Export limit exceeded: 381577 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 381577 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 381577 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (381577 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-14476 2 Redhat, Sssd 11 Enterprise Linux, Enterprise Linux Eus, Openshift and 8 more 2026-08-21 8 High
A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.
CVE-2026-77028 2026-08-21 N/A
Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66
CVE-2026-14164 3 Libarchive, Red Hat, Redhat 10 Libarchive, Enterprise Linux, Discovery and 7 more 2026-08-21 7.5 High
A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.
CVE-2026-77780 1 Roskus 1 Prospero Flow Crm 2026-08-21 N/A
Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting creation permissions to disclose another company's bank account name, bank name and card last four digits via a bank_account_id or bank_card_id belonging to that company in POST /transaction/save, which is persisted and rendered without any company ownership check.
CVE-2025-49796 1 Redhat 16 Cert Manager, Discovery, Enterprise Linux and 13 more 2026-08-21 9.1 Critical
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.
CVE-2025-49794 1 Redhat 15 Cert Manager, Enterprise Linux, Hummingbird and 12 more 2026-08-21 9.1 Critical
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.
CVE-2026-73354 2 Reichertbrothers, Wordpress 2 Simplyrets Real Estate Idx, Wordpress 2026-08-21 7.1 High
Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions.
CVE-2026-73364 2 Wordpress, Wpdesk 2 Wordpress, Flexible Subscriptions 2026-08-21 9.8 Critical
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
CVE-2026-73384 2 Cmsminds, Wordpress 2 Pay With Contact Form 7, Wordpress 2026-08-21 7.5 High
Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
CVE-2026-73385 2 Outanking Team, Wordpress 2 Outranking Plugin Options, Wordpress 2026-08-21 7.5 High
Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions.
CVE-2026-73387 2 Smartdatasoft, Wordpress 2 Resido, Wordpress 2026-08-21 8.1 High
Unauthenticated Local File Inclusion in Resido <= 1.5 versions.
CVE-2026-73389 2 The4, Wordpress 2 Kalles Addons, Wordpress 2026-08-21 9.8 Critical
Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
CVE-2026-73390 2 Klbtheme, Wordpress 2 Total Donations, Wordpress 2026-08-21 9.8 Critical
Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
CVE-2026-73391 2 Klbtheme, Wordpress 2 Total Donations, Wordpress 2026-08-21 9.3 Critical
Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
CVE-2025-6032 1 Redhat 3 Enterprise Linux, Openshift, Rhel Eus 2026-08-21 8.3 High
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
CVE-2026-77067 1 Omnivore-app 1 Omnivore 2026-08-21 5 Medium
The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file imports no validation helper. When a subscribed event fires, callWebhook in packages/api/src/jobs/call_webhook.ts issues axios.request with that url, the method and Content-Type recorded on the webhook, and a JSON body carrying the event data, so an authenticated user can make the server send repeated attacker-shaped requests to internal endpoints, including link-local metadata addresses. The request is blind: callWebhook discards the result and writes only a success line or the axios error to the server log, so the response is not returned through the API.
CVE-2026-74021 2 Anders Norén, Wordpress 2 Chaplin, Wordpress 2026-08-21 7.5 High
Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.
CVE-2025-15637 2 Edge Themes, Wordpress 2 Shuffle, Wordpress 2026-08-21 8.1 High
Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.
CVE-2026-66590 2 Tagembed, Wordpress 2 Tagembed, Wordpress 2026-08-21 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.
CVE-2026-66594 2 Lukeseager, Wordpress 2 Wordpress Persistent Login, Wordpress 2026-08-21 8.5 High
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.