Export limit exceeded: 370925 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 370925 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (370925 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-57701 | 2026-07-23 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions. | ||||
| CVE-2026-65901 | 1 Cure53 | 1 Dompurify | 2026-07-23 | 6.1 Medium |
| DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form nodes. Attackers can supply hostile live DOM objects with real script children whose observable nodeName is clobbered to appear as allowed elements, causing scripts to execute when the sanitized tree is inserted into a live document. | ||||
| CVE-2026-65913 | 1 Cure53 | 1 Dompurify | 2026-07-23 | 6.1 Medium |
| DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick to true, causing DOMPurify to accept event handlers as allowlisted attributes and resulting in DOM-based XSS when sanitized markup is rendered. | ||||
| CVE-2025-24259 | 1 Apple | 1 Macos | 2026-07-23 | 9.8 Critical |
| This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check. | ||||
| CVE-2026-24537 | 2026-07-23 | 4.3 Medium | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions. | ||||
| CVE-2026-27392 | 2026-07-23 | 4.3 Medium | ||
| Contributor Broken Access Control in uListing <= 2.2.0 versions. | ||||
| CVE-2026-25466 | 2 Wordpress, Wpgmaps | 2 Wordpress, Wp Go Maps | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions. | ||||
| CVE-2026-27391 | 2026-07-23 | 5.4 Medium | ||
| Subscriber Broken Access Control in uListing <= 2.2.0 versions. | ||||
| CVE-2026-27423 | 2026-07-23 | 4.3 Medium | ||
| Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions. | ||||
| CVE-2026-57767 | 2026-07-23 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions. | ||||
| CVE-2026-59512 | 2 Piwebsolution, Wordpress | 2 Product Enquiry For Woocommerce, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions. | ||||
| CVE-2026-59525 | 2026-07-23 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. | ||||
| CVE-2026-59544 | 2026-07-23 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. | ||||
| CVE-2026-61944 | 2 Bookly, Wordpress | 2 Bookly, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions. | ||||
| CVE-2026-65463 | 2026-07-23 | 5.4 Medium | ||
| Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions. | ||||
| CVE-2026-65469 | 2026-07-23 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions. | ||||
| CVE-2026-65482 | 2026-07-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions. | ||||
| CVE-2026-65488 | 2026-07-23 | 7.1 High | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions. | ||||
| CVE-2026-65494 | 2026-07-23 | 7.1 High | ||
| Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions. | ||||
| CVE-2025-10911 | 1 Redhat | 11 Discovery, Enterprise Linux, Enterprise Linux Eus and 8 more | 2026-07-23 | 5.5 Medium |
| A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash. | ||||