Export limit exceeded: 370709 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (370709 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-73062 1 Scriban 1 Scriban 2026-08-18 7.5 High
Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multiplier in a template to force multi-gigabyte memory allocations, causing resource exhaustion and availability degradation.
CVE-2026-74955 1 Mozilla 1 Firefox 2026-08-18 8.8 High
Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-73057 1 Stoatchat 1 Stoatchat 2026-08-18 7.5 High
stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger concurrent requests to exhaust available memory across proxy replicas.
CVE-2026-19932 1 Defaultfuction 1 Notice-system-managent 2026-08-18 6.3 Medium
A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects the function GroovyShell.evaluate of the file /execute of the component NoticeController. The manipulation results in code injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project confirms, that "it’s being processed".
CVE-2026-74015 2026-08-18 9.3 Critical
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
CVE-2026-74009 2026-08-18 5.3 Medium
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.
CVE-2026-74006 2026-08-18 4.3 Medium
Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
CVE-2026-73995 2026-08-18 5.4 Medium
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
CVE-2026-73404 2026-08-18 6.5 Medium
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
CVE-2026-73398 2026-08-18 6.5 Medium
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
CVE-2026-73396 2026-08-18 7.1 High
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
CVE-2026-73392 2026-08-18 9.3 Critical
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
CVE-2026-73379 2026-08-18 6.5 Medium
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
CVE-2026-73377 2026-08-18 7.5 High
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
CVE-2026-73365 2026-08-18 9.3 Critical
Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.
CVE-2026-73352 2026-08-18 6.5 Medium
Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.
CVE-2026-74963 1 Mozilla 1 Firefox 2026-08-18 N/A
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74964 1 Mozilla 1 Firefox 2026-08-18 N/A
Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74967 1 Mozilla 1 Firefox 2026-08-18 N/A
Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74969 1 Mozilla 1 Firefox 2026-08-18 N/A
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.