesupplyco, Wordpress | 2 Powerkit, Wordpress | 2026-08-06 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions. | ||||
| CVE-2026-61982 | 2 Jp-secure, Wordpress | 2 Siteguard Wp Plugin, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. | ||||
| CVE-2026-65509 | 2 Wordpress, Wpdatatables | 2 Wordpress, Wpdatatables | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. | ||||
| CVE-2026-66439 | 2 Berocket, Wordpress | 2 Advanced Ajax Product Filters, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions. | ||||
| CVE-2026-65545 | 2 Jordy Meow, Wordpress | 2 Ai-engine, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions. | ||||