Export limit exceeded: 374136 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (374136 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-13154 2026-08-06 7.5 High
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public.
CVE-2026-61961 2 Wordpress, Wpdeveloper 2 Wordpress, Embedpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
CVE-2026-66708 2 Boldgrid, Wordpress 2 Total Upkeep, Wordpress 2026-08-06 8.2 High
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
CVE-2026-66709 2 Webappick, Wordpress 2 Ctx Feed, Wordpress 2026-08-06 9.1 Critical
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
CVE-2026-66710 2 E2pdf, Wordpress 2 E2pdf, Wordpress 2026-08-06 8.1 High
Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.
CVE-2026-28178 2 Codesupplyco, Wordpress 2 Powerkit, Wordpress 2026-08-06 6.5 Medium
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
CVE-2026-32548 2 Surecart, Wordpress 2 Surecart, Wordpress 2026-08-06 5.3 Medium
Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
CVE-2026-7406 1 Autodesk 3 Autocad, Autocad Lt, Revit 2026-08-06 7.8 High
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
CVE-2026-7405 1 Autodesk 3 Autocad, Autocad Lt, Revit 2026-08-06 5.5 Medium
A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service
CVE-2026-61982 2 Jp-secure, Wordpress 2 Siteguard Wp Plugin, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
CVE-2026-65509 2 Wordpress, Wpdatatables 2 Wordpress, Wpdatatables 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
CVE-2026-19023 2026-08-06 N/A
Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.3.0 allows attackers to cause a denial of service via a variable-length string dataset with more than one element dumped in binary mode, which corrupts the per-element stride calculation and causes subsequent elements to be read from a misaligned offset and dereferenced as a pointer.
CVE-2026-65572 2026-08-06 9.8 Critical
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
CVE-2026-66665 2026-08-06 10 Critical
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
CVE-2026-18359 2026-08-06 8.5 High
Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metadata service, via the mets_uri or iiif_uri parameter of POST /api/documents/{pk}/imports/, because the IMPORT_ALLOWED_DOMAINS setting defaults to '*' and no address filtering, redirect cap or timeout is applied
CVE-2026-65573 2 Themerex, Wordpress 2 Abelle, Wordpress 2026-08-06 9.8 Critical
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
CVE-2026-66439 2 Berocket, Wordpress 2 Advanced Ajax Product Filters, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.
CVE-2026-19061 1 Insta 1 Instaknxserviceapp 2026-08-06 3.7 Low
A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a manipulation can lead to insufficient verification of data authenticity. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation is known to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-65545 2 Jordy Meow, Wordpress 2 Ai-engine, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.
CVE-2026-65560 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.