Export limit exceeded: 12055 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (12055 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-14545 | 2 Truebooker, Wordpress | 2 Truebooker, Wordpress | 2026-07-28 | 9.8 Critical |
| The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site. | ||||
| CVE-2026-14924 | 2 Tablesome, Wordpress | 2 Tablesome Table, Wordpress | 2026-07-28 | 7.5 High |
| The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages. | ||||
| CVE-2026-14926 | 2 Fluentcart, Wordpress | 2 A New Era Of Ecommerce, Wordpress | 2026-07-28 | 4.2 Medium |
| The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a subscription belongs to the requesting customer in several of its payment-method endpoints, allowing any authenticated customer to act on another customer's subscription (changing its payment method, or cancelling and re-binding it) when they know the target subscription identifier. | ||||
| CVE-2026-11756 | 1 Dassault Systèmes | 1 Station Launcher App In 3dexperience Platform | 2026-07-28 | 10 Critical |
| A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution. | ||||
| CVE-2026-55977 | 1 Eshare | 1 Esharepro | 2026-07-28 | 3.3 Low |
| Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the application's rate-limiting mechanism, enabling brute-forcing of the screen-sharing code and potentially displaying harmful content on the affected screen. | ||||
| CVE-2026-8167 | 2 Thewp Digital Solutions, Wordpress | 2 News Theme V8, Wordpress | 2026-07-28 | 6.1 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solutions News Theme V8 allows Reflected XSS. This issue affects News Theme V8: through 16.06.2026. | ||||
| CVE-2026-14167 | 2 Ads-tec Industrial It, Ads Tec | 8 Dvg-irf1401, Dvg-irf1421, Dvg-irf3401 and 5 more | 2026-07-28 | 8.8 High |
| A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization. | ||||
| CVE-2026-14168 | 2 Ads-tec Industrial It, Ads Tec | 8 Dvg-irf1401, Dvg-irf1421, Dvg-irf3401 and 5 more | 2026-07-28 | 8.8 High |
| A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access. | ||||
| CVE-2026-14169 | 2 Ads-tec Industrial It, Ads Tec | 8 Dvg-irf1401, Dvg-irf1421, Dvg-irf3401 and 5 more | 2026-07-28 | 8.1 High |
| Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device. | ||||
| CVE-2026-14171 | 2 Ads-tec Industrial It, Ads Tec | 8 Dvg-irf1401, Dvg-irf1421, Dvg-irf3401 and 5 more | 2026-07-28 | 6.1 Medium |
| An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can result in a loss of confidentiality and availability. | ||||
| CVE-2026-11598 | 2 Lrnz, Wordpress | 2 Shortcodify, Wordpress | 2026-07-28 | 5 Medium |
| The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-14785 | 2 Mihail-chepovskiy, Wordpress | 2 Web Directory Free, Wordpress | 2026-07-28 | 7.5 High |
| The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1.7.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-18029 | 1 Pretix Gmbh | 1 Pretix-girosolution | 2026-07-28 | N/A |
| Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment. | ||||
| CVE-2026-13440 | 2 Wedevs, Wordpress | 2 Storegrowth – Upsell, Bogo, Quick View, Direct Checkout & Side Cart For Woocommerce, Wordpress | 2026-07-28 | 7.2 High |
| The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'message_popup' parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit is possible because the 'ajd_protected' nonce required by the create_popup handler is exposed to all unauthenticated frontend visitors via wp_localize_script under bogo_save_url.ajd_nonce, effectively bypassing the nonce-only access control. | ||||
| CVE-2026-15411 | 2 Wedevs, Wordpress | 2 Storegrowth – Upsell, Bogo, Quick View, Direct Checkout & Side Cart For Woocommerce, Wordpress | 2026-07-28 | 5.3 Medium |
| The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the spsg_popup_products option with arbitrary attacker-controlled data. The 'ajd_protected' nonce used as the sole gate is exposed to unauthenticated visitors on every frontend page through the BoGo module's wp_localize_script call, rendering it ineffective as an authorization barrier. | ||||
| CVE-2026-4648 | 1 Casfid Servicios Tecnológicos | 1 Nfc Wristbands | 2026-07-28 | N/A |
| Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tecnológicos S.L.U. (version used at Resurrection Fest 2025), which employs cards based on MIFARE Classic technology (FM11RF08S). The cryptographic weakness of the authentication algorithm allows an attacker to retrieve access keys using techniques known as Backdoored Nested Attack, read the wristband’s entire contents, and clone its credentials onto a compatible rewritable card. Exploitation of this vulnerability could enable the impersonation of other attendees, the fraudulent use of the balance associated with their wristbands, and financial losses for both the affected users and the event organizers. | ||||
| CVE-2026-65882 | 1 Joomdle.com | 1 Joomdle Component For Joomla | 2026-07-28 | 6.1 Medium |
| Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle wrapper endpoint allowed a reflected XSS vector. | ||||
| CVE-2026-66918 | 1 Pivotick | 1 Pivotick | 2026-07-28 | N/A |
| Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style.svgIcon property before inserting it into the document. When rendering a graph node, the vulnerable code assigns the SVG icon markup directly to the innerHTML property of a live SVG element. An attacker able to influence graph data can provide crafted markup containing executable event handlers, such as an <image> element with an onerror attribute. When a victim loads or renders the malicious graph, the payload may execute arbitrary JavaScript in the security context of the application embedding Pivotick. Successful exploitation could allow the attacker to access application data available to the victim, modify displayed content, or perform actions using the victim’s authenticated session. Exploitation requires an application using Pivotick to render graph data that is controlled or modified by an attacker. | ||||
| CVE-2026-66919 | 1 Pivotick | 1 Pivotick | 2026-07-28 | N/A |
| Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. Node labels and descriptions originating from graph data were interpolated directly into HTML used to construct the modal headers. An attacker able to supply or modify graph data could insert a malicious HTML or JavaScript payload into a node’s label or description. The payload would be parsed and executed in the application’s origin when a user opened the affected node’s inspect or edit modal. Successful exploitation could allow the attacker to access information available to the victim, modify application data, or perform actions using the victim’s active session. The vulnerability has been addressed by creating the modal elements without embedding graph data in HTML and assigning node labels and descriptions through textContent. | ||||
| CVE-2026-66921 | 1 Pivotick | 1 Pivotick | 2026-07-28 | N/A |
| Pivotick’s Markdown node-reference renderer failed to HTML-escape the attacker-controlled nodeName value before interpolating it into both the data-node-name attribute and the body of a generated <span> element. Because the node-reference tokenizer rejected only square brackets, a crafted node name could still contain quotation marks, angle brackets, or other HTML metacharacters. An attacker could therefore terminate the quoted attribute or inject additional HTML elements and event-handler attributes. When malicious node-reference content is rendered by a consumer that does not apply DOMPurify or equivalent sanitization, arbitrary JavaScript may execute in the victim’s browser in the security context of the application. Successful exploitation requires a victim to open or render a crafted graph or note and could allow the attacker to access same-origin information, modify displayed content, or perform actions using the victim’s session. The patch resolves the issue by applying context-appropriate HTML escaping to node names before inserting them into either HTML text or quoted attribute values. The shared escaping function now encodes ampersands, angle brackets, and both types of quotation marks. | ||||