Export limit exceeded: 380705 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 380705 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 380705 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (380705 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-5331 | 1 Pcman | 1 Ftp Server | 2026-08-19 | 7.3 High |
| A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown code of the component NLST Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2024-0732 | 1 Pcman | 1 Ftp Server | 2026-08-19 | 5.3 Medium |
| A vulnerability was found in PCMan FTP Server 2.0.7 and classified as problematic. This issue affects some unknown processing of the component STOR Command Handler. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-251555. | ||||
| CVE-2018-18861 | 1 Pcman | 1 Ftp Server | 2026-08-19 | N/A |
| Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command. | ||||
| CVE-2013-4730 | 1 Pcman | 1 Ftp Server | 2026-08-19 | N/A |
| Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USER command. | ||||
| CVE-2025-5635 | 1 Pcman | 1 Ftp Server | 2026-08-19 | 7.3 High |
| A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of the component PLS Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2026-49428 | 1 Freebsd | 1 Freebsd | 2026-08-19 | 8.4 High |
| Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations are not permitted on largepage objects, but the implementation did not verify this. An unprivileged local user can abuse the bug to access freed kernel memory. This can be exploited to escalate privileges. | ||||
| CVE-2026-19842 | 2026-08-19 | 8.8 High | ||
| The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, and offers an administrator a one-click control that promotes that stored certificate to the site's trusted signing certificate, allowing unauthenticated attackers to have a certificate of their own trusted and then authenticate as any user, including an administrator. | ||||
| CVE-2026-19782 | 2026-08-19 | 5.4 Medium | ||
| The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJAX action, allowing any authenticated user, such as a subscriber, to retrieve the email addresses of all registered users. | ||||
| CVE-2026-19709 | 2026-08-19 | 5.3 Medium | ||
| The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing it against the one supplied in a request, allowing unauthenticated attackers to reach its REST routes and disclose any user's membership plan details on sites where the API has been enabled but no keys were ever generated. | ||||
| CVE-2026-19417 | 2026-08-19 | 6.5 Medium | ||
| The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level users to download any file in the media library, including other patients' uploaded medical reports. | ||||
| CVE-2026-19416 | 2026-08-19 | 4.3 Medium | ||
| The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment being modified, allowing authenticated patient-level users to cancel and reschedule other patients' appointments. | ||||
| CVE-2026-19406 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-08-19 | 2.7 Low |
| The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses. | ||||
| CVE-2026-19056 | 2026-08-19 | 7.1 High | ||
| The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one of its administrative pages, leading to reflected Cross-Site Scripting that runs in the session of an administrator induced to submit a crafted request. | ||||
| CVE-2026-19055 | 2026-08-19 | 7.1 High | ||
| The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes on its public pages, leading to reflected Cross-Site Scripting that can be triggered against any visitor, including a logged-in administrator. | ||||
| CVE-2026-18937 | 2026-08-19 | 9 Critical | ||
| The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary code on the server when a classic (non-block) is active. | ||||
| CVE-2026-18779 | 2 Truebooker, Wordpress | 2 Truebooker, Wordpress | 2026-08-19 | 5.3 Medium |
| The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records. | ||||
| CVE-2026-18778 | 2 Truebooker, Wordpress | 2 Truebooker, Wordpress | 2026-08-19 | 5.3 Medium |
| The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to retrieve the personal information of customers who booked an appointment, including their name, email address, phone number and postal address. | ||||
| CVE-2026-18777 | 2 Truebooker, Wordpress | 2 Truebooker, Wordpress | 2026-08-19 | 5.3 Medium |
| The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to change the status of arbitrary appointments, as well as to trigger notification emails to the affected customers. | ||||
| CVE-2026-18776 | 2 Truebooker, Wordpress | 2 Truebooker, Wordpress | 2026-08-19 | 9.8 Critical |
| The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including administrators, and subsequently take over their account via the password reset flow. | ||||
| CVE-2026-18466 | 2 Wordpress, Wp Maps | 2 Wordpress, Wp Maps | 2026-08-19 | 5.4 Medium |
| The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with a Subscriber account to create an unlimited number of options in the database, each of which is loaded on every page request. | ||||