Export limit exceeded: 373862 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 373862 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (373862 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65515 | 2 Affiliatewp, Wordpress | 2 Affiliatewp, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions. | ||||
| CVE-2026-65520 | 2 Miniorange, Wordpress | 2 Wp Oauth Server, Wordpress | 2026-08-06 | 9.3 Critical |
| Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. | ||||
| CVE-2026-65547 | 2 Constantcontact, Wordpress | 2 Creative Mail, Wordpress | 2026-08-06 | 8.5 High |
| Subscriber SQL Injection in Creative Mail <= 1.6.9 versions. | ||||
| CVE-2026-65548 | 2 Muffingroup, Wordpress | 2 Betheme, Wordpress | 2026-08-06 | 9.9 Critical |
| Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions. | ||||
| CVE-2026-65552 | 2 Qlstudio, Wordpress | 2 Export User Data, Wordpress | 2026-08-06 | 9.8 Critical |
| Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. | ||||
| CVE-2026-67873 | 2026-08-06 | 9.8 Critical | ||
| A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the current ASDU frame before encoding object fields and segment data | ||||
| CVE-2026-65508 | 2 Nsquared, Wordpress | 2 Simply Schedule Appointments, Wordpress | 2026-08-06 | 9.3 Critical |
| Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions. | ||||
| CVE-2026-65544 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions. | ||||
| CVE-2026-65549 | 2026-08-06 | 7.2 High | ||
| Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions. | ||||
| CVE-2026-65565 | 2 Ays-pro, Wordpress | 2 Survey Maker, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions. | ||||
| CVE-2026-65571 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. | ||||
| CVE-2026-34502 | 1 Apache | 1 Portable Runtime Utility | 2026-08-06 | 7.5 High |
| Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3. | ||||
| CVE-2025-49506 | 1 Apache | 1 Portable Runtime Utility | 2026-08-06 | N/A |
| APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue. | ||||
| CVE-2026-28178 | 2 Codesupplyco, Wordpress | 2 Powerkit, Wordpress | 2026-08-06 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions. | ||||
| CVE-2026-65569 | 2 Wordpress, Wpjobportal | 2 Wordpress, Wp Job Portal | 2026-08-06 | 8.5 High |
| Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions. | ||||
| CVE-2026-19046 | 1 Noctedefensor | 1 Ludusmcp | 2026-08-06 | 3.3 Low |
| A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesSearch.ts of the component ludus_environment_guides_search. Such manipulation of the argument guide_name leads to path traversal. Local access is required to approach this attack. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-67870 | 1 Open62541 | 1 Open62541 | 2026-08-06 | 9.8 Critical |
| In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues. | ||||
| CVE-2026-18276 | 2026-08-06 | 4.3 Medium | ||
| Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls and object_pk values of a join-room message, which are passed to group_add without an access check | ||||
| CVE-2026-18275 | 2026-08-06 | 6.5 Medium | ||
| Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to run segmentation and transcription against other users' document parts, overwriting their content, via part primary keys supplied to a many=True related field whose queryset restriction was applied to the ManyRelatedField instead of its child_relation and therefore had no effect | ||||
| CVE-2026-18258 | 2026-08-06 | 8.8 High | ||
| Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the global model manager instead of the request-scoped queryset | ||||