Export limit exceeded: 376128 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (376128 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-44401 | 1 Typemill | 1 Typemill | 2026-08-11 | 4.8 Medium |
| Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that allows authenticated users with theme-configuration access to inject malicious JavaScript URIs by supplying unsanitized href values in Markdown links. Attackers can craft Markdown links using the javascript: scheme through ParsedownExtension.php or TwigMarkdownExtension.php, storing a persistent payload that executes in the browser of every visitor who clicks the link, enabling session cookie theft, authenticated request forgery, and credential harvesting. | ||||
| CVE-2026-5304 | 1 Axis Communications Ab | 1 Axis Os | 2026-08-11 | 5.7 Medium |
| An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application. | ||||
| CVE-2026-33921 | 1 Nozomi Networks | 1 Arc | 2026-08-11 | 5.2 Medium |
| The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privileges could use the Npcap driver to capture the traffic reaching the host, which discloses information belonging both to the host and to other systems on the same network segment, and to send arbitrary raw packets on that segment. | ||||
| CVE-2026-67591 | 1 Apache | 2 Qpid Proton-j, Qpid Protonj2 | 2026-08-11 | 6.5 Medium |
| An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue. | ||||
| CVE-2026-67592 | 1 Apache | 2 Qpid Proton-j, Qpid Protonj2 | 2026-08-11 | 7.5 High |
| It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue | ||||
| CVE-2026-0673 | 2 Bdthemes, Wordpress | 2 Element Pack Addons For Elementor, Wordpress | 2026-08-11 | 5.3 Medium |
| The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via the `element_pack_contact_form` AJAX action. This is due to insufficient sanitization of newline characters in user-supplied input that gets concatenated into email headers. This makes it possible for unauthenticated attackers to inject arbitrary email headers into emails sent by the contact form. | ||||
| CVE-2026-18473 | 2 Wordpress, Wpdirectorykit | 2 Wordpress, Wp Directory Kit | 2026-08-11 | 9.1 Critical |
| The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users. | ||||
| CVE-2026-19350 | 1 Dolibarr | 2 Erp, Erp Crm | 2026-08-11 | 6.3 Medium |
| A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is 8992ce8704da947b6abe7b65a6fe59aed736bb81. It is advisable to implement a patch to correct this issue. | ||||
| CVE-2026-19379 | 2 Efm, Iptime | 2 Iptime Ax8004m, Ax8004m | 2026-08-11 | 7.3 High |
| A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-17541 | 2 Filemanagerpro, Wordpress | 2 File Manager, Wordpress | 2026-08-11 | 7.5 High |
| The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them. | ||||
| CVE-2026-17542 | 2 Filemanagerpro, Wordpress | 2 File Manager, Wordpress | 2026-08-11 | 7.5 High |
| The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data. | ||||
| CVE-2026-19053 | 2 Prosolution, Wordpress | 2 Prosolution Wp Client, Wordpress | 2026-08-11 | 9.1 Critical |
| The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection. | ||||
| CVE-2026-15229 | 2 Pinpoint, Wordpress | 2 Pinpoint Booking System, Wordpress | 2026-08-11 | N/A |
| The Pinpoint Booking System WordPress plugin through 2.9.9.6.9 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation. | ||||
| CVE-2026-19089 | 2 Tychesoftwares, Wordpress | 2 Product Input Fields For Woocommerce, Wordpress | 2026-08-11 | N/A |
| The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on servers that do not honour the directory's access rules. | ||||
| CVE-2026-57279 | 1 Cybozu | 1 Cybozu Garoon | 2026-08-11 | N/A |
| Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of a user logged in to the product. | ||||
| CVE-2026-21078 | 1 Samsung | 1 Smart Switch | 2026-08-11 | N/A |
| Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity. | ||||
| CVE-2026-21079 | 1 Samsung | 1 Smart Switch | 2026-08-11 | N/A |
| Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data. | ||||
| CVE-2026-21080 | 1 Samsung | 1 Smart Switch | 2026-08-11 | N/A |
| Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. | ||||
| CVE-2026-21083 | 1 Samsung | 1 Smart Switch | 2026-08-11 | N/A |
| Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. | ||||
| CVE-2026-21084 | 1 Samsung | 1 Smartthings | 2026-08-11 | N/A |
| Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information. | ||||