Export limit exceeded: 370672 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 370672 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (370672 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-73366 2026-08-18 9.8 Critical
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
CVE-2026-73362 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions.
CVE-2026-73361 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions.
CVE-2026-73359 2026-08-18 6.5 Medium
Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.
CVE-2026-73356 2026-08-18 8.2 High
Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.
CVE-2026-73355 2026-08-18 9.3 Critical
Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
CVE-2026-73351 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.
CVE-2026-73348 2026-08-18 6.5 Medium
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
CVE-2026-73345 2026-08-18 7.1 High
Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.
CVE-2026-73342 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.
CVE-2026-73339 2026-08-18 9.3 Critical
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
CVE-2026-73338 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.
CVE-2026-73181 2026-08-18 7.5 High
Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.
CVE-2026-71518 1 Typemill 1 Typemill 2026-08-18 7.5 High
Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash prefixes, double slashes, or percent-encoded sequences to pass role-based restriction checks while the filesystem resolves the request to the protected file, enabling unauthorized file download without credentials.
CVE-2026-68568 2026-08-18 6.3 Medium
Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.
CVE-2026-68517 1 Nicolargo 1 Glances 2026-08-18 6.5 Medium
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list containing the wildcard to retain cors_credentials and expose authenticated REST API data to an untrusted website visited by a previously authenticated user. This issue is fixed in 4.5.6.
CVE-2026-66792 1 Redhat 4 Acm, Multicluster Globalhub, Openshift and 1 more 2026-08-18 9.9 Critical
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources.
CVE-2026-66667 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions.
CVE-2026-66651 2026-08-18 6.5 Medium
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions.
CVE-2026-66645 2026-08-18 6.5 Medium
Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.