Export limit exceeded: 92759 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (92759 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-67867 | 1 Systerel | 1 S2opc | 2026-08-06 | 7.5 High |
| Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Alarm/Conditions wrapper when processing PublishResponse EventNotificationList data | ||||
| CVE-2026-61483 | 1 Apache | 1 Lucy | 2026-08-06 | 7.5 High |
| ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | ||||
| CVE-2026-11714 | 1 Ibm | 2 Websphere Application Server, Websphere Application Server Liberty | 2026-08-06 | 8.5 High |
| IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled. | ||||
| CVE-2026-18990 | 1 Letta-ai | 1 Lettabot | 2026-08-06 | 7.3 High |
| A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Route. The manipulation results in missing authentication. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-66712 | 2 Wordpress, Wp.insider | 2 Wordpress, Simple Membership | 2026-08-06 | 7.5 High |
| Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions. | ||||
| CVE-2026-66440 | 2 Wordpress, Xplodedthemes | 2 Wordpress, Wpide - File Manager & Code Editor | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions. | ||||
| CVE-2026-19036 | 1 Shibby | 1 Tomato | 2026-08-06 | 7.2 High |
| A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This project is superseded by FreshTomato. | ||||
| CVE-2026-28143 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions. | ||||
| CVE-2025-63822 | 2026-08-06 | 8.1 High | ||
| SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is authorized to access the target user's data. | ||||
| CVE-2026-18050 | 2026-08-06 | 7.5 High | ||
| The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The identifier is high-entropy, is disclosed only to the uploader, and the file is removed on submission or by a scheduled cleanup, so a cross-user read is not achievable by guessing alone. | ||||
| CVE-2026-61961 | 2 Wordpress, Wpdeveloper | 2 Wordpress, Embedpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. | ||||
| CVE-2026-66708 | 2 Boldgrid, Wordpress | 2 Total Upkeep, Wordpress | 2026-08-06 | 8.2 High |
| Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions. | ||||
| CVE-2026-66710 | 2 E2pdf, Wordpress | 2 E2pdf, Wordpress | 2026-08-06 | 8.1 High |
| Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions. | ||||
| CVE-2026-61982 | 2 Jp-secure, Wordpress | 2 Siteguard Wp Plugin, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. | ||||
| CVE-2026-65509 | 2 Wordpress, Wpdatatables | 2 Wordpress, Wpdatatables | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. | ||||
| CVE-2026-66439 | 2 Berocket, Wordpress | 2 Advanced Ajax Product Filters, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions. | ||||
| CVE-2026-65545 | 2 Jordy Meow, Wordpress | 2 Ai-engine, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions. | ||||
| CVE-2026-65560 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions. | ||||
| CVE-2026-66457 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions. | ||||
| CVE-2026-3430 | 2026-08-06 | 8.6 High | ||
| The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail. | ||||