Export limit exceeded: 379067 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (379067 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73062 | 1 Scriban | 1 Scriban | 2026-08-18 | 7.5 High |
| Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multiplier in a template to force multi-gigabyte memory allocations, causing resource exhaustion and availability degradation. | ||||
| CVE-2026-74955 | 1 Mozilla | 1 Firefox | 2026-08-18 | 8.8 High |
| Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. | ||||
| CVE-2026-73057 | 1 Stoatchat | 1 Stoatchat | 2026-08-18 | 7.5 High |
| stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger concurrent requests to exhaust available memory across proxy replicas. | ||||
| CVE-2026-19932 | 1 Defaultfuction | 1 Notice-system-managent | 2026-08-18 | 6.3 Medium |
| A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects the function GroovyShell.evaluate of the file /execute of the component NoticeController. The manipulation results in code injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project confirms, that "it’s being processed". | ||||
| CVE-2026-74015 | 2026-08-18 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Readabler < 2.0.18 versions. | ||||
| CVE-2026-74009 | 2026-08-18 | 5.3 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions. | ||||
| CVE-2026-74007 | 2026-08-18 | 5.3 Medium | ||
| Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions. | ||||
| CVE-2026-74006 | 2026-08-18 | 4.3 Medium | ||
| Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions. | ||||
| CVE-2026-74003 | 2026-08-18 | 4.3 Medium | ||
| Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions. | ||||
| CVE-2026-73996 | 2026-08-18 | 9.8 Critical | ||
| Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. | ||||
| CVE-2026-73995 | 2026-08-18 | 5.4 Medium | ||
| Subscriber Broken Authentication in User Registration <= 5.2.6 versions. | ||||
| CVE-2026-73404 | 2026-08-18 | 6.5 Medium | ||
| Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. | ||||
| CVE-2026-73399 | 2026-08-18 | 6.5 Medium | ||
| Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. | ||||
| CVE-2026-73398 | 2026-08-18 | 6.5 Medium | ||
| Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. | ||||
| CVE-2026-73396 | 2026-08-18 | 7.1 High | ||
| Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. | ||||
| CVE-2026-73393 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions. | ||||
| CVE-2026-73392 | 2026-08-18 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions. | ||||
| CVE-2026-73382 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions. | ||||
| CVE-2026-73380 | 2026-08-18 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. | ||||
| CVE-2026-73379 | 2026-08-18 | 6.5 Medium | ||
| Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. | ||||