Export limit exceeded: 16030 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (16030 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-6881 | 1 Ellucian | 2 Advance Web, Legacy Advance | 2026-07-29 | N/A |
| A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field. This issue affects Advance Web: all versions; Legacy Advance: all versions. Ellucian CRM Advance is not impacted. | ||||
| CVE-2026-16581 | 1 Igloohome | 1 Smart Lock Mobile Application | 2026-07-29 | 5.3 Medium |
| In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls. | ||||
| CVE-2026-49447 | 1 Azukaar | 1 Cosmos-server | 2026-07-29 | 5.3 Medium |
| Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. In 0.22.18, `GET /cosmos/api/constellation/public-devices` discloses Constellation device metadata to a requester that supplies any non-empty Authorization header. The handler strips the string Bearer from the header but never validates the resulting token and never uses it in the database query. This vulnerability is fixed in 0.22.19. | ||||
| CVE-2026-54638 | 1 Gotd | 1 Td | 2026-07-29 | 7.5 High |
| gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]byte, dataLen) before checking the remaining buffer, allowing remote unauthenticated denial of service through excessive memory allocation and CPU or garbage collection pressure. This issue is fixed in version 0.145.1. | ||||
| CVE-2026-54658 | 1 Hypequery | 1 Hypequery | 2026-07-29 | 9.8 Critical |
| Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing attacker controlled query parameters with a trailing backslash to escape the closing quote and inject arbitrary SQL. This issue is fixed in version 2.0.2. | ||||
| CVE-2026-54650 | 1 Bablilayoub | 1 Openhole | 2026-07-29 | 8.6 High |
| openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing percent encoded dot segments %2e and separators %2f to reach tunneled local services as ../ and / for path traversal. This issue is fixed in version 0.1.2. | ||||
| CVE-2026-54659 | 1 Ddnexus | 1 Pagy | 2026-07-29 | N/A |
| Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as <locale>.yml path components, allowing untrusted params[:locale] values with absolute paths or ../ sequences to create a file existence and readability oracle for YAML files. This issue is fixed in version 43.5.6. | ||||
| CVE-2026-17166 | 2 Magepeopleteam, Wordpress | 2 Event Booking Manager For Woocommerce – Sell Tickets, Event Registration, Rsvp & Event Calendar, Wordpress | 2026-07-29 | 4.3 Medium |
| The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to modify site-wide payment settings — including WooCommerce payment enablement, cart redirect behavior, login requirements for checkout, confirmation page ID, and confirmed ticket statuses — that govern how all event bookings are processed. | ||||
| CVE-2026-18072 | 2 Nico23, Wordpress | 2 Advanced Responsive Video Embedder For Rumble, Odysee, Youtube, Vimeo, Kick …, Wordpress | 2026-07-29 | 9.8 Critical |
| The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs before any authentication checks on every request — reads an attacker-supplied token from the `_wplogin` (or `_wpm`) parameter and compares it against a hardcoded SHA-256 hash embedded directly in the plugin source, with no nonce verification, no capability check, and no password validation anywhere in the flow. Because this static hash constitutes a set of universal credentials that are publicly accessible in the plugin's source code, unauthenticated attackers can supply the known token to be authenticated as an arbitrarily selected existing administrator account, gaining full administrative control over the affected WordPress site. This was likely introduced by an attacker who gained commit access to the developers account. | ||||
| CVE-2026-63235 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 3.7 Low |
| An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the session of any user given their email address via the login kickout endpoint, resulting in a denial of service. | ||||
| CVE-2026-63236 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 3.7 Low |
| An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name, internal identifier, scores, lesson status, lesson position, and cached lesson state via the SCORM API endpoint. | ||||
| CVE-2026-63237 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 4.8 Medium |
| A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled seed to generate a matching one-time password and bypass the second authentication factor, potentially enabling unauthorised access to administrator accounts. | ||||
| CVE-2026-63238 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 6.5 Medium |
| An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, including administrator accounts, by supplying a valid user UUID without providing primary credentials via the 2FA validation endpoint. | ||||
| CVE-2026-63239 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 5.4 Medium |
| A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception. | ||||
| CVE-2026-63240 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 4.3 Medium |
| An information disclosure vulnerability in Koollab LMS allowed an authenticated learner to obtain correct quiz answers from the course status endpoint without completing the assessment legitimately, compromising the integrity of assessments. | ||||
| CVE-2026-63241 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 3.1 Low |
| An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course completion progress of any other user without authorisation, disclosing private learning progress information. | ||||
| CVE-2026-63242 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 4.3 Medium |
| A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to completed via the SCORM commit endpoint without viewing the lesson material, compromising training and completion records. | ||||
| CVE-2026-18192 | 1 Vacron | 1 Vin-ds783e-e6 | 2026-07-29 | 6.5 Medium |
| VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files. | ||||
| CVE-2026-13425 | 2 Code4life, Wordpress | 2 Database For Cf7, Wordpress | 2026-07-29 | 7.2 High |
| The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by unauthenticated attackers because Contact Form 7 accepts array-structured input for ordinary text fields (e.g., your-name[]) via the public REST API endpoint /wp-json/contact-form-7/v1/contact-forms/{id}/feedback, and the plugin stores submitted data using $wpdb INSERT with serialize() into a custom wp_cf7db table, bypassing WordPress save-time filtering via wp_insert_post/wp_kses. | ||||
| CVE-2026-9720 | 2 Facturadorvirtual, Wordpress | 2 Facturación Electrónica Costa Rica, Wordpress | 2026-07-29 | 4.3 Medium |
| The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the (global scope, included by fvcr_admin_page_html) function. This makes it possible for unauthenticated attackers to modify the plugin's configuration, including API tokens, access tokens, economic activity, Hacienda environment mode, invoice and ticket emission flags, exchange rate, and branch settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | ||||