Search Results (398 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-41928 2 Givanz, Vvveb 2 Vvveb, Vvveb 2026-07-28 5.3 Medium
Vvveb before 1.0.8.2 contains an information disclosure vulnerability in the cron controller that allows unauthenticated attackers to retrieve the application's secret cron key. Attackers can access the cron controller without authentication and retrieve the exposed secret key from the response, enabling them to trigger scheduled task execution outside of the intended schedule.
CVE-2026-59548 2 Byteflows, Wordpress 2 Byteflows Travel & Hotel Booking, Wordpress 2026-07-27 7.5 High
Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1.0.0 versions.
CVE-2025-59178 1 Ericsson 1 Packet Core Controller 2026-07-27 N/A
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.
CVE-2026-65564 2 Chrisrichardson, Wordpress 2 Mappress Maps For Wordpress, Wordpress 2026-07-27 5.3 Medium
Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.
CVE-2026-59528 2 Shiptime, Wordpress 2 Shiptime: Discounted Shipping Rates, Wordpress 2026-07-27 7.5 High
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
CVE-2026-44955 1 Pronetiqs 1 Panduit Intravue 2026-07-27 5.3 Medium
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discovery by unauthenticated users.
CVE-2026-28698 1 Pronetiqs 1 Panduit Intravue 2026-07-27 8.6 High
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.
CVE-2026-61081 1 Oracle 2 Mysql Cluster, Mysql Server 2026-07-27 2.7 Low
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).
CVE-2023-37507 2 Hclsoftware, Hcltech 2 Devops Plan, Devops Plan 2026-07-23 7.5 High
HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.
CVE-2026-65490 2 Mischiefmarmot, Wordpress 2 Create By Mediavine, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.
CVE-2026-65521 2 Mahmudul Hasan Arif, Wordpress 2 Wp Social Ninja, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.
CVE-2026-65535 2 Takayuki Miyauchi, Wordpress 2 Tinymce Templates, Wordpress 2026-07-23 4.3 Medium
Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
CVE-2026-61945 2 Multivendorx, Wordpress 2 Woocommerce Product Stock Alert, Wordpress 2026-07-23 6.5 Medium
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.
CVE-2026-65474 2 Wordpress, Wpmanageninja 2 Wordpress, Ninja Tables 2026-07-23 5.3 Medium
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
CVE-2026-65505 2 Bdthemes, Wordpress 2 Utlimate Store Kit Elementor Addons, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
CVE-2026-57393 2 Edgarrojas, Wordpress 2 Woocommerce Pdf Invoice Builder, Wordpress 2026-07-21 6.5 Medium
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 2.0.8.
CVE-2026-47081 1 Cyrusimap 1 Cyrus Imap 2026-07-16 3.1 Low
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of arbitrary mailboxes on other users' accounts via the XAPPLEPUSHSERVICE command and then create Apple Push Notification Service notifications for new mail in those mailboxes to their own APNS device. This did not leak any data about the content of mailboxes. Instead, a "mailbox has changed" notice would be pushed when the mailbox modseq changed.
CVE-2026-50294 1 Microsoft 18 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 15 more 2026-07-16 6.2 Medium
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.
CVE-2018-25358 2 D-link, Dlink 2 Dir601na, Dir-601 2026-07-15 7.5 High
D-Link DIR601 2.02NA contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by manipulating the table_name parameter in POST requests. Attackers can send requests to /my_cgi.cgi with table_name values like admin_user, wireless_settings, and wireless_security to extract administrative credentials and wireless network keys in clear text.
CVE-2026-61977 2 Crocoblock, Wordpress 2 Jetsearch, Wordpress 2026-07-13 5.3 Medium
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2.