Export limit exceeded: 12709 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (12709 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-48504 | 1 Opentelemetry | 1 Opentelemetry-rust | 2026-07-28 | 5.3 Medium |
| OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context in opentelemetry_sdk did not enforce W3C Baggage size limits before parsing an inbound baggage header, so a large attacker-controlled header could cause unnecessary CPU work and short-lived heap allocations while parsing entries later discarded by the SDK's baggage storage limits. Services that accept untrusted inbound propagation headers may experience increased per-request resource usage when processing oversized baggage headers. This issue is fixed in version 0.32.1. | ||||
| CVE-2026-62183 | 1 Apache | 1 Syncope | 2026-07-28 | 9.8 Critical |
| Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for user self registration of self update requests the following scenario could happen. A REST API call can allow the user to grant themselves one or more of defined Roles, thus gaining their Entitlements and becoming in fact an administrator; the actual Entitlements gained depend on the Roles that are effectively defined on the specific Syncope deployment. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue. | ||||
| CVE-2026-16615 | 2 Gnome, Redhat | 2 Librest, Enterprise Linux | 2026-07-28 | 6.8 Medium |
| A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow. | ||||
| CVE-2026-16287 | 1 Tubitak Bilgem Software Technologies Research Institute | 1 Pardus Update | 2026-07-28 | 7.8 High |
| Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection. This issue affects pardus-update: from 0.6.6 before 0.7.0. | ||||
| CVE-2026-11804 | 1 Tridium | 2 Niagara Enterprise Security, Niagara Framework | 2026-07-28 | 5.2 Medium |
| Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse. This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Security: before 4.14.6, before 4.15.5. | ||||
| CVE-2026-65761 | 1 Joomshaper.com | 1 Easy Store Extension For Joomla | 2026-07-28 | N/A |
| Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions. | ||||
| CVE-2026-65759 | 1 Joomshaper.com | 1 Easy Store Extension For Joomla | 2026-07-28 | N/A |
| Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order states of arbritrary orders. | ||||
| CVE-2026-65763 | 1 Phoca | 1 Phoca Maps Extension For Joomla | 2026-07-28 | N/A |
| Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs lead to a reflective XSS vulnerability. | ||||
| CVE-2026-65762 | 1 Phoca | 1 Phoca Guestbook Extension For Joomla | 2026-07-28 | N/A |
| Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XSS vulnerability. | ||||
| CVE-2026-21655 | 2 Johnson Control, Johnsoncontrols | 2 Victor, Victor | 2026-07-28 | N/A |
| Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0. | ||||
| CVE-2026-13400 | 2 Nsquared, Wordpress | 2 Simply Schedule Appointments, Wordpress | 2026-07-28 | 6.1 Medium |
| Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments WordPress plugin before 1.6.12.4's wp_kses_post() filter, so a double-encoded payload survives intake and is reintroduced as an executable element at render time. | ||||
| CVE-2026-13597 | 2 Markchenlife, Wordpress | 2 Qrcode-login-for-weixin, Wordpress | 2026-07-28 | 9.1 Critical |
| The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem it through an unauthenticated AJAX action to log in as that user, including an administrator, without a password. | ||||
| CVE-2026-13726 | 2 Themeisle, Wordpress | 2 Mpg, Wordpress | 2026-07-28 | 7.1 High |
| The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request. | ||||
| CVE-2026-14289 | 2 Facturaone Para Woocommerce Con Verifactu, Wordpress | 2 Facturaone Para Woocommerce Con Verifactu, Wordpress | 2026-07-28 | 9 Critical |
| The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible directory and achieve remote code execution. | ||||
| CVE-2026-66476 | 2 Syed Balkhi, Wordpress | 2 Easy Digital Downloads, Wordpress | 2026-07-28 | 4.9 Medium |
| Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions. | ||||
| CVE-2026-66477 | 2 Shufflehound, Wordpress | 2 Gillion, Wordpress | 2026-07-28 | 5.3 Medium |
| Unauthenticated Broken Access Control in Gillion <= 4.13 versions. | ||||
| CVE-2026-48030 | 1 Pheditor | 1 Pheditor | 2026-07-28 | 9.9 Critical |
| Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS commands by injecting shell metacharacters into the 'dir' POST parameter, completely bypassing the TERMINAL_COMMANDS whitelist and achieving full Remote Code Execution with web server privileges. This issue has been patched in version 2.0.4. | ||||
| CVE-2026-54540 | 1 Pheditor | 1 Pheditor | 2026-07-28 | 8.8 High |
| Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated terminal command whitelist bypass. The terminal feature checks whether the submitted command starts with one of the configured TERMINAL_COMMANDS values, then passes the full command string to shell_exec(). Shell command substitution such as $() is not blocked, so an authenticated user with the terminal permission can bypass a restricted command allowlist and execute arbitrary shell commands as the web server user. This issue has been patched in version 2.0.5. | ||||
| CVE-2026-15304 | 2 Foomagoo, Wordpress | 2 Plugin Organizer, Wordpress | 2026-07-28 | 6.5 Medium |
| The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions up to, and including, 10.2.4. This is due to insufficient escaping on the user-supplied parameter in the perform_plugin_search() function, where esc_sql() output is passed as the replacement string to preg_replace(), which collapses backslash escapes and defeats the quoting protection; additionally, the AJAX handler lacks both nonce verification and capability checks. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-55579 | 1 Pheditor | 1 Pheditor | 2026-07-28 | 9.8 Critical |
| Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-512 hash stored at pheditor.php:11). There is no mechanism to force a password change on first login. Any deployment using the default credentials grants an attacker full access to the file editor, file upload, and terminal features, enabling arbitrary file read/write and remote code execution. This issue has been patched in version 2.0.6. | ||||