Export limit exceeded: 374188 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (374188 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16731 | 2 Omicron Electronics, Omicron Electronics Gmbh | 2 Omicron Stationscout, Omicron Stationscout | 2026-08-07 | N/A |
| OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients. An attacker can gain full access to the system configuration, allowing modification, reset, or unauthorized alteration of system parameters or injecting network traffic into the connected network. | ||||
| CVE-2026-5134 | 1 Loca Software Informatics Technology | 1 Cms | 2026-08-07 | 9.8 Critical |
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-64993 | 1 Dell | 1 Rvtools | 2026-08-07 | 6.8 Medium |
| Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity. | ||||
| CVE-2026-54489 | 1 Dell | 1 Virtual Storage Integrator For Vmware Vsphere Client | 2026-08-07 | 9.1 Critical |
| Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity. | ||||
| CVE-2026-53975 | 1 Bohdan Triapitsyn | 1 Openchamber | 2026-08-07 | 9.8 Critical |
| OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response. | ||||
| CVE-2026-53976 | 1 Bohdan Triapitsyn | 1 Openchamber | 2026-08-07 | 9.1 Critical |
| OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPathWithinRoot guard to read sensitive files such as the JWT signing secret, SSH private keys, API credentials, and environment variables, enabling full authentication bypass by forging session cookies on password-protected deployments. | ||||
| CVE-2026-28141 | 2 Syed Balkhi, Wordpress | 2 Nextgen Gallery, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions. | ||||
| CVE-2026-28172 | 2 Data443 Risk Mitigation, Inc., Wordpress | 2 Tracking Code Manager, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions. | ||||
| CVE-2026-28177 | 2 Daniel Iser, Wordpress | 2 Popup Maker, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions. | ||||
| CVE-2026-28179 | 2 Damian Góra, Wordpress | 2 Fibosearch, Wordpress | 2026-08-07 | 5.9 Medium |
| Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions. | ||||
| CVE-2026-32469 | 2 Wordpress, Wpkube | 2 Wordpress, Captcha 4wp | 2026-08-07 | 5.3 Medium |
| Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions. | ||||
| CVE-2026-65504 | 2 Ivanbebek, Wordpress | 2 Box Now Delivery Croatia, Wordpress | 2026-08-07 | 7.5 High |
| Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions. | ||||
| CVE-2026-65517 | 2 Scott Paterson, Wordpress | 2 Easy Paypal Buy Now Button, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions. | ||||
| CVE-2026-65523 | 2 Approveme, Wordpress | 2 Formidable Forms Signature Online Contract Automation, Wordpress | 2026-08-07 | 7.5 High |
| Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions. | ||||
| CVE-2026-65541 | 2 Solutioned, Wordpress | 2 Staff Training, Wordpress | 2026-08-07 | 7.3 High |
| Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions. | ||||
| CVE-2026-65542 | 2 Rajat Varlani, Wordpress | 2 Super Socializer, Wordpress | 2026-08-07 | 8.8 High |
| Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions. | ||||
| CVE-2026-65543 | 2 Vimeodev, Wordpress | 2 Vimeo, Wordpress | 2026-08-07 | 7.5 High |
| Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions. | ||||
| CVE-2026-65544 | 2 Rajat Varlani, Wordpress | 2 Super Socializer, Wordpress | 2026-08-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions. | ||||
| CVE-2026-65546 | 2 Qode, Wordpress | 2 Qode Tours, Wordpress | 2026-08-07 | 9.3 Critical |
| Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions. | ||||
| CVE-2026-65553 | 2 Wbolt.com, Wordpress | 2 Spider Analyser – Wordpress搜索引擎蜘蛛分析插件, Wordpress | 2026-08-07 | 10 Critical |
| Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions. | ||||