Export limit exceeded: 377195 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 377195 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (377195 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-28004 | 2026-08-13 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions. | ||||
| CVE-2026-28003 | 2026-08-13 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions. | ||||
| CVE-2026-27544 | 2 Quarka, Wordpress | 2 Qa Analytics, Wordpress | 2026-08-13 | 10 Critical |
| Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. | ||||
| CVE-2026-27543 | 2 Fluxbuilder, Wordpress | 2 Mstore Api, Wordpress | 2026-08-13 | 8.1 High |
| Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions. | ||||
| CVE-2026-27538 | 2 Wordpress, Wpdirectorykit | 2 Wordpress, Wp Directory Kit | 2026-08-13 | 7.5 High |
| Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. | ||||
| CVE-2026-27537 | 2026-08-13 | 6.5 Medium | ||
| Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions. | ||||
| CVE-2026-27536 | 2 Pluginops, Wordpress | 2 Mailchimp Subscribe Form, Wordpress | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions. | ||||
| CVE-2026-27535 | 2 Solacewp, Wordpress | 2 Solace Extra, Wordpress | 2026-08-13 | 7.1 High |
| Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions. | ||||
| CVE-2026-27380 | 2 Magepeopleteam, Wordpress | 2 Car Rental Manager, Wordpress | 2026-08-13 | 7.2 High |
| Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions. | ||||
| CVE-2026-27345 | 2026-08-13 | 7.5 High | ||
| Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions. | ||||
| CVE-2026-21832 | 2026-08-13 | 4.3 Medium | ||
| HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions. | ||||
| CVE-2026-19716 | 1 Maalfer | 1 Pentestify | 2026-08-13 | N/A |
| Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the username with escapeHTML() before interpolating it into the onclick attribute of the account deletion button, but the browser HTML-decodes attribute values before the JavaScript engine parses the handler, allowing an encoded single quote (') to break out of the string literal and inject arbitrary JavaScript that executes when the victim clicks the delete button for that account. | ||||
| CVE-2026-19385 | 1 Postgresql | 1 Postgresql | 2026-08-13 | 8.8 High |
| Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | ||||
| CVE-2026-18744 | 1 Cert | 1 Vince | 2026-08-13 | 6.5 Medium |
| Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func only checks _is_my_case, not ownership of kwargs['member']. Bypasses share_status; leaks embargoed vendor affected/not-affected + statement text cross-tenant. | ||||
| CVE-2026-18675 | 1 Konghq | 1 Kong Mesh | 2026-08-13 | N/A |
| The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose kid is a JSON number decodes as a float64 and triggers a runtime panic before any signature, claims, or authorization check runs. The panic terminates the entire kuma-cp process, HTTP API, the health and readiness endpoints, and xDS. Unauthenticated access to the dataplane gRPC server can trigger the crash with a malformed token A single request is a transient interruption; sustaining an outage requires repeated requests. | ||||
| CVE-2026-18663 | 1 Redhat | 2 Directory Server, Enterprise Linux | 2026-08-13 | 5.9 Medium |
| A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation teardown then frees the same pointer again, causing a double-free. An unauthenticated remote attacker can trigger this with a single BIND request carrying a critical Session Tracking control, resulting in heap corruption and potential denial of service. | ||||
| CVE-2026-18408 | 1 Postgresql | 1 Postgresql | 2026-08-13 | 8.8 High |
| Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | ||||
| CVE-2026-16241 | 1 Postgresql | 1 Postgresql | 2026-08-13 | 3.8 Low |
| Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | ||||
| CVE-2026-16239 | 1 Postgresql | 1 Postgresql | 2026-08-13 | 8.8 High |
| Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | ||||
| CVE-2026-16238 | 1 Postgresql | 1 Postgresql | 2026-08-13 | 8.8 High |
| Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected. | ||||