Export limit exceeded: 382273 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (382273 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-78555 1 Ransomlook 1 Ransomlook 2026-08-24 N/A
RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Although the interface displayed only a shortened representation of each key, the full token was embedded in hidden form fields used by the enable/disable, private-access, and delete actions. As a result, API credentials could be recovered by inspecting the page source or DOM. The credentials could also be unintentionally exposed through components that retain or inspect HTTP response bodies, such as debugging proxies, browser caches, monitoring systems, or other intermediaries. An attacker obtaining one of these tokens could subsequently authenticate using the privileges assigned to that key, including access to private data where the key was granted such permissions. The patch removes API keys from subsequent page rendering and replaces them with SHA-256-derived opaque handles. Administrative actions submit only these handles, which are resolved back to the corresponding token on the server. The full API key is therefore disclosed only once, when it is initially created.
CVE-2026-76816 1 Netty 1 Netty 2026-08-24 3.5 Low
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names before encoding, allowing prohibited null bytes in MQTT UTF-8 string fields and potentially causing routing, access-control, or identity mismatches in downstream brokers. The vulnerability is exploitable when an application uses Netty's MQTT encoder to construct messages from user-controlled input. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.
CVE-2026-76098 1 Lepture 1 Mistune 2026-08-24 7.5 High
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can exceed Python's recursion limit and raise RecursionError, allowing crafted Markdown to crash a parsing process. This issue is fixed in version 3.3.3
CVE-2026-39458 1 F5 22 Big-ip, Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager and 19 more 2026-08-24 7.5 High
When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanced WAF DoS protection), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-78282 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
CVE-2026-78268 2026-08-24 7.5 High
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.
CVE-2026-78267 2026-08-24 9.8 Critical
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
CVE-2026-78266 2026-08-24 6.5 Medium
Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
CVE-2026-78265 2026-08-24 9.8 Critical
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
CVE-2026-78264 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
CVE-2026-78263 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
CVE-2026-78262 2026-08-24 9.8 Critical
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
CVE-2026-78259 2026-08-24 7.3 High
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
CVE-2026-32563 2026-08-24 9.8 Critical
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
CVE-2026-32561 2026-08-24 8.8 High
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
CVE-2026-32560 2026-08-24 8.8 High
Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions.
CVE-2026-32559 2026-08-24 9.9 Critical
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
CVE-2026-32556 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
CVE-2026-32555 2026-08-24 9.3 Critical
Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
CVE-2026-32554 2026-08-24 9.3 Critical
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.