Export limit exceeded: 15860 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 15860 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 15860 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 15860 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (15860 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-65534 2 Charlie Etienne, Wordpress 2 Custom Links In Elementor Image Carousel, Wordpress 2026-07-23 5.9 Medium
Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.
CVE-2026-65535 2 Takayuki Miyauchi, Wordpress 2 Tinymce Templates, Wordpress 2026-07-23 4.3 Medium
Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
CVE-2026-65536 2 Mahdi Yousefi, Wordpress 2 افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری), Wordpress 2026-07-23 6.5 Medium
Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.
CVE-2026-65539 2 Bimal Rekhadiya, Wordpress 2 Kwayy Html Sitemap, Wordpress 2026-07-23 7.1 High
Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
CVE-2026-65540 2 Metin Saraç, Wordpress 2 Popup For Cf7 With Sweet Alert, Wordpress 2026-07-23 7.1 High
Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.
CVE-2026-65550 2 Wordpress, Wpshopmart 2 Wordpress, Tabs 2026-07-23 5.9 Medium
Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
CVE-2026-61945 2 Multivendorx, Wordpress 2 Woocommerce Product Stock Alert, Wordpress 2026-07-23 6.5 Medium
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.
CVE-2026-16733 1 Bahmutov 1 Find-cypress-specs 2026-07-23 5.3 Medium
A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-8287 1 Bizimhesap Information Systems Industry And Trade 1 Online Pre-accounting Software 2026-07-23 4.3 Medium
Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive Allocation. This issue affects Online Pre-Accounting Software: through 17072026.
CVE-2026-65450 2 Romancode, Wordpress 2 Mapsvg, Wordpress 2026-07-23 8.5 High
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-27403 2 Nerdpress, Wordpress 2 Hubbub Lites, Wordpress 2026-07-23 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3.
CVE-2026-13064 1 Mongodb 1 Mongodb Server 2026-07-23 6.5 Medium
Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in affected MongoDB deployments, potentially leading to resource exhaustion. The resulting CPU-bound operation cannot be interrupted through standard administrative controls.
CVE-2026-13063 1 Mongodb 1 Mongodb Server 2026-07-23 4.3 Medium
An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a crafted aggregation command. MongoDB's libmongocrypt library insufficiently validates payload-supplied values, which can result in an excessively large memory allocation.
CVE-2026-6516 1 Zohocorp 1 Manageengine Adaudit Plus 2026-07-23 10 Critical
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
CVE-2026-16756 1 Aws 1 Aws-smithy-http-server 2026-07-23 7.5 High
Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. To mitigate this issue, users should upgrade to aws-smithy-http-server 0.66.5 or later.
CVE-2026-65594 1 N8n 1 N8n 2026-07-23 N/A
n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. On instances with at least one active MCP Server Trigger workflow configured with n8n OAuth2 authentication, a member-level user can register an OAuth client, self-approve consent for another user's workflow, and obtain a valid token. The workflow then runs in the owner's project context with the owner's stored credentials, and the attacker can set tool inputs and read outputs (potentially including data from the owner's connected integrations), breaking user and project isolation.
CVE-2026-65012 1 Invoke-ai 1 Invokeai 2026-07-23 5.3 Medium
InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_folder endpoint that accepts attacker-controlled scan_path parameters. Unauthenticated attackers can recursively enumerate arbitrary server filesystem directories and use HTTP response codes to determine file existence and readability, bypassing multi-user mode access controls.
CVE-2026-13078 1 Mongodb 1 Mongodb Server 2026-07-23 7.7 High
A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process's privileges. An authenticated user could exploit this through crafted aggregation pipeline commands to read sensitive files accessible to the MongoDB server process.
CVE-2026-13077 1 Mongodb 1 Mongodb Server 2026-07-23 7.1 High
A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pipeline. The vulnerability can be exploited by an authenticated user by generating a malformed BSONColumn data containing a CodeWScope element, bypassing wire-level BSON validation. When the forged element is decompressed, the unchecked size value is used in pointer arithmetic, causing either a server crash or disclosure of adjacent heap memory contents.
CVE-2026-13076 1 Mongodb 1 Mongodb Server 2026-07-23 6.5 Medium
An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation within MongoDB's aggregation framework. The behavior stems from disproportionate memory consumption during this operation, and requires both write access to the database and the ability to run aggregation queries.