Export limit exceeded: 377705 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 377705 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (377705 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-82182 | 2 Wordpress, Wpvividplugins | 2 Wordpress, Wpvivid — Backup, Migration & Staging | 2026-09-02 | 4.1 Medium |
| The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied list of identifiers before using it in a SQL query, allowing administrators to perform SQL injection attacks. | ||||
| CVE-2026-18672 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-09-02 | 7.5 High |
| In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image directories. | ||||
| CVE-2026-19219 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-09-02 | 8.1 High |
| In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution. | ||||
| CVE-2026-84803 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2026-09-02 | 9 Critical |
| SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. Attackers can upload files with extensions like .xht, .ehtml, .xsl, .xbl, or .rdf that resolve to executable media types and execute JavaScript to steal API tokens and compromise workspaces. | ||||
| CVE-2026-81289 | 2 Sonaar, Wordpress | 2 Mp3 Audio Player For Music, Radio & Podcast, Wordpress | 2026-09-02 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions. | ||||
| CVE-2026-73474 | 1 Drupal | 1 Entity Share | 2026-09-02 | 5.3 Medium |
| Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2. | ||||
| CVE-2026-48521 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 5.9 Medium |
| No description is available for this CVE. | ||||
| CVE-2026-50572 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 5.9 Medium |
| No description is available for this CVE. | ||||
| CVE-2026-73511 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 5.3 Medium |
| No description is available for this CVE. | ||||
| CVE-2026-73512 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.5 High |
| No description is available for this CVE. | ||||
| CVE-2026-73513 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.5 High |
| No description is available for this CVE. | ||||
| CVE-2026-73546 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.4 High |
| No description is available for this CVE. | ||||
| CVE-2026-73547 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.5 High |
| No description is available for this CVE. | ||||
| CVE-2026-73548 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.5 High |
| No description is available for this CVE. | ||||
| CVE-2026-73549 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 5.3 Medium |
| No description is available for this CVE. | ||||
| CVE-2026-73550 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.5 High |
| No description is available for this CVE. | ||||
| CVE-2026-73551 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 5.3 Medium |
| No description is available for this CVE. | ||||
| CVE-2026-73552 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.5 High |
| No description is available for this CVE. | ||||
| CVE-2026-73553 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.5 High |
| No description is available for this CVE. | ||||
| CVE-2026-18765 | 1 Teracity | 1 E-osb | 2026-09-02 | 9.8 Critical |
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects E-OSB: before V02.26.07.08.01. | ||||