Export limit exceeded: 371997 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (371997 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-18188 1 Asustor 1 Adm 2026-07-30 N/A
A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsync backup configuration or log data may be processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected backup component. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
CVE-2026-16610 2 Wordpress, Wpase 2 Wordpress, Admin And Site Enhancements 2026-07-30 9.8 Critical
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no authentication check, CAPTCHA validation is bypassable by omitting an attacker-supplied key, and repeater row keys from cfgroup[input] are stored verbatim and later spliced into an eval() call in recursive_html without any sanitization or identifier validation. This makes it possible for unauthenticated attackers to execute code on the server. This requires the [post_cf_form] shortcode to be present on at least one publicly accessible page, as the nonce and session ID needed to reach the vulnerable save handler are emitted to unauthenticated visitors by that shortcode.
CVE-2026-12500 2 Wordpress, Wptravelengine 2 Wordpress, Wp Travel Engine 2026-07-30 N/A
The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before 6.8.2 option (the public nonce that gates the action is served to anonymous visitors).
CVE-2026-13330 2 Wealcoder, Wordpress 2 Animation Addons For Elementor, Wordpress 2026-07-30 6.1 Medium
The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with the upload_files capability (Author and above) to upload files containing malicious JavaScript, leading to Stored Cross-Site Scripting.
CVE-2026-13344 2 Wordpress, Wpdevteam 2 Wordpress, Essential Addons For Elementor 2026-07-30 4.8 Medium
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed, including in the session of an administrator previewing or visiting the post.
CVE-2026-13345 2 Wordpress, Wpdevteam 2 Wordpress, Essential Addons For Elementor 2026-07-30 N/A
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price, and SKU of draft, pending, and private products that are otherwise withheld from public view.
CVE-2026-14310 2 Tutorlms, Wordpress 2 Tutor Lms Pro, Wordpress 2026-07-30 5.4 Medium
The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread belongs to before returning or writing to that thread, allowing authenticated users with subscriber-level access and above who can access any single course to read the Q&A threads of other courses and to inject replies into them.
CVE-2026-58040 1 Nodejs 1 Nodejs 2026-07-30 N/A
An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
CVE-2026-56850 1 Nodejs 1 Nodejs 2026-07-30 N/A
A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
CVE-2026-58043 1 Nodejs 1 Nodejs 2026-07-30 N/A
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.
CVE-2026-56847 1 Nodejs 1 Nodejs 2026-07-30 N/A
A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
CVE-2026-16969 1 Dfir-iris 1 Iris 2026-07-30 7.6 High
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function.
CVE-2026-18360 1 Dfir-iris 1 Iris 2026-07-30 7.6 High
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.
CVE-2026-18361 1 Dfir-iris 1 Iris 2026-07-30 7.6 High
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.
CVE-2026-16971 1 Dfir-iris 1 Iris 2026-07-30 5.9 Medium
The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.
CVE-2026-18362 1 Dfir-iris 1 Iris 2026-07-30 5.9 Medium
The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.
CVE-2026-16970 1 Dfir-iris 1 Iris 2026-07-30 4.2 Medium
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.
CVE-2026-54364 1 Gladinet 1 Centrestack 2026-07-30 6.5 Medium
CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inject arbitrary session variables by embedding newline and tab characters into a crafted AccountName parameter posted to the SelectProvider.aspx endpoint. Attackers can exploit the lack of input sanitization in the custom session serialization format to inject a resellerid session variable, bypassing the IsValidRSession authentication check and gaining unauthorized access to management pages.
CVE-2026-54365 1 Gladinet 1 Centrestack 2026-07-30 7.5 High
CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a malicious StorageConfigure parameter to the jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn endpoints to trigger InternalImportAdUserByUPN(), causing GladinetCloudMonitor.exe to invoke the NetUserAdd Windows API with attacker-controlled credentials and create arbitrary directories on the server filesystem.
CVE-2026-54366 1 Gladinet 1 Centrestack 2026-07-30 7.5 High
CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary files by supplying a malicious URL to the SharePoint storage configuration handler. Attackers can send a crafted request to the unauthenticated StorageConfig endpoint causing the server to fetch and parse attacker-controlled XML containing external DTD references, resulting in out-of-band file exfiltration of sensitive files such as Web.config, which may contain database credentials and cryptographic key material.