Export limit exceeded: 385152 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (385152 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-82330 | 2 Gimp, Redhat | 2 Gimp, Enterprise Linux | 2026-08-31 | 6.1 Medium |
| A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents. | ||||
| CVE-2026-82957 | 1 Firefly | 1 Firefly | 2026-08-31 | 7.3 High |
| A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Subscription. Performing a manipulation of the argument url results in server-side request forgery. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-30060 | 1 Free5gc | 1 Free5gc | 2026-08-31 | 7.5 High |
| An issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) when parsing crafted SUCI data during UE registration. | ||||
| CVE-2026-38577 | 2026-08-31 | N/A | ||
| Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access. | ||||
| CVE-2026-75458 | 2026-08-31 | N/A | ||
| The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 contains a vertical privilege escalatio vulnerability. This interface accepts a user ID and then executes getUserById(id), setDeleted(true), updateByIdFilter() in sequence, without any validation of whether the current user has the authority to delete the target user. An authenticated teacher user (role=2) can delete an administrator account (role=3), constituting a vertical privilege escalation where a lower-privileged user performs a high-privileged operation. | ||||
| CVE-2026-82226 | 2 Tickera, Wordpress | 2 Tickera, Wordpress | 2026-08-31 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions. | ||||
| CVE-2026-82229 | 2 Miniorange, Wordpress | 2 Wordpress Social Login And Register, Wordpress | 2026-08-31 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions. | ||||
| CVE-2026-81293 | 2 Passionate Programmer Peter, Wordpress | 2 Wp Data Access, Wordpress | 2026-08-31 | 9.3 Critical |
| Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions. | ||||
| CVE-2026-81296 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluent Forms Pro Add On Pack | 2026-08-31 | 7.5 High |
| Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions. | ||||
| CVE-2026-82221 | 2 Metagauss, Wordpress | 2 Registrationmagic, Wordpress | 2026-08-31 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions. | ||||
| CVE-2026-82224 | 2 Iova.mihai, Wordpress | 2 Slicewp, Wordpress | 2026-08-31 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions. | ||||
| CVE-2026-82228 | 2 Siteground, Wordpress | 2 Siteground Security, Wordpress | 2026-08-31 | 8.1 High |
| Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions. | ||||
| CVE-2026-61638 | 1 Ellite | 1 Wallos | 2026-08-31 | N/A |
| Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/notifications/testemailnotifications.php accepts smtpaddress and smtpport from POST body with zero SSRF validation. PHPMailer connects to attacker-supplied host:port. Every other notification endpoint uses ssrf_helper.php but email was missed. Any authenticated user can probe internal network, cloud metadata. This issue has been patched in version 4.9.6. | ||||
| CVE-2026-18545 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-08-31 | 4.3 Medium |
| IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | ||||
| CVE-2026-18729 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-08-31 | 8.8 High |
| IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code. | ||||
| CVE-2026-18891 | 2 Ibm, Langflow | 2 Langflow Oss, Langflow | 2026-08-31 | 8.2 High |
| IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication. | ||||
| CVE-2026-82954 | 1 Dokploy | 1 Dokploy | 2026-08-31 | 9.9 Critical |
| A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the argument path results in path traversal. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-81780 | 2 Hashthemes, Wordpress | 2 Hash Form, Wordpress | 2026-08-31 | 10 Critical |
| Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. | ||||
| CVE-2026-82225 | 2 Metagauss, Wordpress | 2 Registrationmagic, Wordpress | 2026-08-31 | 7.4 High |
| Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions. | ||||
| CVE-2026-81768 | 2 Highwarden, Wordpress | 2 Super Store Finder, Wordpress | 2026-08-31 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions. | ||||