Export limit exceeded: 48757 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (48757 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-41122 | 1 Dell | 2 Data Domain Operating System, Powerprotect Data Domain | 2026-08-03 | 7.1 High |
| Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain a stored cross-site scripting vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability. Exploitation may lead to information disclosure, session theft, or client-side request forgery. | ||||
| CVE-2026-15127 | 1 Google | 1 Chrome | 2026-08-03 | 6.1 Medium |
| Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-47831 | 1 Cloudfoundry | 1 Bosh-windows-stemcell-builder | 2026-08-03 | N/A |
| Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attacker to brute-force the resulting SSH login via TCP/22. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98. | ||||
| CVE-2026-50758 | 1 Dayuanjiang | 1 Next-ai-draw-io | 2026-08-03 | 8.1 High |
| Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter | ||||
| CVE-2026-60634 | 1 Oracle | 1 Webcenter Content | 2026-08-02 | 8.8 High |
| Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). | ||||
| CVE-2026-60637 | 1 Oracle | 1 Webcenter Content | 2026-08-02 | 8.8 High |
| Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). | ||||
| CVE-2024-32387 | 1 Kerlink | 1 Wirnet Istation 868 Keros | 2026-08-02 | 5.7 Medium |
| An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the community string component. | ||||
| CVE-2026-12978 | 2 Funnelkit, Wordpress | 2 Funnelkit, Wordpress | 2026-08-02 | 7.1 High |
| The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX actions, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against logged-in users who open a crafted page. The affected action is only registered when the Divi /builder is active. | ||||
| CVE-2026-15794 | 2 Berocket, Wordpress | 2 Grid/list View For Woocommerce, Wordpress | 2026-08-02 | 6.4 Medium |
| The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The shortcode's all_page="1" attribute can be used to force the widget to render on any page, expanding the attack surface beyond shop and category pages. | ||||
| CVE-2026-57373 | 2 Wisetr, Wordpress | 2 Funnel Kit Funnel Builder Pro, Wordpress | 2026-08-02 | 6.5 Medium |
| Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions. | ||||
| CVE-2026-57374 | 2 Wisetr, Wordpress | 2 Funnel Kit Funnel Builder Pro, Wordpress | 2026-08-02 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions. | ||||
| CVE-2026-65514 | 2 Codepeople, Wordpress | 2 Appointment Hour Booking, Wordpress | 2026-08-02 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions. | ||||
| CVE-2026-65518 | 2 Scott Paterson, Wordpress | 2 Accept Donations With Paypal & Stripe, Wordpress | 2026-08-02 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions. | ||||
| CVE-2026-15665 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluent Support – Helpdesk & Customer Support Ticket System | 2026-08-02 | 6.4 Medium |
| The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The XSS payload is in a hidden attribute so it only fires in specific browsers when specific access keys are used making exploitation unlikely. | ||||
| CVE-2026-15739 | 2 Widgetpack, Wordpress | 2 Rich Showcase For Google Reviews, Wordpress | 2026-08-02 | 6.4 Medium |
| The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and including, 6.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-13605 | 2 Photoswipe, Wordpress | 2 Photoswipe, Wordpress | 2026-08-02 | 6.8 Medium |
| The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping. Because the title attribute survives the post-content sanitization applied to users who lack the unfiltered_html capability, an authenticated user with Author-level access can store a JavaScript payload that executes in the browser of any visitor, including an administrator, who clicks the link. | ||||
| CVE-2026-14234 | 2 Wolf, Wordpress | 2 Wolf, Wordpress | 2026-08-02 | 7.1 High |
| The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker to trick a logged-in administrator into writing arbitrary content, including a malicious script, into a post via a cross-site request, resulting in stored Cross-Site Scripting. | ||||
| CVE-2026-18452 | 1 Rich Source | 1 Dms+ (non-mobile) | 2026-08-02 | 10 Critical |
| DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices. | ||||
| CVE-2026-65313 | 1 Andritz | 2 250 Scala, Hipase-250 | 2026-08-02 | 8.1 High |
| A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations. | ||||
| CVE-2026-34495 | 2 Johnson Controls, Johnsoncontrols | 3 Fm Systems Employee, Fm Systems Employee, Fms Employee | 2026-08-02 | 5.4 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: before 2025.3.1. | ||||