Export limit exceeded: 370710 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (370710 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-66646 2026-08-18 6.5 Medium
Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions.
CVE-2026-66640 2026-08-18 6.5 Medium
Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.
CVE-2026-66638 2026-08-18 6.5 Medium
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
CVE-2026-66635 2026-08-18 7.4 High
Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.
CVE-2026-66633 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
CVE-2026-66620 2026-08-18 7.2 High
Editor PHP Object Injection in OptionTree <= 2.7.3 versions.
CVE-2026-75774 1 Karakeep-app 1 Karakeep 2026-08-18 3.7 Low
A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the file apps/web/server/auth.ts of the component OAuth Sign-In. This manipulation causes improper authentication. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-32547 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.
CVE-2026-32474 2026-08-18 9.9 Critical
Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
CVE-2026-32467 2026-08-18 6 Medium
Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.
CVE-2026-32464 2026-08-18 8.1 High
Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.
CVE-2026-32444 2026-08-18 9.9 Critical
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
CVE-2026-32333 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions.
CVE-2026-28570 2026-08-18 8.1 High
Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.
CVE-2026-28568 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions.
CVE-2026-28567 2026-08-18 7.5 High
Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.
CVE-2026-60112 2 Nasa, Nasa-ammos 2 Ait Gui, Ait-gui 2026-08-18 9.8 Critical
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward arbitrary commands directly to the AIT command bus without any authentication gate between session creation and command dispatch.
CVE-2026-74961 1 Mozilla 1 Firefox 2026-08-18 N/A
Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-74978 1 Mozilla 1 Firefox 2026-08-18 N/A
Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
CVE-2026-74979 1 Mozilla 1 Firefox 2026-08-18 N/A
Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.