Export limit exceeded: 372965 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 372965 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372965 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-14239 | 2 Tourmaster, Wordpress | 2 Tourmaster, Wordpress | 2026-08-04 | N/A |
| The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken from a request parameter, and does not escape that label when echoing it on the filter admin page, allowing an unauthenticated attacker to trick a logged-in administrator into storing JavaScript that then executes in the admin area (stored Cross-Site Scripting via CSRF). | ||||
| CVE-2026-14305 | 2 Wordpress, Wpdelicious | 2 Wordpress, Wp Delicious | 2026-08-04 | N/A |
| The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to modify limited post metadata (a like counter and an associated identifier list) on arbitrary posts, including inflating the counter and growing the stored metadata without bound. | ||||
| CVE-2026-58043 | 1 Nodejs | 1 Nodejs | 2026-08-04 | N/A |
| A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**. | ||||
| CVE-2026-22620 | 1 Eaton | 1 Padm | 2026-08-04 | 8.6 High |
| Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device. | ||||
| CVE-2026-22621 | 1 Eaton | 1 Padm | 2026-08-04 | 8.3 High |
| Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment. | ||||
| CVE-2026-56428 | 1 Bosch | 1 Bsh Elp (electronic Platform) Modules | 2026-08-04 | 8.1 High |
| The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in possession of the corresponding private key could leverage it to bypass authentication and gain root-level access to the appliance. | ||||
| CVE-2026-60007 | 2026-08-04 | N/A | ||
| In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession` requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials. | ||||
| CVE-2026-15978 | 1 Sglang | 1 Sglang | 2026-08-04 | 7.5 High |
| SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data transfer, attackers can exfiltrate all model weights. | ||||
| CVE-2026-14847 | 2 Cozmoslabs, Wordpress | 2 Paid Membership Subscriptions, Wordpress | 2026-08-04 | 4.3 Medium |
| The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its payment-related AJAX actions, allowing any authenticated user with Subscriber-level access and above to disclose the payment details of any member by enumerating the payment identifier. | ||||
| CVE-2026-14921 | 2026-08-04 | N/A | ||
| The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_VC_Addons::uavc_link_init(), | ||||
| CVE-2026-13325 | 1 Redhat | 1 Openshift Virtualization | 2026-08-04 | 8.5 High |
| Red Hat Product Security has come to the conclusion that this CVE is not needed. | ||||
| CVE-2026-14931 | 2026-08-04 | 6.5 Medium | ||
| The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check on a user-listing handler, allowing Contributor-level users to enumerate the email addresses of all registered WordPress users. | ||||
| CVE-2026-15258 | 2026-08-04 | 8.1 High | ||
| The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks. | ||||
| CVE-2026-14862 | 2026-08-04 | 3.7 Low | ||
| The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file name to download other users' private ticket attachments. | ||||
| CVE-2026-16105 | 1 Redhat | 8 Build Keycloak, Build Of Keycloak, Data Grid and 5 more | 2026-08-04 | 4.9 Medium |
| A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm. | ||||
| CVE-2026-16843 | 1 Hikvision | 6 Ds-3wap521-si, Ds-3wap522-si, Ds-3wap621e-si and 3 more | 2026-08-04 | 7.2 High |
| Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution. | ||||
| CVE-2026-14315 | 2026-08-04 | 6.5 Medium | ||
| The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side advertising conversion APIs using the site's stored credentials. | ||||
| CVE-2026-14920 | 2 Acymailing, Wordpress | 2 Acymailing, Wordpress | 2026-08-04 | N/A |
| ## Summary | ||||
| CVE-2026-16291 | 2 Profilegrid, Wordpress | 2 Profilegrid, Wordpress | 2026-08-04 | N/A |
| The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers. | ||||
| CVE-2026-52102 | 2026-08-04 | N/A | ||
| An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters. | ||||