Export limit exceeded: 374976 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (374976 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-52608 | 1 Reportico | 1 Reportico | 2026-08-24 | 9.8 Critical |
| An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution. | ||||
| CVE-2021-43716 | 1 Epson | 1 Easymp Network Updater | 2026-08-24 | 9.8 Critical |
| Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB. | ||||
| CVE-2026-66636 | 2 Marcin, Wordpress | 2 Wise Chat, Wordpress | 2026-08-24 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions. | ||||
| CVE-2026-66641 | 2 Deepen Bajracharya, Wordpress | 2 Video Conferencing With Zoom, Wordpress | 2026-08-24 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions. | ||||
| CVE-2026-66667 | 2 Wordpress, Wpdeveloper | 2 Wordpress, Templately | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions. | ||||
| CVE-2026-73345 | 2 Saad Iqbal, Wordpress | 2 License Manager For Woocommerce, Wordpress | 2026-08-24 | 7.1 High |
| Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions. | ||||
| CVE-2026-73365 | 2 Crocoblock. Jetimpex Inc., Wordpress | 2 Jetappointment, Wordpress | 2026-08-24 | 9.3 Critical |
| Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. | ||||
| CVE-2026-73380 | 2 Supsysticcom, Wordpress | 2 Popup By Supsystic, Wordpress | 2026-08-24 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. | ||||
| CVE-2026-73381 | 2 Supsysticcom, Wordpress | 2 Popup By Supsystic, Wordpress | 2026-08-24 | 9.1 Critical |
| Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. | ||||
| CVE-2026-77781 | 1 Davorg-cpan | 1 Tie Hash Regex | 2026-08-24 | N/A |
| Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys. The FETCH, EXISTS and DELETE methods throw an exception when on malformed regular expressions. Each method falls back to a regex match when the key is not already stored in the hash, compiling the caller's key with a bare qr// and no eval guard. A key that is not a valid regular expression pattern, such as a single unmatched bracket, dies. An application that looks up externally supplied strings in a tied hash will die on an invalid key. | ||||
| CVE-2026-78203 | 1 Ghostmanager | 1 Ghostwriter | 2026-08-24 | 7.1 High |
| Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers to attach client-scoped templates from other clients to their own reports. Attackers can exploit sequential template primary keys to enumerate and attach foreign templates, then generate reports to disclose template contents including letterhead, boilerplate, and methodology text. | ||||
| CVE-2026-78204 | 1 Ghostmanager | 1 Ghostwriter | 2026-08-24 | 5.4 Medium |
| Ghostwriter through 7.2.6 does not apply per-object authorization on its report template lint endpoints. RoleBasedAccessControlMixin.test_func returns only request.user.is_active unless a view overrides it, and neither the endpoint that lints a report template nor the endpoint that returns stored lint results provides an override, so each resolves a ReportTemplate from a caller-supplied primary key with no ownership or client-scope check. Any authenticated account can therefore lint an arbitrary template, which overwrites that template's stored lint result, and can read the returned findings, which enumerate the template's variable names and template-engine errors and so disclose its structure. This is distinct from the template swap path: that endpoint authorizes the report but omits the per-template check, whereas these endpoints omit authorization entirely and remain unfixed. | ||||
| CVE-2026-78209 | 2 Exceljs, Exceljs Project | 2 Exceljs, Exceljs | 2026-08-24 | 8.2 High |
| exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened in a spreadsheet application, potentially exfiltrating data or performing other malicious actions. | ||||
| CVE-2026-78180 | 2 Alibaba-fusion, Next | 2 Next, Next | 2026-08-24 | 7.3 High |
| A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly controlled modification of object prototype attributes. The attack may be initiated remotely. The reported GitHub issue was closed automatically due to inactivity. | ||||
| CVE-2026-78211 | 1 4mosan Security Technology | 1 4mosan Gcb Doctor | 2026-08-24 | 9.8 Critical |
| 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter, thereby executing arbitrary system commands on the server. | ||||
| CVE-2026-78212 | 1 4mosan Security Technology | 1 4mosan Management Center | 2026-08-24 | 7.5 High |
| 4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Relative Path Traversal flaw to download arbitrary system files. | ||||
| CVE-2026-59561 | 1 Sakura-editor | 1 Sakura | 2026-08-24 | N/A |
| Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal". | ||||
| CVE-2026-78200 | 1 Itsourcecode | 1 Library Management System | 2026-08-24 | 6.3 Medium |
| A flaw has been found in itsourcecode Library Management System 1.0. The affected element is an unknown function of the file editbooks.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | ||||
| CVE-2026-8173 | 1 Murrelektronik | 24 6 Tx M Ge + 4 Power M12 Ip67, Xelity-16tx-m-ge, Xelity-16tx-m-ge-pn and 21 more | 2026-08-24 | 5.3 Medium |
| The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools. | ||||
| CVE-2026-78251 | 1 Dji | 15 Air 3, Air 3s, Dji Avata 2 and 12 more | 2026-08-24 | N/A |
| DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in **/blackbox/upgrade/**, as well as overwrite existing files in that directory. An attacker with access to the drone's internal network or USB RNDIS interface can exhaust the available storage, preventing the aircraft from writing flight records, logs, and telemetry and potentially preventing subsequent firmware updates. Uploaded files persist across reboot and factory reset. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor. | ||||