Export limit exceeded: 381219 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381219 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-62299 | 2026-08-20 | 6.6 Medium | ||
| HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges. | ||||
| CVE-2025-62300 | 2026-08-20 | 5.9 Medium | ||
| HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable behavior. | ||||
| CVE-2026-7485 | 1 Checkmk | 1 Checkmk | 2026-08-20 | N/A |
| Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of hosts and services they are not authorized to see. | ||||
| CVE-2025-62306 | 2026-08-20 | 5 Medium | ||
| HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response. | ||||
| CVE-2026-66581 | 2026-08-20 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. | ||||
| CVE-2026-66609 | 2026-08-20 | 9.3 Critical | ||
| Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. | ||||
| CVE-2026-66598 | 2026-08-20 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions. | ||||
| CVE-2026-68564 | 2026-08-20 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions. | ||||
| CVE-2026-66672 | 2026-08-20 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. | ||||
| CVE-2025-15637 | 2026-08-20 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. | ||||
| CVE-2025-62307 | 2026-08-20 | 5.4 Medium | ||
| HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing. | ||||
| CVE-2026-74020 | 2026-08-20 | 7.5 High | ||
| Unauthenticated Broken Access Control in Koji <= 2.2.1 versions. | ||||
| CVE-2026-74019 | 2026-08-20 | 7.1 High | ||
| Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions. | ||||
| CVE-2026-74018 | 2026-08-20 | 9.9 Critical | ||
| Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions. | ||||
| CVE-2026-74013 | 2026-08-20 | 8.5 High | ||
| Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions. | ||||
| CVE-2026-73998 | 2026-08-20 | 8.5 High | ||
| Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. | ||||
| CVE-2026-66677 | 2026-08-20 | 7.6 High | ||
| Subscriber Broken Authentication in Leyka <= 3.32.3 versions. | ||||
| CVE-2026-66614 | 2026-08-20 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions. | ||||
| CVE-2026-66606 | 2026-08-20 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions. | ||||
| CVE-2026-66594 | 2026-08-20 | 8.5 High | ||
| Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. | ||||