Export limit exceeded: 395608 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (395608 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-17542 | 2 Filemanagerpro, Wordpress | 2 File Manager, Wordpress | 2026-08-11 | 7.5 High |
| The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data. | ||||
| CVE-2026-19053 | 2 Prosolution, Wordpress | 2 Prosolution Wp Client, Wordpress | 2026-08-11 | 9.1 Critical |
| The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection. | ||||
| CVE-2026-57279 | 1 Cybozu | 1 Cybozu Garoon | 2026-08-11 | N/A |
| Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of a user logged in to the product. | ||||
| CVE-2026-21084 | 1 Samsung | 1 Smartthings | 2026-08-11 | N/A |
| Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information. | ||||
| CVE-2026-72577 | 1 Nasa | 1 Fprime | 2026-08-11 | 9.8 Critical |
| Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask application in src/fprime_gds/flask/app.py applies no authentication to any endpoint. | ||||
| CVE-2026-59686 | 1 Progress | 6 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster and 3 more | 2026-08-11 | 8.4 High |
| An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise. | ||||
| CVE-2026-59687 | 1 Progress | 6 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster and 3 more | 2026-08-11 | 8.4 High |
| An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise. | ||||
| CVE-2026-59688 | 1 Progress | 6 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster and 3 more | 2026-08-11 | 8.4 High |
| An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise. | ||||
| CVE-2026-59689 | 1 Progress | 6 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster and 3 more | 2026-08-11 | 8 High |
| An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise. | ||||
| CVE-2026-72748 | 1 Wwbn | 1 Avideo | 2026-08-11 | 9.1 Critical |
| AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authentication. Attackers can exhaust disk space causing denial of service, poison the video encoding pipeline, or chain this with local file inclusion to achieve remote code execution. | ||||
| CVE-2026-59690 | 2 Process Software, Progress | 8 Multi Tenant, Connection Manager For Objectscale, Ecs Connection Manager and 5 more | 2026-08-11 | 8 High |
| A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise. | ||||
| CVE-2026-2299 | 1 Mattermost | 2 Google Drive, Mattermost Google Drive Plugin | 2026-08-11 | 4.2 Medium |
| The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership. | ||||
| CVE-2026-72781 | 1 Craftcms | 1 Craft Cms | 2026-08-11 | 8.8 High |
| Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in the Twig sandbox mechanism. Because Craft marks the ElementInterface as safe (via the AllowedInSandbox attribute) and the sandbox allowlisting extends to the entire class hierarchy (craft\base\Component up to yii\base\Component), an authenticated attacker with permission to access the control panel can render a malicious Twig template that abuses the yii\base\Component arbitrary function-call gadget to execute arbitrary code, even when the Twig sandbox is enabled via enableTwigSandbox(). | ||||
| CVE-2026-18478 | 1 Magnolia-cms | 1 Magnolia Cms | 2026-08-11 | N/A |
| Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed when opening uploaded image. The issue was fixed in version 6.3.10 | ||||
| CVE-2026-15059 | 1 Systemd | 1 Systemd | 2026-08-11 | 5.5 Medium |
| Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation. | ||||
| CVE-2026-16742 | 1 Systemd | 1 Systemd | 2026-08-11 | 6.7 Medium |
| systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user | ||||
| CVE-2026-56620 | 1 Hcltech | 1 Bigfix Mobile | 2026-08-11 | 4.3 Medium |
| HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error reporting. | ||||
| CVE-2026-56619 | 1 Hcltech | 1 Bigfix Mobile | 2026-08-11 | 5.4 Medium |
| HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and output encoding of user-controlled input. | ||||
| CVE-2026-72914 | 1 Joinmastodon | 1 Mastodon | 2026-08-11 | 7.5 High |
| Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative statistics endpoints handled by Api::V1::Admin::MeasuresController and Api::V1::Admin::RetentionController checked authorization only after beginning expensive calculations. Anonymous callers could submit keys, start_at, and end_at parameters that caused long-running SQL queries in Admin::Metrics::Measure, Admin::Metrics::Retention, and Admin::Metrics::Dimension::BaseDimension, allowing repeated requests to exhaust server resources. This issue is fixed in versions 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1. | ||||
| CVE-2026-72916 | 1 Joinmastodon | 1 Mastodon | 2026-08-11 | N/A |
| Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, PrivateAddressCheck.private_address? in app/lib/private_address_check.rb normalized IPv4-mapped IPv6 addresses but did not recognize IPv4-compatible IPv6 addresses with IPAddr#ipv4_compat?. An attacker could supply an address in the omitted range to bypass the ALLOWED_PRIVATE_ADDRESSES protection and make Mastodon send HTTP requests to loopback interfaces, potentially accessing private resources and services. Exploitation requires a system that supports the obsolete IPv4-compatible IPv6 mechanism. This issue is fixed in versions 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1. | ||||