Export limit exceeded: 380224 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 380224 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (380224 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-74004 | 2026-08-18 | 5.4 Medium | ||
| Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions. | ||||
| CVE-2026-73997 | 2026-08-18 | 7.5 High | ||
| Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. | ||||
| CVE-2026-73996 | 2026-08-18 | 9.8 Critical | ||
| Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. | ||||
| CVE-2026-73994 | 2026-08-18 | 7.5 High | ||
| Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. | ||||
| CVE-2026-73522 | 2026-08-18 | 7.5 High | ||
| COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to write past the end of a fixed 15-slot stack array by sending a crafted UDP datagram containing more than 15 ACF-CAN messages. The avtp_to_can() function increments its write index without bounding it against the caller-supplied array size, and because the listener accepts datagrams from any sender matching a hardcoded unauthenticated stream ID transmitted in plaintext, attackers can corrupt adjacent stack memory to achieve arbitrary code execution or denial of service. | ||||
| CVE-2026-73424 | 1 Withastro | 1 Astro | 2026-08-18 | 6.5 Medium |
| Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/integrations/vercel/src/serverless/entrypoint.ts accepts x_astro_path for the public /_isr function based only on the x-vercel-isr header, allowing unauthenticated GET requests to render routes protected only by Vercel edge path rules or split edge middleware. This issue is fixed in 11.0.3. | ||||
| CVE-2026-73399 | 2026-08-18 | 6.5 Medium | ||
| Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. | ||||
| CVE-2026-73397 | 2026-08-18 | 9.8 Critical | ||
| Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. | ||||
| CVE-2026-73395 | 2026-08-18 | 6.5 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions. | ||||
| CVE-2026-73381 | 2026-08-18 | 9.1 Critical | ||
| Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. | ||||
| CVE-2026-73378 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions. | ||||
| CVE-2026-73376 | 2026-08-18 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. | ||||
| CVE-2026-73375 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions. | ||||
| CVE-2026-73359 | 2026-08-18 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions. | ||||
| CVE-2026-73345 | 2026-08-18 | 7.1 High | ||
| Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions. | ||||
| CVE-2026-73342 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions. | ||||
| CVE-2026-73338 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions. | ||||
| CVE-2026-73181 | 2026-08-18 | 7.5 High | ||
| Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions. | ||||
| CVE-2026-71518 | 1 Typemill | 1 Typemill | 2026-08-18 | 7.5 High |
| Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash prefixes, double slashes, or percent-encoded sequences to pass role-based restriction checks while the filesystem resolves the request to the protected file, enabling unauthorized file download without credentials. | ||||
| CVE-2026-68568 | 2026-08-18 | 6.3 Medium | ||
| Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions. | ||||