Export limit exceeded: 97877 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (97877 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66667 | 2 Wordpress, Wpdeveloper | 2 Wordpress, Templately | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions. | ||||
| CVE-2026-73345 | 2 Saad Iqbal, Wordpress | 2 License Manager For Woocommerce, Wordpress | 2026-08-24 | 7.1 High |
| Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions. | ||||
| CVE-2026-78180 | 2 Alibaba-fusion, Next | 2 Next, Next | 2026-08-24 | 7.3 High |
| A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly controlled modification of object prototype attributes. The attack may be initiated remotely. The reported GitHub issue was closed automatically due to inactivity. | ||||
| CVE-2026-78212 | 1 4mosan Security Technology | 1 4mosan Management Center | 2026-08-24 | 7.5 High |
| 4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Relative Path Traversal flaw to download arbitrary system files. | ||||
| CVE-2026-66599 | 2 Liquid Web / Stellarwp, Wordpress | 2 Wpcomplete, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions. | ||||
| CVE-2026-66671 | 2 Elated-themes, Wordpress | 2 Verdure Core, Wordpress | 2026-08-24 | 8.1 High |
| Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions. | ||||
| CVE-2026-28153 | 2 Notification Master, Wordpress | 2 Notification Master – Real-time Wordpress Notifications With Email, Sms, Webhooks & More, Wordpress | 2026-08-24 | 7.5 High |
| Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More <= 1.7.1 versions. | ||||
| CVE-2026-28171 | 2 Vanquish, Wordpress | 2 Woocommerce File Approval, Wordpress | 2026-08-24 | 8.6 High |
| Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions. | ||||
| CVE-2026-28190 | 2 Themebing, Wordpress | 2 Prolancer Element, Wordpress | 2026-08-24 | 7.1 High |
| Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions. | ||||
| CVE-2026-32471 | 2 Themebing, Wordpress | 2 Prolancer Element, Wordpress | 2026-08-24 | 8.5 High |
| Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions. | ||||
| CVE-2026-32476 | 2 Amplebyte Pvt Limited, Wordpress | 2 Brave Conversion Engine (pro), Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions. | ||||
| CVE-2026-66585 | 2 Wordpress, Wpcafe | 2 Wordpress, Wp Cafe Pro | 2026-08-24 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions. | ||||
| CVE-2026-66670 | 2 Elated-themes, Wordpress | 2 Måne, Wordpress | 2026-08-24 | 8.1 High |
| Unauthenticated Local File Inclusion in Måne <= 1.7 versions. | ||||
| CVE-2026-21756 | 1 Hcltech | 1 Hive | 2026-08-24 | 7.2 High |
| HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments. | ||||
| CVE-2026-76842 | 1 Mercadopago | 1 Mercadopago | 2026-08-24 | 8.2 High |
| The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding them, so characters that are structural in a URL survive into the outgoing request. The payment (get, capture, cancel), paymentRefund (create, total, list, get), advancedPayment (get, capture, cancel, update, updateReleaseDate) and disbursementRefund (create, createAll, listAll) clients build their path as a template literal, for example RestClient.fetch(`/v1/payments/${id}`, ...) in src/clients/payment/get/index.ts. A dot-dot or slash sequence in the identifier is normalised by the WHATWG URL parser and redirects the request to a different endpoint, and a question mark appends attacker-chosen query parameters, in both cases carrying the merchant's own access token. An application that forwards an identifier influenced by an untrusted party into one of these methods without an ownership check therefore allows that party to reach other resources within the merchant's token scope. The repository already contains the intended helper, encodePathParam in src/utils/path.ts, which pull request 451 applied to roughly 29 other clients while leaving these unchanged. | ||||
| CVE-2026-21751 | 1 Hcltech | 1 Hive | 2026-08-24 | 7.4 High |
| HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized lateral compromise or widespread credential leakage if a single internal component is breached. | ||||
| CVE-2026-71907 | 1 Draytek | 12 Vigorap 1060c, Vigorap 1060c Firmware, Vigorap 903 and 9 more | 2026-08-24 | 7.2 High |
| Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability is caused by insufficient filtering of the selectSlaves field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface. | ||||
| CVE-2026-71909 | 1 Draytek | 12 Vigorap 1060c, Vigorap 1060c Firmware, Vigorap 903 and 9 more | 2026-08-24 | 7.2 High |
| Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface. | ||||
| CVE-2026-71912 | 1 Draytek | 12 Vigorap 1060c, Vigorap 1060c Firmware, Vigorap 903 and 9 more | 2026-08-24 | 7.2 High |
| Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is caused by missing length checks during memory copy operations involving the CMD6 field. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface. | ||||
| CVE-2026-70863 | 1 Oracle | 1 Application Testing Suite | 2026-08-24 | 8.8 High |
| Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTPS to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). | ||||