Export limit exceeded: 12739 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (12739 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-9085 | 1 Tubitak Bilgem Software Technologies Research Institute | 1 Pardus-parental-control | 2026-07-29 | 8.8 High |
| Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-Parental-Control allows DNS Spoofing. This issue affects Pardus-Parental-Control: from <=0.5.1 before 0.7.0. | ||||
| CVE-2026-12741 | 2 Epsiloncool, Wordpress | 2 Wp Fast Total Search – The Power Of Indexed Search, Wordpress | 2026-07-29 | 7.5 High |
| The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter in all versions up to, and including, 1.80.280 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-67182 | 1 Tomaka | 1 Rouille | 2026-07-29 | 7.5 High |
| Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass access controls by injecting bare line feed characters (0x0A) into client-supplied request header values that are copied verbatim to upstream connections without validation. Attackers can craft a header value containing a complete additional HTTP request that is interpreted as a separate request by backends such as Go net/http and Python http.server, causing the backend to process a smuggled request with attacker-chosen method, path, and headers that bypasses the rouille handler's access control logic. | ||||
| CVE-2026-6881 | 1 Ellucian | 2 Advance Web, Legacy Advance | 2026-07-29 | N/A |
| A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field. This issue affects Advance Web: all versions; Legacy Advance: all versions. Ellucian CRM Advance is not impacted. | ||||
| CVE-2026-54638 | 1 Gotd | 1 Td | 2026-07-29 | 7.5 High |
| gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]byte, dataLen) before checking the remaining buffer, allowing remote unauthenticated denial of service through excessive memory allocation and CPU or garbage collection pressure. This issue is fixed in version 0.145.1. | ||||
| CVE-2026-54658 | 1 Hypequery | 1 Hypequery | 2026-07-29 | 9.8 Critical |
| Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing attacker controlled query parameters with a trailing backslash to escape the closing quote and inject arbitrary SQL. This issue is fixed in version 2.0.2. | ||||
| CVE-2026-54650 | 1 Bablilayoub | 1 Openhole | 2026-07-29 | 8.6 High |
| openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing percent encoded dot segments %2e and separators %2f to reach tunneled local services as ../ and / for path traversal. This issue is fixed in version 0.1.2. | ||||
| CVE-2026-17166 | 2 Magepeopleteam, Wordpress | 2 Event Booking Manager For Woocommerce – Sell Tickets, Event Registration, Rsvp & Event Calendar, Wordpress | 2026-07-29 | 4.3 Medium |
| The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to modify site-wide payment settings — including WooCommerce payment enablement, cart redirect behavior, login requirements for checkout, confirmation page ID, and confirmed ticket statuses — that govern how all event bookings are processed. | ||||
| CVE-2026-63235 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 3.7 Low |
| An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the session of any user given their email address via the login kickout endpoint, resulting in a denial of service. | ||||
| CVE-2026-63236 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 3.7 Low |
| An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name, internal identifier, scores, lesson status, lesson position, and cached lesson state via the SCORM API endpoint. | ||||
| CVE-2026-63238 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 6.5 Medium |
| An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, including administrator accounts, by supplying a valid user UUID without providing primary credentials via the 2FA validation endpoint. | ||||
| CVE-2026-63239 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 5.4 Medium |
| A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception. | ||||
| CVE-2026-63240 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 4.3 Medium |
| An information disclosure vulnerability in Koollab LMS allowed an authenticated learner to obtain correct quiz answers from the course status endpoint without completing the assessment legitimately, compromising the integrity of assessments. | ||||
| CVE-2026-63241 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 3.1 Low |
| An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course completion progress of any other user without authorisation, disclosing private learning progress information. | ||||
| CVE-2026-63242 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 4.3 Medium |
| A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to completed via the SCORM commit endpoint without viewing the lesson material, compromising training and completion records. | ||||
| CVE-2025-10656 | 2 Holest, Wordpress | 2 Spreadsheet Price Changer For Woocommerce And Wp E-commerce – Light, Wordpress | 2026-07-29 | 9.8 Critical |
| The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. This makes it possible for unauthenticated attackers to create admin accounts. | ||||
| CVE-2026-4604 | 2 Klubraum, Wordpress | 2 Klubraum Membership Request, Wordpress | 2026-07-29 | 5.3 Medium |
| The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `kr_mr_store_settings()` function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update the plugin's settings, including the Klubraum API token and introduction text, effectively hijacking the plugin's integration with the Klubraum service. | ||||
| CVE-2026-65883 | 1 Aimy-extensions.com | 1 Aimy Captcha-less Form Guard Plugin For Joomla | 2026-07-29 | N/A |
| Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution. | ||||
| CVE-2026-50642 | 1 So-fancy | 1 Diff-so-fancy | 2026-07-29 | 4.4 Medium |
| diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting diff data. The application only strips ANSI SGR sequences while allowing other control characters, including carriage return (\r) and escape sequences (e.g., OSC, CSI), to pass through unsanitized. An attacker can embed malicious control sequences in filenames, diff metadata, or file content that are rendered directly in the terminal during diff viewing. This can lead to output manipulation, including filename spoofing, terminal screen clearing, and clipboard injection via supported escape sequences. Successful exploitation may mislead users during code review, alter terminal state, or result in unintended command execution through clipboard hijacking. This issue has been fixed in the commit 9c81294 | ||||
| CVE-2026-14270 | 2 Themecomplete, Wordpress | 2 Extra Checkout Options - Addon For Extra Product Options Plugin, Wordpress | 2026-07-29 | 8.8 High |
| The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validation in the eco_save_settings() function, which allows low-privileged authenticated users to modify the tc_eco_custom_file_types upload allowlist setting, combined with insufficient authorization on the wc_eco_upload_file AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to allow PHP uploads, upload a PHP file using the frontend upload nonce exposed on cart and checkout pages, and achieve remote code execution. NOTE: This vulnerability was partially fixed in version 2.3.2. | ||||