Export limit exceeded: 382273 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (382273 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-78555 | 1 Ransomlook | 1 Ransomlook | 2026-08-24 | N/A |
| RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Although the interface displayed only a shortened representation of each key, the full token was embedded in hidden form fields used by the enable/disable, private-access, and delete actions. As a result, API credentials could be recovered by inspecting the page source or DOM. The credentials could also be unintentionally exposed through components that retain or inspect HTTP response bodies, such as debugging proxies, browser caches, monitoring systems, or other intermediaries. An attacker obtaining one of these tokens could subsequently authenticate using the privileges assigned to that key, including access to private data where the key was granted such permissions. The patch removes API keys from subsequent page rendering and replaces them with SHA-256-derived opaque handles. Administrative actions submit only these handles, which are resolved back to the corresponding token on the server. The full API key is therefore disclosed only once, when it is initially created. | ||||
| CVE-2026-76816 | 1 Netty | 1 Netty | 2026-08-24 | 3.5 Low |
| Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names before encoding, allowing prohibited null bytes in MQTT UTF-8 string fields and potentially causing routing, access-control, or identity mismatches in downstream brokers. The vulnerability is exploitable when an application uses Netty's MQTT encoder to construct messages from user-controlled input. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final. | ||||
| CVE-2026-76098 | 1 Lepture | 1 Mistune | 2026-08-24 | 7.5 High |
| Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can exceed Python's recursion limit and raise RecursionError, allowing crafted Markdown to crash a parsing process. This issue is fixed in version 3.3.3 | ||||
| CVE-2026-39458 | 1 F5 | 22 Big-ip, Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager and 19 more | 2026-08-24 | 7.5 High |
| When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanced WAF DoS protection), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | ||||
| CVE-2026-78282 | 2026-08-24 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions. | ||||
| CVE-2026-78268 | 2026-08-24 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions. | ||||
| CVE-2026-78267 | 2026-08-24 | 9.8 Critical | ||
| Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions. | ||||
| CVE-2026-78266 | 2026-08-24 | 6.5 Medium | ||
| Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions. | ||||
| CVE-2026-78265 | 2026-08-24 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions. | ||||
| CVE-2026-78264 | 2026-08-24 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions. | ||||
| CVE-2026-78263 | 2026-08-24 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions. | ||||
| CVE-2026-78262 | 2026-08-24 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions. | ||||
| CVE-2026-78259 | 2026-08-24 | 7.3 High | ||
| Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions. | ||||
| CVE-2026-32563 | 2026-08-24 | 9.8 Critical | ||
| Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | ||||
| CVE-2026-32561 | 2026-08-24 | 8.8 High | ||
| Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions. | ||||
| CVE-2026-32560 | 2026-08-24 | 8.8 High | ||
| Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions. | ||||
| CVE-2026-32559 | 2026-08-24 | 9.9 Critical | ||
| Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions. | ||||
| CVE-2026-32556 | 2026-08-24 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions. | ||||
| CVE-2026-32555 | 2026-08-24 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Boost <= 2.0.4 versions. | ||||
| CVE-2026-32554 | 2026-08-24 | 9.3 Critical | ||
| Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions. | ||||