Export limit exceeded: 370672 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 370672 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 370672 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (370672 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-32470 2026-08-18 9.8 Critical
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
CVE-2026-32467 2026-08-18 6 Medium
Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.
CVE-2026-32464 2026-08-18 8.1 High
Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.
CVE-2026-32444 2026-08-18 9.9 Critical
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
CVE-2026-32333 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions.
CVE-2026-28570 2026-08-18 8.1 High
Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.
CVE-2026-28568 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions.
CVE-2026-28567 2026-08-18 7.5 High
Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.
CVE-2026-60112 2 Nasa, Nasa-ammos 2 Ait Gui, Ait-gui 2026-08-18 9.8 Critical
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward arbitrary commands directly to the AIT command bus without any authentication gate between session creation and command dispatch.
CVE-2026-74961 1 Mozilla 1 Firefox 2026-08-18 N/A
Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-74978 1 Mozilla 1 Firefox 2026-08-18 N/A
Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-74979 1 Mozilla 1 Firefox 2026-08-18 N/A
Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-74981 1 Mozilla 1 Firefox 2026-08-18 N/A
Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-74954 1 Mozilla 1 Firefox 2026-08-18 N/A
Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-60113 2 Nasa, Nasa-ammos 2 Ait Dsn, Ait-dsn 2026-08-18 9.8 Critical
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials. Attackers can reach the exposed SLE endpoints to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links.
CVE-2026-18751 1 Citrix 1 Workspace App 2026-08-18 N/A
External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607.
CVE-2026-75852 1 Arcadedata 1 Arcadedb 2026-08-18 9.8 Critical
ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.
CVE-2026-74934 1 Mozilla 1 Firefox 2026-08-18 N/A
Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74944 1 Mozilla 1 Firefox 2026-08-18 N/A
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
CVE-2026-74948 1 Mozilla 1 Firefox 2026-08-18 N/A
Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.