Export limit exceeded: 381577 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381577 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-14476 | 2 Redhat, Sssd | 11 Enterprise Linux, Enterprise Linux Eus, Openshift and 8 more | 2026-08-21 | 8 High |
| A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass. | ||||
| CVE-2026-77028 | 2026-08-21 | N/A | ||
| Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66 | ||||
| CVE-2026-14164 | 3 Libarchive, Red Hat, Redhat | 10 Libarchive, Enterprise Linux, Discovery and 7 more | 2026-08-21 | 7.5 High |
| A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service. | ||||
| CVE-2026-77780 | 1 Roskus | 1 Prospero Flow Crm | 2026-08-21 | N/A |
| Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting creation permissions to disclose another company's bank account name, bank name and card last four digits via a bank_account_id or bank_card_id belonging to that company in POST /transaction/save, which is persisted and rendered without any company ownership check. | ||||
| CVE-2025-49796 | 1 Redhat | 16 Cert Manager, Discovery, Enterprise Linux and 13 more | 2026-08-21 | 9.1 Critical |
| A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory. | ||||
| CVE-2025-49794 | 1 Redhat | 15 Cert Manager, Enterprise Linux, Hummingbird and 12 more | 2026-08-21 | 9.1 Critical |
| A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors. | ||||
| CVE-2026-73354 | 2 Reichertbrothers, Wordpress | 2 Simplyrets Real Estate Idx, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions. | ||||
| CVE-2026-73364 | 2 Wordpress, Wpdesk | 2 Wordpress, Flexible Subscriptions | 2026-08-21 | 9.8 Critical |
| Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. | ||||
| CVE-2026-73384 | 2 Cmsminds, Wordpress | 2 Pay With Contact Form 7, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions. | ||||
| CVE-2026-73385 | 2 Outanking Team, Wordpress | 2 Outranking Plugin Options, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions. | ||||
| CVE-2026-73387 | 2 Smartdatasoft, Wordpress | 2 Resido, Wordpress | 2026-08-21 | 8.1 High |
| Unauthenticated Local File Inclusion in Resido <= 1.5 versions. | ||||
| CVE-2026-73389 | 2 The4, Wordpress | 2 Kalles Addons, Wordpress | 2026-08-21 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. | ||||
| CVE-2026-73390 | 2 Klbtheme, Wordpress | 2 Total Donations, Wordpress | 2026-08-21 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. | ||||
| CVE-2026-73391 | 2 Klbtheme, Wordpress | 2 Total Donations, Wordpress | 2026-08-21 | 9.3 Critical |
| Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. | ||||
| CVE-2025-6032 | 1 Redhat | 3 Enterprise Linux, Openshift, Rhel Eus | 2026-08-21 | 8.3 High |
| A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack. | ||||
| CVE-2026-77067 | 1 Omnivore-app | 1 Omnivore | 2026-08-21 | 5 Medium |
| The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file imports no validation helper. When a subscribed event fires, callWebhook in packages/api/src/jobs/call_webhook.ts issues axios.request with that url, the method and Content-Type recorded on the webhook, and a JSON body carrying the event data, so an authenticated user can make the server send repeated attacker-shaped requests to internal endpoints, including link-local metadata addresses. The request is blind: callWebhook discards the result and writes only a success line or the axios error to the server log, so the response is not returned through the API. | ||||
| CVE-2026-74021 | 2 Anders Norén, Wordpress | 2 Chaplin, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions. | ||||
| CVE-2025-15637 | 2 Edge Themes, Wordpress | 2 Shuffle, Wordpress | 2026-08-21 | 8.1 High |
| Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. | ||||
| CVE-2026-66590 | 2 Tagembed, Wordpress | 2 Tagembed, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions. | ||||
| CVE-2026-66594 | 2 Lukeseager, Wordpress | 2 Wordpress Persistent Login, Wordpress | 2026-08-21 | 8.5 High |
| Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. | ||||