Export limit exceeded: 373057 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 373057 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 373057 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (373057 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73993 | 2 Roxnor, Wordpress | 2 Fundengine, Wordpress | 2026-08-20 | 9.8 Critical |
| Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | ||||
| CVE-2026-73992 | 2 Jonathan Daggerhart, Wordpress | 2 Query Wrangler, Wordpress | 2026-08-20 | 9.9 Critical |
| Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions. | ||||
| CVE-2026-68566 | 2 Repute Infosystems, Wordpress | 2 Bookingpress Appointment Booking Pro, Wordpress | 2026-08-20 | 9.3 Critical |
| Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. | ||||
| CVE-2026-67921 | 2026-08-20 | 9.3 Critical | ||
| Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java components. This allows a remote attacker to execute arbitrary code. | ||||
| CVE-2026-67920 | 2026-08-20 | 8.8 High | ||
| An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir(), and org.springframework.util.FileSystemUtils.copyRecursively() components | ||||
| CVE-2026-66682 | 2 Tychesoftwares, Wordpress | 2 Abandoned Cart Pro For Woocommerce, Wordpress | 2026-08-20 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. | ||||
| CVE-2026-66649 | 2 E-plugins, Wordpress | 2 Directory Pro, Wordpress | 2026-08-20 | 9.3 Critical |
| Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions. | ||||
| CVE-2026-66615 | 2 Eric Teubert, Wordpress | 2 Podlove Podcast Publisher, Wordpress | 2026-08-20 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions. | ||||
| CVE-2026-66600 | 2 Davidlingren, Wordpress | 2 Media Library Assistant, Wordpress | 2026-08-20 | 9.1 Critical |
| Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. | ||||
| CVE-2026-66597 | 2 Melograno Venture Studio, Wordpress | 2 Wpdatatables, Wordpress | 2026-08-20 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions. | ||||
| CVE-2026-66582 | 2 Cozmoslabs, Wordpress | 2 Translatepress, Wordpress | 2026-08-20 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions. | ||||
| CVE-2026-63016 | 1 Apache | 1 Inlong | 2026-08-20 | 5.3 Medium |
| Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow upload of non-official packages. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/12095 https://github.com/apache/inlong/pull/11732 | ||||
| CVE-2026-60767 | 1 Oracle | 1 Siebel Apps - Marketing | 2026-08-20 | 8.8 High |
| Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). | ||||
| CVE-2026-60754 | 1 Oracle | 1 Siebel Apps - Marketing | 2026-08-20 | 9.1 Critical |
| Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Apps - Marketing accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H). | ||||
| CVE-2026-52610 | 2026-08-20 | 9.1 Critical | ||
| An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user by specifying a filename in the "saveTemplate" parameter in conjuction with "execute_mode=PREPARE" parameter in the "run.php" endpoint. | ||||
| CVE-2026-28150 | 2 Uxper, Wordpress | 2 Golo Framework, Wordpress | 2026-08-20 | 8.1 High |
| Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions. | ||||
| CVE-2026-18102 | 1 Ibm | 1 I | 2026-08-20 | 3.5 Low |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memory due to an integer underflow during bounds checking. | ||||
| CVE-2026-17015 | 1 Ibm | 1 I | 2026-08-20 | 5.4 Medium |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read. | ||||
| CVE-2026-16932 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 8.8 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper validation of the ODMDIR environment variable. | ||||
| CVE-2026-16927 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 7.3 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-check to time-of-use (TOCTOU) race condition. | ||||