Export limit exceeded: 371966 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (371966 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-18187 | 1 Asustor | 1 Adm | 2026-07-30 | N/A |
| A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be included in an error response and processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected CGI process. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81. | ||||
| CVE-2026-18188 | 1 Asustor | 1 Adm | 2026-07-30 | N/A |
| A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsync backup configuration or log data may be processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected backup component. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81. | ||||
| CVE-2026-16610 | 2 Wordpress, Wpase | 2 Wordpress, Admin And Site Enhancements | 2026-07-30 | 9.8 Critical |
| The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no authentication check, CAPTCHA validation is bypassable by omitting an attacker-supplied key, and repeater row keys from cfgroup[input] are stored verbatim and later spliced into an eval() call in recursive_html without any sanitization or identifier validation. This makes it possible for unauthenticated attackers to execute code on the server. This requires the [post_cf_form] shortcode to be present on at least one publicly accessible page, as the nonce and session ID needed to reach the vulnerable save handler are emitted to unauthenticated visitors by that shortcode. | ||||
| CVE-2026-15252 | 2 Search Atlas Group, Wordpress | 2 Search Atlas Seo, Wordpress | 2026-07-30 | N/A |
| The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX handlers, allowing any authenticated user such as a Subscriber to invoke the site's Google Indexing API integration, submitting or removing the site's URLs from Google's index and consuming its indexing quota. | ||||
| CVE-2026-15382 | 2 Unitecms, Wordpress | 2 Unlimited Addons For Wpbakery Page Builder, Wordpress | 2026-07-30 | N/A |
| The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request. | ||||
| CVE-2026-11782 | 2 Wordpress, Wpswings | 2 Wordpress, Points And Rewards For Woocommerce | 2026-07-30 | N/A |
| The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being changed, allowing unauthenticated attackers to arbitrarily modify or corrupt (including driving it negative) the stored wallet balance and loyalty points of any user. Modifying the wallet balance additionally requires the companion Wallet System for WooCommerce Points and Rewards for WooCommerce WordPress plugin before 2.10.1 to be active. | ||||
| CVE-2026-12500 | 2 Wordpress, Wptravelengine | 2 Wordpress, Wp Travel Engine | 2026-07-30 | N/A |
| The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before 6.8.2 option (the public nonce that gates the action is served to anonymous visitors). | ||||
| CVE-2026-13330 | 2 Wealcoder, Wordpress | 2 Animation Addons For Elementor, Wordpress | 2026-07-30 | 6.1 Medium |
| The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, allowing users with the upload_files capability (Author and above) to upload files containing malicious JavaScript, leading to Stored Cross-Site Scripting. | ||||
| CVE-2026-13344 | 2 Wordpress, Wpdevteam | 2 Wordpress, Essential Addons For Elementor | 2026-07-30 | 4.8 Medium |
| The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed, including in the session of an administrator previewing or visiting the post. | ||||
| CVE-2026-13345 | 2 Wordpress, Wpdevteam | 2 Wordpress, Essential Addons For Elementor | 2026-07-30 | N/A |
| The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCommerce products in its product-comparison feature, allowing unauthenticated users to disclose the title, price, and SKU of draft, pending, and private products that are otherwise withheld from public view. | ||||
| CVE-2026-14310 | 2 Tutorlms, Wordpress | 2 Tutor Lms Pro, Wordpress | 2026-07-30 | 5.4 Medium |
| The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread belongs to before returning or writing to that thread, allowing authenticated users with subscriber-level access and above who can access any single course to read the Q&A threads of other courses and to inject replies into them. | ||||
| CVE-2026-58040 | 1 Nodejs | 1 Nodejs | 2026-07-30 | N/A |
| An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**. | ||||
| CVE-2026-56850 | 1 Nodejs | 1 Nodejs | 2026-07-30 | N/A |
| A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**. | ||||
| CVE-2026-58043 | 1 Nodejs | 1 Nodejs | 2026-07-30 | N/A |
| A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**. | ||||
| CVE-2026-56847 | 1 Nodejs | 1 Nodejs | 2026-07-30 | N/A |
| A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**. | ||||
| CVE-2026-16969 | 1 Dfir-iris | 1 Iris | 2026-07-30 | 7.6 High |
| The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function. | ||||
| CVE-2026-18360 | 1 Dfir-iris | 1 Iris | 2026-07-30 | 7.6 High |
| The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function. | ||||
| CVE-2026-18361 | 1 Dfir-iris | 1 Iris | 2026-07-30 | 7.6 High |
| The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function. | ||||
| CVE-2026-16971 | 1 Dfir-iris | 1 Iris | 2026-07-30 | 5.9 Medium |
| The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks. | ||||
| CVE-2026-18362 | 1 Dfir-iris | 1 Iris | 2026-07-30 | 5.9 Medium |
| The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks. | ||||