Export limit exceeded: 12100 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 369970 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (369970 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65525 | 2 Uxper, Wordpress | 2 Civi Framework, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions. | ||||
| CVE-2026-65534 | 2 Charlie Etienne, Wordpress | 2 Custom Links In Elementor Image Carousel, Wordpress | 2026-07-23 | 5.9 Medium |
| Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions. | ||||
| CVE-2026-65535 | 2 Takayuki Miyauchi, Wordpress | 2 Tinymce Templates, Wordpress | 2026-07-23 | 4.3 Medium |
| Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions. | ||||
| CVE-2026-65536 | 2 Mahdi Yousefi, Wordpress | 2 افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری), Wordpress | 2026-07-23 | 6.5 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions. | ||||
| CVE-2026-65537 | 2 Themeisle, Wordpress | 2 Cyr To Lat Reloaded – Transliteration Of Links And File Names, Wordpress | 2026-07-23 | 4.3 Medium |
| Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions. | ||||
| CVE-2026-65538 | 2 Nilo Velez, Wordpress | 2 Machete, Wordpress | 2026-07-23 | 5.9 Medium |
| Author Cross Site Scripting (XSS) in Machete <= 5.2 versions. | ||||
| CVE-2026-65539 | 2 Bimal Rekhadiya, Wordpress | 2 Kwayy Html Sitemap, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions. | ||||
| CVE-2026-65540 | 2 Metin Saraç, Wordpress | 2 Popup For Cf7 With Sweet Alert, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions. | ||||
| CVE-2026-65550 | 2 Wordpress, Wpshopmart | 2 Wordpress, Tabs | 2026-07-23 | 5.9 Medium |
| Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. | ||||
| CVE-2026-61945 | 2 Multivendorx, Wordpress | 2 Woocommerce Product Stock Alert, Wordpress | 2026-07-23 | 6.5 Medium |
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6. | ||||
| CVE-2026-65687 | 1 Bold Reports | 1 Standalone Report Designer | 2026-07-23 | 9.8 Critical |
| Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application. | ||||
| CVE-2026-65688 | 1 Bold Reports | 1 Standalone Report Designer | 2026-07-23 | 9.8 Critical |
| Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application. | ||||
| CVE-2026-65689 | 1 Bold Reports | 1 Standalone Report Designer | 2026-07-23 | 9.8 Critical |
| Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application. | ||||
| CVE-2026-16733 | 1 Bahmutov | 1 Find-cypress-specs | 2026-07-23 | 5.3 Medium |
| A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-65690 | 1 Bold Reports | 1 Standalone Report Designer | 2026-07-23 | 8.8 High |
| Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute arbitrary commands with high privileges on the server. | ||||
| CVE-2026-8287 | 1 Bizimhesap Information Systems Industry And Trade | 1 Online Pre-accounting Software | 2026-07-23 | 4.3 Medium |
| Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Allocation. This issue affects Online Pre-Accounting Software: through 17072026. | ||||
| CVE-2026-48530 | 1 Gfi Software | 1 Gfi Archiver | 2026-07-23 | 5.4 Medium |
| GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated attackers to inject arbitrary web script or HTML via the rule name and email criteria parameters to /Archiver/CategorizationPolicyWizard.aspx. The injected payload is stored by CategorizationPolicyWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the Classification Rules page. | ||||
| CVE-2026-48531 | 1 Gfi Software | 1 Gfi Archiver | 2026-07-23 | 5.4 Medium |
| GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/RetentionPolicyWizard.aspx. The injected payload is stored by RetentionPolicyWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the Retention and Spam Policies page. | ||||
| CVE-2026-48532 | 1 Gfi Software | 1 Gfi Archiver | 2026-07-23 | 5.4 Medium |
| GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/FAARetentionPolicyWizard.aspx. The injected payload is stored by RetentionPolicyWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the File History Retention Policies page. | ||||
| CVE-2026-48534 | 1 Gfi Software | 1 Gfi Archiver | 2026-07-23 | 5.4 Medium |
| GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the server URL parameter to /Archiver/ImapServerWizard.aspx. The injected payload is stored by ImapServerWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the IMAP Server configuration page. | ||||