Export limit exceeded: 373862 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (91043 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65056 | 1 Mzxrai | 1 Mcp-webresearch | 2026-07-23 | 8.2 High |
| mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validates the URL protocol without filtering private or reserved IP ranges. Attackers can steer the LLM-controlled URL argument through prompt injection to navigate the server's Playwright browser to internal endpoints such as cloud instance metadata services, causing the server to return sensitive internal page content including credentials into the model context. | ||||
| CVE-2026-47237 | 1 Kubeflow | 1 Community-distribution | 2026-07-23 | 8 High |
| Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnerable to authorization token stealing from any user of the Kubeflow UI or APIs, such as the Dashboard, Pipelines API, or Notebooks. With this token, the attacker can take over the user's account and the data that is processed by that user. The attacker needs a valid user with the ``kubeflow-edit`` role / Contributor role in a random Kubeflow namespace to perform this attack. This is given if _Automatic Profile Creation_ is enabled. Version 26.03-rc.1 fixes the issue. | ||||
| CVE-2026-65317 | 1 Weaviate | 1 Verba | 2026-07-23 | 8.6 High |
| Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a crafted Origin header and attacker-controlled host and port values. Attackers can bypass the localhost origin check in the API middleware by sending any Origin value prefixed with ' regardless of port, then submit arbitrary host and port parameters to the /api/connect endpoint to cause the server to issue outbound GET requests to attacker-controlled infrastructure. | ||||
| CVE-2026-65318 | 1 Weaviate | 1 Verba | 2026-07-23 | 8.6 High |
| Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint. Attackers can connect to the /ws/import_files WebSocket endpoint without authentication, specify arbitrary URLs in the HTMLReader configuration, and cause the server to fetch internal resources such as co-located database endpoints or cloud instance metadata services to retrieve sensitive credentials. | ||||
| CVE-2026-65319 | 1 Feedbin | 1 Feedbin | 2026-07-23 | 7.5 High |
| Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the authorization before-action filter entirely. Attackers can iterate sequential integer entry IDs through the GET /api/v2/entries/:id/text endpoint to enumerate and extract plain-text content of all stored articles, including private newsletter content, personal page-saves, and articles from any user's private subscriptions. | ||||
| CVE-2026-15802 | 2 Chimpstudio, Wordpress | 2 Wp Foodbakery, Wordpress | 2026-07-23 | 8.1 High |
| The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). | ||||
| CVE-2026-3821 | 1 Smci | 2 X14dbg-dap, X14dbi | 2026-07-23 | 8.8 High |
| Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the BMC. | ||||
| CVE-2026-63047 | 1 Joomdonation.com | 1 Events Booking Extension For Joomla | 2026-07-23 | 7.5 High |
| Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information. | ||||
| CVE-2026-14551 | 1 Servereye | 1 Windows Agent (sensorhub) | 2026-07-23 | 8.8 High |
| The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory %ProgramData%\ServerEye3\update\ for a trigger file named "update_available". Due to insufficient access restrictions on this directory, a local standard user can create the trigger file and provide a path to a directory containing malicious JSON instructions. The service subsequently executes the utility UpdaterAction.exe with SYSTEM privileges, which parses the instructions and performs an unvalidated file copy from a user-controlled source to a protected system destination (e.g., overwriting a service binary). This leads to full system compromise as the service automatically restarts the overwritten binary with SYSTEM privileges. | ||||
| CVE-2026-4773 | 1 Magarsus Consulting | 1 Idm-mfa | 2026-07-23 | 8.1 High |
| Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authentication Bypass. This issue affects IDM-MFA: from 2025.11.27 before 2026.03.10. | ||||
| CVE-2026-65013 | 1 Onlook | 1 Repo | 2026-07-23 | 8.8 High |
| Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API procedures including project.get, member.remove, and chat.conversation.delete. Attackers can provide arbitrary projectId or conversationId values without authorization validation to read, modify, and delete other users' project data, members, and conversation history. | ||||
| CVE-2026-64611 | 1 Redhat | 1 Enterprise Linux | 2026-07-23 | 7.5 High |
| A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service. | ||||
| CVE-2026-9713 | 2 King-theme, Wordpress | 2 Product Designer For Woocommerce Wordpress | Lumise, Wordpress | 2026-07-23 | 7.5 High |
| The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed by the checkout AJAX action in versions up to, and including, 2.1.1. This is due to insufficient escaping on the user-supplied parameters before they are appended directly to a raw SQL query in the find_resource() function — the 'id' field is interpolated without quotes into a WHERE clause (numeric context) and 'table' is interpolated into the FROM clause, neither of which is protected by wp_magic_quotes or passed through $wpdb->prepare(). This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-25405 | 2 Digitalme, Wordpress | 2 Eroom, Wordpress | 2026-07-23 | 8.5 High |
| Contributor SQL Injection in eRoom <= 1.7.1 versions. | ||||
| CVE-2026-57370 | 2 Codepress It Solutions Llc, Wordpress | 2 Visitor Traffic Real Time Statistics Pro, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions. | ||||
| CVE-2026-57397 | 2 Thimpress., Wordpress | 2 Coaching, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions. | ||||
| CVE-2026-57427 | 2 Download Monitor, Wordpress | 2 Download Monitor - Wpforms Lock, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions. | ||||
| CVE-2026-57699 | 2 Bqworks, Wordpress | 2 Slider Pro, Wordpress | 2026-07-23 | 7.1 High |
| Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions. | ||||
| CVE-2026-57785 | 2 Apustheme, Wordpress | 2 Apuslisting, Wordpress | 2026-07-23 | 8.8 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions. | ||||
| CVE-2026-59542 | 2 Wordpress, Wp Chill | 2 Wordpress, Kali Forms | 2026-07-23 | 7.7 High |
| Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions. | ||||