Export limit exceeded: 385063 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (385063 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-82228 | 2026-08-31 | 8.1 High | ||
| Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions. | ||||
| CVE-2026-82226 | 2026-08-31 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions. | ||||
| CVE-2026-82225 | 2026-08-31 | 7.4 High | ||
| Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions. | ||||
| CVE-2026-82224 | 2026-08-31 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions. | ||||
| CVE-2026-82221 | 2026-08-31 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions. | ||||
| CVE-2026-81780 | 2026-08-31 | 10 Critical | ||
| Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. | ||||
| CVE-2026-81765 | 2026-08-31 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions. | ||||
| CVE-2026-81764 | 2026-08-31 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions. | ||||
| CVE-2026-81763 | 2026-08-31 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions. | ||||
| CVE-2026-81762 | 2026-08-31 | 6.5 Medium | ||
| Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions. | ||||
| CVE-2026-81758 | 2026-08-31 | 6.3 Medium | ||
| Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions. | ||||
| CVE-2026-81756 | 2026-08-31 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. | ||||
| CVE-2026-81298 | 2026-08-31 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions. | ||||
| CVE-2026-81293 | 2026-08-31 | 9.3 Critical | ||
| Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions. | ||||
| CVE-2026-81290 | 2026-08-31 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions. | ||||
| CVE-2026-81287 | 2026-08-31 | 8.5 High | ||
| Subscriber SQL Injection in Charitable <= 1.8.12.1 versions. | ||||
| CVE-2026-81280 | 2026-08-31 | 6.5 Medium | ||
| Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions. | ||||
| CVE-2026-54599 | 2026-08-31 | N/A | ||
| Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, login.php generates an OIDC state nonce stored in $_SESSION['oidc_state'], but checksession.php dispatches the OIDC callback without comparing the incoming state against the session value. An attacker can trick a victim into visiting a crafted URL, causing Wallos to exchange the attacker's authorization code and log the victim into the attacker's account. This issue has been patched in version 4.9.4. | ||||
| CVE-2025-63607 | 2026-08-31 | N/A | ||
| TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id parameter verbatim into the rendered page, permitting execution of attacker-supplied JavaScript in users browser. | ||||
| CVE-2026-82909 | 1 Quantumnous | 1 New-api | 2026-08-31 | 4.3 Medium |
| A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler. Executing a manipulation can lead to session expiration. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.0.0-rc.17 can resolve this issue. This patch is called 0d5995eb63f8801d32eb32fbe74b75b68752bfa9. The affected component should be upgraded. | ||||