Export limit exceeded: 11697 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 11697 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (11697 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-61186 | 1 Oracle | 1 Agile Engineering Data Management | 2026-08-02 | 9.4 Critical |
| Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as unauthorized read access to a subset of Oracle Agile Engineering Data Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H). | ||||
| CVE-2026-61187 | 1 Oracle | 1 Agile Engineering Data Management | 2026-08-02 | 2.8 Low |
| Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 2.8 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L). | ||||
| CVE-2026-61190 | 1 Oracle | 1 Agile Engineering Data Management | 2026-08-02 | 6.4 Medium |
| Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N). | ||||
| CVE-2026-61192 | 1 Oracle | 1 Agile Engineering Data Management | 2026-08-02 | 5.3 Medium |
| Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H). | ||||
| CVE-2026-61194 | 1 Oracle | 1 Agile Engineering Data Management | 2026-08-02 | 6.5 Medium |
| Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). | ||||
| CVE-2026-24537 | 2 Alex Volkov, Wordpress | 2 Wp Accessibility Helper, Wordpress | 2026-08-02 | 4.3 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions. | ||||
| CVE-2026-27372 | 2 Peprodev, Wordpress | 2 Peprodev Ultimate Invoice, Wordpress | 2026-08-02 | 6.5 Medium |
| Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions. | ||||
| CVE-2026-27391 | 2 Stylemixthemes, Wordpress | 2 Ulisting, Wordpress | 2026-08-02 | 5.4 Medium |
| Subscriber Broken Access Control in uListing <= 2.2.0 versions. | ||||
| CVE-2026-27392 | 2 Stylemixthemes, Wordpress | 2 Ulisting, Wordpress | 2026-08-02 | 4.3 Medium |
| Contributor Broken Access Control in uListing <= 2.2.0 versions. | ||||
| CVE-2026-27423 | 2 Rolandbarkerxnauwebdesign, Wordpress | 2 Participants Database, Wordpress | 2026-08-02 | 4.3 Medium |
| Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions. | ||||
| CVE-2026-57367 | 2 Wordpress, Wpbookingsystem | 2 Wordpress, Wp Booking System | 2026-08-02 | 7.1 High |
| Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions. | ||||
| CVE-2026-57701 | 2 Webcodingplace, Wordpress | 2 Real Estate Manager, Wordpress | 2026-08-02 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions. | ||||
| CVE-2026-57717 | 2 Knit Pay, Wordpress | 2 Knit Pay, Wordpress | 2026-08-02 | 6.5 Medium |
| Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions. | ||||
| CVE-2026-57767 | 2 Codecabin, Wordpress | 2 Wp Google Maps, Wordpress | 2026-08-02 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions. | ||||
| CVE-2026-57784 | 2 Ninjaforms, Wordpress | 2 Ninja Forms File Uploads, Wordpress | 2026-08-02 | 9.6 Critical |
| Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | ||||
| CVE-2026-59513 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-08-02 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions. | ||||
| CVE-2026-59524 | 2 Sandhillsdev, Wordpress | 2 Easy Digital Downloads, Wordpress | 2026-08-02 | 6.5 Medium |
| Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions. | ||||
| CVE-2026-59525 | 2 Rolandbarkerxnauwebdesign, Wordpress | 2 Participants Database, Wordpress | 2026-08-02 | 9.3 Critical |
| Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. | ||||
| CVE-2026-59540 | 2 Cozyvision, Wordpress | 2 Sms Alert Order Notifications, Wordpress | 2026-08-02 | 9.8 Critical |
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. | ||||
| CVE-2026-59544 | 2 Thrivethemes, Wordpress | 2 Thrive Quiz Builder, Wordpress | 2026-08-02 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. | ||||