Export limit exceeded: 379189 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (379189 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73339 | 2026-08-18 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions. | ||||
| CVE-2026-73338 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions. | ||||
| CVE-2026-73181 | 2026-08-18 | 7.5 High | ||
| Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions. | ||||
| CVE-2026-71518 | 1 Typemill | 1 Typemill | 2026-08-18 | 7.5 High |
| Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash prefixes, double slashes, or percent-encoded sequences to pass role-based restriction checks while the filesystem resolves the request to the protected file, enabling unauthorized file download without credentials. | ||||
| CVE-2026-68568 | 2026-08-18 | 6.3 Medium | ||
| Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions. | ||||
| CVE-2026-68517 | 1 Nicolargo | 1 Glances | 2026-08-18 | 6.5 Medium |
| Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list containing the wildcard to retain cors_credentials and expose authenticated REST API data to an untrusted website visited by a previously authenticated user. This issue is fixed in 4.5.6. | ||||
| CVE-2026-66792 | 1 Redhat | 4 Acm, Multicluster Globalhub, Openshift and 1 more | 2026-08-18 | 9.9 Critical |
| A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources. | ||||
| CVE-2026-66667 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions. | ||||
| CVE-2026-66645 | 2026-08-18 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions. | ||||
| CVE-2026-66643 | 2026-08-18 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions. | ||||
| CVE-2026-66641 | 2026-08-18 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions. | ||||
| CVE-2026-66639 | 2026-08-18 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions. | ||||
| CVE-2026-66636 | 2026-08-18 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions. | ||||
| CVE-2026-66634 | 2026-08-18 | 4.3 Medium | ||
| Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions. | ||||
| CVE-2026-66621 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions. | ||||
| CVE-2026-65974 | 1 Frappe | 1 Erpnext | 2026-08-18 | 9.9 Critical |
| ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forcing restrict_globals, allowing server-side template injection and remote code execution. This issue is fixed in versions 15.111.0 and 16.22.0. | ||||
| CVE-2026-64865 | 1 Quantumnous | 1 New-api | 2026-08-18 | N/A |
| New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_modules can race relay billing because controller/user.go calls User.Update and updateUserCache performs a full RedisHSetObj write to user:.Quota, overwriting concurrent HINCRBY deductions and allowing an authenticated user to keep cached quota artificially high. This issue is fixed in version 1.0.0-rc.16. | ||||
| CVE-2026-59909 | 1 Dell | 1 Objectscale | 2026-08-18 | 7.1 High |
| Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | ||||
| CVE-2026-59902 | 1 Netty | 1 Netty | 2026-08-18 | 7.5 High |
| Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing unauthenticated peers to exhaust memory with large SCTP fragments. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final. | ||||
| CVE-2026-56090 | 1 Dell | 1 Objectscale | 2026-08-18 | 7.3 High |
| Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | ||||