Export limit exceeded: 41104 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (41104 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-32348 | 1 Google | 1 Android | 2026-06-02 | 7.8 High |
| In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-42677 | 2 Ben Balter, Wordpress | 2 Wp Document Revisions, Wordpress | 2026-06-02 | 7.5 High |
| Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Document Revisions: from n/a before 4.0.0. | ||||
| CVE-2026-45267 | 1 Nextcloud | 1 Forms | 2026-06-02 | 6.5 Medium |
| Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed users to request reading form submissions of other users. This issue has been patched in version 5.2.6. | ||||
| CVE-2024-52011 | 1 Vitejs | 2 Launch-editor, Vite | 2026-06-02 | 8.3 High |
| launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that contains special characters. This issue has been fixed in the `launch-editor` version 2.9.0, corresponding to vite version 5.4.9. | ||||
| CVE-2026-41013 | 1 Cloudfoundry | 2 Cf-deployment, Smb-volume-release | 2026-06-02 | 8.1 High |
| Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells. Affected versions: smb-volume-release: All versions prior to v3.60.0 CF Deployment: All versions prior to v56.0.0 | ||||
| CVE-2018-25428 | 1 Paroiciel | 1 Paroiciel | 2026-06-02 | 8.2 High |
| Paroiciel 11.20 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the tRecIdListe parameter. Attackers can send GET requests to the trec.php endpoint with crafted SQL payloads to extract database information including table and column names. | ||||
| CVE-2018-25429 | 1 Paroiciel | 1 Paroiciel | 2026-06-02 | 7.1 High |
| Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the zProIdPro parameter. Attackers can send GET requests to zpro.php with crafted SQL payloads in the zProIdPro parameter to extract sensitive database information including usernames, databases, and version details. | ||||
| CVE-2018-25430 | 1 Paroiciel | 1 Paroiciel | 2026-06-02 | 7.1 High |
| Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the eGeqIdEquipe parameter. Attackers can send GET requests to the egeq.php endpoint with crafted SQL payloads to extract sensitive database information including version details and other data. | ||||
| CVE-2018-25433 | 1 Joomlaextensions | 1 Je Photo Gallery | 2026-06-02 | 8.2 High |
| Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categoryid parameter. Attackers can send GET requests to index.php with crafted categoryid values in the com_jephotogallery component to execute arbitrary SQL queries and retrieve sensitive data like usernames and password hashes. | ||||
| CVE-2018-25434 | 3 Eliekhoury, What3words, Wordpress | 3 Wp Autosuggest, Autosuggest, Wordpress | 2026-06-02 | 8.2 High |
| WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wpas_keys parameter. Attackers can send GET requests to autosuggest.php with crafted wpas_keys values to extract sensitive database information from WordPress posts and other tables. | ||||
| CVE-2026-49491 | 1 Pixastudio | 1 Pixa Bank | 2026-06-02 | 8.2 High |
| Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive data by injecting SQL code into the 'rib' parameter. Attackers can send POST requests to the agence-ajax.php endpoint with UNION-based SQL payloads to retrieve user information including names, email addresses, and phone numbers from the database. | ||||
| CVE-2026-9234 | 2 Ntbyk, Wordpress | 2 Jtl-connector For Woocommerce, Wordpress | 2026-06-02 | 4.3 Medium |
| The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.4.1. This is due to missing capability checks and nonce verification on the admin_post_settings_save_woo-jtl-connector action (handled by JtlConnectorAdmin::save()) and on the wp_ajax_downloadJTLLogs and wp_ajax_clearJTLLogs AJAX actions (handled by the global downloadJTLLogs() and clearJTLLogs() functions). This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify arbitrary plugin settings, download a ZIP archive of the connector's developer log files, and delete those log files. | ||||
| CVE-2025-52766 | 2 Printeers, Wordpress | 2 Printeers Print & Ship, Wordpress | 2026-06-02 | 6.5 Medium |
| Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Printeers Print & Ship: from n/a through 1.17.0. | ||||
| CVE-2025-53302 | 2 Anton Shevchuk, Wordpress | 2 Constructor, Wordpress | 2026-06-02 | 5.3 Medium |
| Missing Authorization vulnerability in Anton Shevchuk Constructor allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Constructor: from n/a through 1.6.5. | ||||
| CVE-2025-53345 | 2 Thimpress, Wordpress | 2 Thim Core, Wordpress | 2026-06-02 | 8.8 High |
| Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress Thim Core. This issue affects Thim Core: from n/a through 2.3.3. | ||||
| CVE-2025-53346 | 2 Thimpress, Wordpress | 2 Thim Core, Wordpress | 2026-06-02 | 4.3 Medium |
| Missing Authorization vulnerability in ThimPress Thim Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Thim Core: from n/a through 2.3.3. | ||||
| CVE-2026-42670 | 2 Etoile Web Design Incorporated, Wordpress | 2 Five Star Restaurant Reservations, Wordpress | 2026-06-02 | 7.5 High |
| Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Five Star Restaurant Reservations: from n/a through 2.7.14. | ||||
| CVE-2026-42684 | 2 Ahmad, Wordpress | 2 Wp Job Portal, Wordpress | 2026-06-02 | 9.3 Critical |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection. This issue affects WP Job Portal: from n/a through 2.5.1. | ||||
| CVE-2026-27351 | 2 Sekander Badsha, Wordpress | 2 Crew Hrm, Wordpress | 2026-06-02 | 5.4 Medium |
| Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Crew HRM: from n/a through 1.2.2. | ||||
| CVE-2025-30028 | 1 Synology | 2 Active Backup For Business, Diskstation Manager | 2026-06-02 | 8.6 High |
| A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files. | ||||