Export limit exceeded: 96514 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (96514 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73190 | 2 Shahjada, Wordpress | 2 Wpdm Premium Packages, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions. | ||||
| CVE-2026-73378 | 2 Supsysticcom, Wordpress | 2 Contact Form By Supsystic, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions. | ||||
| CVE-2026-50538 | 1 Libvncserver | 1 Libvncserver | 2026-08-24 | 8.8 High |
| LibVNCClient is a library for easy implementation of a VNC client. In versions 0.9.12 through 0.9.15, a malicious (or man-in-the-middle) VNC server can force a connecting `libvncclient` to write attacker-controlled data past the end of its framebuffer. This is an out-of-bounds heap write with attacker-controlled length, contents, and offset. It needs no authentication (the attacker is the server), works in a default build with default settings, and fires from a single `FramebufferUpdate` the moment the victim connects. It crashes any client unconditionally (denial of service); we also demonstrated it overwriting an application callback pointer and redirecting execution to attacker-chosen code (code execution) under the default configuration. Commit 540332be3e0acc566fa64da6f1b4680c72c724dd patches the issue. | ||||
| CVE-2026-10582 | 1 Gohugo | 1 Hugo | 2026-08-24 | 7.4 High |
| Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern list and then re-checks a canonicalised form of an integer, hex or octal IPv4 host, but it never resolves the hostname and never inspects the address the HTTP client actually connects to. The client constructed in resources/resource_factories/create/create.go installs no dial-time hook, so no check occurs at connection time either. A hostname that resolves to a loopback, private or cloud-metadata address therefore satisfies the policy, and the response body is embedded in the generated site. An attacker who can supply a URL through content, for example a front-matter field or a CMS field, can make the build fetch an internal endpoint and publish the response in the static output, so the build artifact itself carries the data out. | ||||
| CVE-2026-16922 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-24 | 7 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-check to time-of-use (TOCTOU) race condition. | ||||
| CVE-2026-16923 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-24 | 7 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management. | ||||
| CVE-2026-16924 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-24 | 7.5 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory offset during IPsec decapsulation. | ||||
| CVE-2026-16925 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-24 | 7.1 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to improper authorization. | ||||
| CVE-2025-36940 | 1 Google | 1 Android | 2026-08-24 | 8.8 High |
| Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (AP) | ||||
| CVE-2026-66584 | 2 Code4recovery, Wordpress | 2 12 Step Meeting List, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions. | ||||
| CVE-2026-78270 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluentcrm | 2026-08-24 | 7.6 High |
| Author SQL Injection in FluentCRM Pro <= 3.1.12 versions. | ||||
| CVE-2026-28151 | 2 Select-themes, Wordpress | 2 Tonda Core, Wordpress | 2026-08-24 | 8.1 High |
| Unauthenticated Local File Inclusion in Tonda < 2.6 versions. | ||||
| CVE-2026-32477 | 2 Radiustheme, Wordpress | 2 Shopbuilder – Elementor Woocommerce Builder Addons, Wordpress | 2026-08-24 | 8.6 High |
| Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions. | ||||
| CVE-2026-32478 | 2 Wedevs, Wordpress | 2 Wp Project Manager, Wordpress | 2026-08-24 | 8.5 High |
| Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions. | ||||
| CVE-2026-71505 | 1 Dolibarr | 1 Dolibarr | 2026-08-24 | 7.1 High |
| Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation rights to overwrite the WebPortal password of any company by bypassing per-object access checks that are only enforced on read routes. Attackers can replace the victim company's WebPortal password through the write endpoint, authenticate as that company to access its invoice data, and also obtain the victim's previous password verifier from the API response. | ||||
| CVE-2026-16927 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-24 | 7.3 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-check to time-of-use (TOCTOU) race condition. | ||||
| CVE-2026-16928 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-24 | 7.5 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a heap-based buffer overflow. | ||||
| CVE-2026-16932 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-24 | 8.8 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper validation of the ODMDIR environment variable. | ||||
| CVE-2026-16930 | 1 Ibm | 39 Power System E1050 \(9043-mrx\), Power System E1050 \(9043-mrx\) Firmware, Power System E1080 \(9080-hex\) and 36 more | 2026-08-24 | 8.2 High |
| IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can execute arbitrary code on the host system, giving full control over the host system and all hosted partitions, resulting in a confidentiality, integrity, and availability impact. | ||||
| CVE-2026-16989 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-24 | 7.1 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper resolution of symbolic links. | ||||