Export limit exceeded: 372706 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 372706 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372706 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-14864 | 2026-08-02 | N/A | ||
| The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the context of higher-privileged users such as administrators. | ||||
| CVE-2026-15929 | 1 Lg Electronics | 1 Smartshare | 2026-08-02 | N/A |
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection. This issue affects SmartShare: through 2.3.1712.1202, which is supported on Microsoft Windows 10 and earlier versions. | ||||
| CVE-2026-16727 | 1 Asus | 1 Armoury Crate | 2026-08-02 | N/A |
| Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement. Refer to the ' Security Update for ASUS Armoury Crate ' section on the ASUS Security Advisory for more information. | ||||
| CVE-2026-16527 | 1 Redhat | 3 Enterprise Linux, Openshift, Openshift Container Platform | 2026-08-02 | 7.3 High |
| An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover. | ||||
| CVE-2026-58046 | 1 Webpros | 1 Plesk | 2026-08-02 | 9.9 Critical |
| Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel. | ||||
| CVE-2026-58066 | 1 Rocket.chat | 1 Rocket.chat | 2026-08-02 | N/A |
| Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity attributes alongside any valid signature made by the trusted IdP certificate, and log in as an arbitrary user. | ||||
| CVE-2026-15971 | 1 Sglang | 1 Sglang | 2026-08-02 | 9.8 Critical |
| SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on inference requests. | ||||
| CVE-2026-38711 | 2026-08-02 | N/A | ||
| TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the system.upgrade_check interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input. | ||||
| CVE-2026-50986 | 2026-08-02 | N/A | ||
| PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validation controller has no CSRF token. An attacker can confirm an order in an awaiting status by hijacking a link. | ||||
| CVE-2026-51785 | 2026-08-02 | N/A | ||
| An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request | ||||
| CVE-2026-52134 | 1 Mz-automation | 1 Libiec61850 | 2026-08-02 | N/A |
| An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame. | ||||
| CVE-2026-52232 | 2026-08-02 | N/A | ||
| A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build 118101 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL. | ||||
| CVE-2026-14921 | 2026-08-02 | N/A | ||
| The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_VC_Addons::uavc_link_init(), | ||||
| CVE-2026-58047 | 1 Webpros | 2 Cpanel, Wp Squared | 2026-08-02 | N/A |
| HTTP Smuggling in cPanel allows potential leak of credentials. | ||||
| CVE-2026-58048 | 1 Webpros | 2 Cpanel, Wp Squared | 2026-08-02 | N/A |
| Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. | ||||
| CVE-2026-15932 | 2026-08-02 | N/A | ||
| The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download route, allowing unauthenticated attackers to read arbitrary files with an allowlisted extension — including other users' private ticket attachments — from the server. | ||||
| CVE-2025-15669 | 2 Bit Form, Wordpress | 2 Bit Form, Wordpress | 2026-08-02 | N/A |
| The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as administrators, who do not hold the unfiltered_html capability on multisite) to store JavaScript that executes in the browser of any visitor who views the form. | ||||
| CVE-2026-12966 | 2026-08-02 | N/A | ||
| The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted WooCommerce order in several unauthenticated AJAX handlers before changing its status and overwriting its payment metadata, allowing unauthenticated attackers to tamper with other customers' orders, including forging a "payment sent" state, overwriting the payment-method label, and attaching forged payment-proof files. | ||||
| CVE-2026-14309 | 2026-08-02 | N/A | ||
| The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS one-time-password password reset is enabled. | ||||
| CVE-2026-14596 | 2026-08-02 | N/A | ||
| The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the base of the password-reset link it emails, allowing unauthenticated attackers to send a target user a legitimately-formatted reset email whose link points to an attacker-controlled host and carries a valid reset key, leading to account takeover when the victim clicks it. | ||||