Export limit exceeded: 378146 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (398 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-41928 | 2 Givanz, Vvveb | 2 Vvveb, Vvveb | 2026-07-28 | 5.3 Medium |
| Vvveb before 1.0.8.2 contains an information disclosure vulnerability in the cron controller that allows unauthenticated attackers to retrieve the application's secret cron key. Attackers can access the cron controller without authentication and retrieve the exposed secret key from the response, enabling them to trigger scheduled task execution outside of the intended schedule. | ||||
| CVE-2026-59548 | 2 Byteflows, Wordpress | 2 Byteflows Travel & Hotel Booking, Wordpress | 2026-07-27 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions. | ||||
| CVE-2025-59178 | 1 Ericsson | 1 Packet Core Controller | 2026-07-27 | N/A |
| Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system. | ||||
| CVE-2026-65564 | 2 Chrisrichardson, Wordpress | 2 Mappress Maps For Wordpress, Wordpress | 2026-07-27 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions. | ||||
| CVE-2026-59528 | 2 Shiptime, Wordpress | 2 Shiptime: Discounted Shipping Rates, Wordpress | 2026-07-27 | 7.5 High |
| Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions. | ||||
| CVE-2026-44955 | 1 Pronetiqs | 1 Panduit Intravue | 2026-07-27 | 5.3 Medium |
| Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discovery by unauthenticated users. | ||||
| CVE-2026-28698 | 1 Pronetiqs | 1 Panduit Intravue | 2026-07-27 | 8.6 High |
| Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem. | ||||
| CVE-2026-61081 | 1 Oracle | 2 Mysql Cluster, Mysql Server | 2026-07-27 | 2.7 Low |
| Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N). | ||||
| CVE-2023-37507 | 2 Hclsoftware, Hcltech | 2 Devops Plan, Devops Plan | 2026-07-23 | 7.5 High |
| HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed. | ||||
| CVE-2026-65490 | 2 Mischiefmarmot, Wordpress | 2 Create By Mediavine, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions. | ||||
| CVE-2026-65521 | 2 Mahmudul Hasan Arif, Wordpress | 2 Wp Social Ninja, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions. | ||||
| CVE-2026-65535 | 2 Takayuki Miyauchi, Wordpress | 2 Tinymce Templates, Wordpress | 2026-07-23 | 4.3 Medium |
| Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions. | ||||
| CVE-2026-61945 | 2 Multivendorx, Wordpress | 2 Woocommerce Product Stock Alert, Wordpress | 2026-07-23 | 6.5 Medium |
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6. | ||||
| CVE-2026-65474 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Ninja Tables | 2026-07-23 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions. | ||||
| CVE-2026-65505 | 2 Bdthemes, Wordpress | 2 Utlimate Store Kit Elementor Addons, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | ||||
| CVE-2026-57393 | 2 Edgarrojas, Wordpress | 2 Woocommerce Pdf Invoice Builder, Wordpress | 2026-07-21 | 6.5 Medium |
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 2.0.8. | ||||
| CVE-2026-47081 | 1 Cyrusimap | 1 Cyrus Imap | 2026-07-16 | 3.1 Low |
| An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of arbitrary mailboxes on other users' accounts via the XAPPLEPUSHSERVICE command and then create Apple Push Notification Service notifications for new mail in those mailboxes to their own APNS device. This did not leak any data about the content of mailboxes. Instead, a "mailbox has changed" notice would be pushed when the mailbox modseq changed. | ||||
| CVE-2026-50294 | 1 Microsoft | 18 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 15 more | 2026-07-16 | 6.2 Medium |
| Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2018-25358 | 2 D-link, Dlink | 2 Dir601na, Dir-601 | 2026-07-15 | 7.5 High |
| D-Link DIR601 2.02NA contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by manipulating the table_name parameter in POST requests. Attackers can send requests to /my_cgi.cgi with table_name values like admin_user, wireless_settings, and wireless_security to extract administrative credentials and wireless network keys in clear text. | ||||
| CVE-2026-61977 | 2 Crocoblock, Wordpress | 2 Jetsearch, Wordpress | 2026-07-13 | 5.3 Medium |
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2. | ||||