Export limit exceeded: 382433 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 382433 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (382433 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-77567 | 1 Filamentphp | 1 Filament | 2026-08-24 | 8.1 High |
| Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are enabled. Email-based multi-factor authentication is not affected. This issue is fixed in versions 4.12.0 and 5.7.0. | ||||
| CVE-2026-78555 | 1 Ransomlook | 1 Ransomlook | 2026-08-24 | N/A |
| RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Although the interface displayed only a shortened representation of each key, the full token was embedded in hidden form fields used by the enable/disable, private-access, and delete actions. As a result, API credentials could be recovered by inspecting the page source or DOM. The credentials could also be unintentionally exposed through components that retain or inspect HTTP response bodies, such as debugging proxies, browser caches, monitoring systems, or other intermediaries. An attacker obtaining one of these tokens could subsequently authenticate using the privileges assigned to that key, including access to private data where the key was granted such permissions. The patch removes API keys from subsequent page rendering and replaces them with SHA-256-derived opaque handles. Administrative actions submit only these handles, which are resolved back to the corresponding token on the server. The full API key is therefore disclosed only once, when it is initially created. | ||||
| CVE-2026-76816 | 1 Netty | 1 Netty | 2026-08-24 | 3.5 Low |
| Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names before encoding, allowing prohibited null bytes in MQTT UTF-8 string fields and potentially causing routing, access-control, or identity mismatches in downstream brokers. The vulnerability is exploitable when an application uses Netty's MQTT encoder to construct messages from user-controlled input. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final. | ||||
| CVE-2026-76098 | 1 Lepture | 1 Mistune | 2026-08-24 | 7.5 High |
| Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can exceed Python's recursion limit and raise RecursionError, allowing crafted Markdown to crash a parsing process. This issue is fixed in version 3.3.3 | ||||
| CVE-2026-39458 | 1 F5 | 22 Big-ip, Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager and 19 more | 2026-08-24 | 7.5 High |
| When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanced WAF DoS protection), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | ||||
| CVE-2026-78282 | 2026-08-24 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions. | ||||
| CVE-2026-78268 | 2026-08-24 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions. | ||||
| CVE-2026-78265 | 2026-08-24 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions. | ||||
| CVE-2026-78264 | 2026-08-24 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions. | ||||
| CVE-2026-78259 | 2026-08-24 | 7.3 High | ||
| Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions. | ||||
| CVE-2026-32561 | 2026-08-24 | 8.8 High | ||
| Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions. | ||||
| CVE-2026-32560 | 2026-08-24 | 8.8 High | ||
| Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions. | ||||
| CVE-2026-32559 | 2026-08-24 | 9.9 Critical | ||
| Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions. | ||||
| CVE-2026-32556 | 2026-08-24 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions. | ||||
| CVE-2026-32555 | 2026-08-24 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Boost <= 2.0.4 versions. | ||||
| CVE-2026-32554 | 2026-08-24 | 9.3 Critical | ||
| Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions. | ||||
| CVE-2026-78284 | 2026-08-24 | 8.6 High | ||
| Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions. | ||||
| CVE-2026-61241 | 1 Oracle | 1 Internet Directory | 2026-08-24 | 10 Critical |
| Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). | ||||
| CVE-2026-62449 | 1 Oracle | 1 Work In Process | 2026-08-24 | 7 High |
| Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Work in Process executes to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in takeover of Oracle Work in Process. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). | ||||
| CVE-2026-71073 | 2 Oracle, Oracle Corporation | 3 Mysql Connector/odbc, Mysql Connector\/odbc, Mysql Connectors | 2026-08-24 | 5.5 Medium |
| Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). | ||||