Export limit exceeded: 374264 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (374264 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-19020 | 1 Itsourcecode | 1 Hospital Management System | 2026-08-06 | 6.3 Medium |
| A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /servicetype.php. This manipulation of the argument editid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. | ||||
| CVE-2026-19036 | 1 Shibby | 1 Tomato | 2026-08-06 | 7.2 High |
| A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This project is superseded by FreshTomato. | ||||
| CVE-2026-19041 | 1 Missionsquad | 1 Mcp-api | 2026-08-06 | 6.3 Medium |
| A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageService.installPackage of the file src/controllers/packages.ts of the component NPM Package Version Handler. The manipulation leads to command injection. It is possible to initiate the attack remotely. Upgrading to version 1.11.9 is sufficient to resolve this issue. The identifier of the patch is a40f54d4533ba6618e1749383a245900eeb024c1. The affected component should be upgraded. | ||||
| CVE-2026-28143 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions. | ||||
| CVE-2025-63822 | 2026-08-06 | 8.1 High | ||
| SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is authorized to access the target user's data. | ||||
| CVE-2025-63823 | 2026-08-06 | 9.8 Critical | ||
| My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values. | ||||
| CVE-2026-14313 | 2026-08-06 | 5.3 Medium | ||
| PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is vulnerable to unauthenticated missing-authorization / IDOR write. Requires WooCommerce. | ||||
| CVE-2026-14314 | 2026-08-06 | 5.3 Medium | ||
| The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated attackers to forge a token and disclose image attachments, including other customers' uploaded payment receipts, that they do not own. | ||||
| CVE-2026-14240 | 2 Tourmaster, Wordpress | 2 Tourmaster, Wordpress | 2026-08-06 | 5.3 Medium |
| The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its publicly accessible directory with no access control, allowing unauthenticated users to download the exported customers' personal information once an administrator has run an export. | ||||
| CVE-2026-16290 | 2 Profilegrid, Wordpress | 2 Profilegrid, Wordpress | 2026-08-06 | 5.3 Medium |
| The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin before 6.0.0.0's member-visibility setting. | ||||
| CVE-2026-18050 | 2026-08-06 | 7.5 High | ||
| The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The identifier is high-entropy, is disclosed only to the uploader, and the file is removed on submission or by a scheduled cleanup, so a cross-user read is not achievable by guessing alone. | ||||
| CVE-2026-61961 | 2 Wordpress, Wpdeveloper | 2 Wordpress, Embedpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. | ||||
| CVE-2026-66708 | 2 Boldgrid, Wordpress | 2 Total Upkeep, Wordpress | 2026-08-06 | 8.2 High |
| Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions. | ||||
| CVE-2026-66709 | 2 Webappick, Wordpress | 2 Ctx Feed, Wordpress | 2026-08-06 | 9.1 Critical |
| Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions. | ||||
| CVE-2026-66710 | 2 E2pdf, Wordpress | 2 E2pdf, Wordpress | 2026-08-06 | 8.1 High |
| Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions. | ||||
| CVE-2026-28178 | 2 Codesupplyco, Wordpress | 2 Powerkit, Wordpress | 2026-08-06 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions. | ||||
| CVE-2026-32548 | 2 Surecart, Wordpress | 2 Surecart, Wordpress | 2026-08-06 | 5.3 Medium |
| Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions. | ||||
| CVE-2026-61982 | 2 Jp-secure, Wordpress | 2 Siteguard Wp Plugin, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. | ||||
| CVE-2026-65509 | 2 Wordpress, Wpdatatables | 2 Wordpress, Wpdatatables | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. | ||||
| CVE-2026-65573 | 2 Themerex, Wordpress | 2 Abelle, Wordpress | 2026-08-06 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. | ||||