Export limit exceeded: 374231 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (374231 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-53976 | 1 Bohdan Triapitsyn | 1 Openchamber | 2026-08-07 | 9.1 Critical |
| OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPathWithinRoot guard to read sensitive files such as the JWT signing secret, SSH private keys, API credentials, and environment variables, enabling full authentication bypass by forging session cookies on password-protected deployments. | ||||
| CVE-2026-28141 | 2 Syed Balkhi, Wordpress | 2 Nextgen Gallery, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions. | ||||
| CVE-2026-28172 | 2 Data443 Risk Mitigation, Inc., Wordpress | 2 Tracking Code Manager, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions. | ||||
| CVE-2026-28177 | 2 Daniel Iser, Wordpress | 2 Popup Maker, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions. | ||||
| CVE-2026-28179 | 2 Damian Góra, Wordpress | 2 Fibosearch, Wordpress | 2026-08-07 | 5.9 Medium |
| Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions. | ||||
| CVE-2026-32469 | 2 Wordpress, Wpkube | 2 Wordpress, Captcha 4wp | 2026-08-07 | 5.3 Medium |
| Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions. | ||||
| CVE-2026-65504 | 2 Ivanbebek, Wordpress | 2 Box Now Delivery Croatia, Wordpress | 2026-08-07 | 7.5 High |
| Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions. | ||||
| CVE-2026-65517 | 2 Scott Paterson, Wordpress | 2 Easy Paypal Buy Now Button, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions. | ||||
| CVE-2026-65523 | 2 Approveme, Wordpress | 2 Formidable Forms Signature Online Contract Automation, Wordpress | 2026-08-07 | 7.5 High |
| Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions. | ||||
| CVE-2026-65541 | 2 Solutioned, Wordpress | 2 Staff Training, Wordpress | 2026-08-07 | 7.3 High |
| Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions. | ||||
| CVE-2026-65542 | 2 Rajat Varlani, Wordpress | 2 Super Socializer, Wordpress | 2026-08-07 | 8.8 High |
| Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions. | ||||
| CVE-2026-65543 | 2 Vimeodev, Wordpress | 2 Vimeo, Wordpress | 2026-08-07 | 7.5 High |
| Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions. | ||||
| CVE-2026-65544 | 2 Rajat Varlani, Wordpress | 2 Super Socializer, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions. | ||||
| CVE-2026-65546 | 2 Qode, Wordpress | 2 Qode Tours, Wordpress | 2026-08-07 | 9.3 Critical |
| Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions. | ||||
| CVE-2026-65553 | 2 Wbolt.com, Wordpress | 2 Spider Analyser – Wordpress搜索引擎蜘蛛分析插件, Wordpress | 2026-08-07 | 10 Critical |
| Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions. | ||||
| CVE-2026-65554 | 2 Lattepress, Wordpress | 2 Anspress – Question And Answer, Wordpress | 2026-08-07 | 7.1 High |
| Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions. | ||||
| CVE-2026-65556 | 2 Mihche, Wordpress | 2 Wpbruiser {no- Captcha Anti-spam}, Wordpress | 2026-08-07 | 9.8 Critical |
| Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. | ||||
| CVE-2026-65571 | 2 Axiomthemes, Wordpress | 2 69 Clothing, Wordpress | 2026-08-07 | 9.8 Critical |
| Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. | ||||
| CVE-2026-65572 | 2 Axiomthemes, Wordpress | 2 A.williams, Wordpress | 2026-08-07 | 9.8 Critical |
| Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. | ||||
| CVE-2026-66452 | 2 It-recht Kanzlei, Wordpress | 2 Legal Text Connector Of The It-recht Kanzlei, Wordpress | 2026-08-07 | 6.5 Medium |
| Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions. | ||||