Export limit exceeded: 37125 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (37125 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-70445 | 1 Jenkins Project | 1 Jenkins Sauce Ondemand Plugin | 2026-08-07 | 4.3 Medium |
| Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | ||||
| CVE-2026-70446 | 1 Jenkins Project | 1 Jenkins Codesonar Plugin | 2026-08-07 | 4.3 Medium |
| Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | ||||
| CVE-2026-70447 | 1 Jenkins Project | 1 Jenkins Aws Codebuild Plugin | 2026-08-07 | 4.3 Medium |
| Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | ||||
| CVE-2026-70448 | 1 Jenkins Project | 1 Jenkins Ivy Report Plugin | 2026-08-07 | 7.1 High |
| Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files. | ||||
| CVE-2026-63457 | 1 Hpe | 1 Hpe Integrated Lights-out 6 | 2026-08-07 | 6.5 Medium |
| A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78. | ||||
| CVE-2026-70615 | 1 Boringproxy | 1 Boringproxy | 2026-08-07 | 9.9 Critical |
| boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in the domain parameter of the tunnel creation endpoint. Attackers can insert an unrestricted public key entry into authorized_keys to gain persistent shell access, and subsequently read cleartext credentials from the database file including all user tokens, tunnel private keys, and TLS certificates. | ||||
| CVE-2026-70616 | 1 Boringproxy | 1 Boringproxy | 2026-08-07 | 6.5 Medium |
| boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanently exhaust server file descriptors, goroutines, and memory by sending requests to the GET /loading endpoint with attacker-supplied id query parameter values. Because the handler performs no map-lookup validity check and receives on a nil channel that blocks forever, with no timeout, no context cancellation, and no server-side reclamation due to absent HTTP server timeouts, each malicious request permanently holds one goroutine, one file descriptor, and approximately 50 kB of memory until the server's file descriptor limit is reached and listener Accept calls fail, halting all tunnel traffic forwarding for all users. | ||||
| CVE-2026-70617 | 1 Spacebar Server | 1 Spacebar Server | 2026-08-07 | 8.1 High |
| Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without membership verification. Attackers can exploit the unguarded PUT /channels/{channel_id}/recipients/{user_id} handler to join private group DMs, read complete message history, post messages as a participant, and force-add third-party users without their consent. | ||||
| CVE-2026-70618 | 1 Spacebar Server | 1 Spacebar Server | 2026-08-07 | 4.3 Medium |
| Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user to enumerate complete guild membership by querying the GET /guilds/{guild_id}/roles/{role_id}/member-ids endpoint without guild membership verification. Attackers can exploit the unprotected route handler in the roles member-ids endpoint, which lacks permission checks present in sibling endpoints, to retrieve the full list of member user IDs for any guild on the instance using only a valid bearer token and a known guild ID. | ||||
| CVE-2026-21766 | 1 Hcltech | 1 Digital Experience Compose | 2026-08-07 | 5.4 Medium |
| The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs. This only affects applications using the default login portlet. | ||||
| CVE-2026-18411 | 1 Acrisure | 2 Dr-100, Karr Bt | 2026-08-07 | 8.1 High |
| The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the vehicle, potentially allowing unauthorized access to vehicle functions, including door unlocking and engine immobilization. | ||||
| CVE-2026-17583 | 1 Thermo Fisher | 8 Abi Prism 3100/3100-avant Data Collection Software, Abi Prism 310 Data Collection Software, Applied Biosystems 3130 Series Data Collection Software and 5 more | 2026-08-07 | 8.4 High |
| The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes. | ||||
| CVE-2026-18839 | 2 Popt-devel, Redhat | 6 Popt-static, Enterprise Linux, Hardened Images and 3 more | 2026-08-07 | 2.2 Low |
| An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application. | ||||
| CVE-2026-16636 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluentsmtp – Wp Smtp Plugin With Amazon Ses, Sendgrid, Mailgun, Postmark, Cloudflare, Tosend, Gmail And Any Smtp | 2026-08-07 | 7.2 High |
| The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs in all versions up to, and including, 2.2.95 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is delivered via an attacker-controlled recipient display name (to.name) in a wp_mail() call and does not fire in the log list view — only in the detail view when an administrator uses the Prev/Next navigation controls, as that path bypasses the escapeHtml pipeline used by the list view. | ||||
| CVE-2026-15991 | 2 Bitpressadmin, Wordpress | 2 File Manager, Wordpress | 2026-08-07 | 8.8 High |
| The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary files on the server, which can lead to remote code execution when the right file is deleted (such as wp-config.php). The bypass is triggered by passing cmd=rm or cmf=file in the URL query string of a POST request: elFinder's bind registration reads the command exclusively from $_POST and therefore never registers the rm.pre permission handler, while the dispatcher reads from the merged $_GET+$_POST superglobal and executes the rm or file command unchecked against a volume that defaults to ABSPATH. | ||||
| CVE-2026-18909 | 1 Elan Microelectronics Corp. | 1 Elan Smart-pad | 2026-08-07 | 4.7 Medium |
| A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range value to be forwarded to ETD.sys where it is used as a loop counter for a stack buffer copy without destination size validation. A local attacker with standard user privileges can trigger a kernel bugcheck (BSOD 0xF7 DRIVER_OVERRAN_STACK_BUFFER), resulting in denial of service. This issue affects ELAN Smart-Pad through ETD24.21.52.3. | ||||
| CVE-2026-15459 | 2 Wordpress, Wpmudev | 2 Wordpress, Wpmu Dev Dashboard | 2026-08-07 | 8.1 High |
| The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys the WDP-AUTH request signature is empty, making the signature verified by validate_hash() trivially forgeable; version 5.0.0 additionally removed the replay check in validate_nonce(), and the remote handler is bound to the public init hook with no capability check. This makes it possible for unauthenticated attackers to invoke privileged Hub actions — including installing and activating a plugin from an attacker-supplied URL (resulting in remote code execution), deleting plugins and themes, upgrading WordPress core, or logging in as an administrator via SSO. Sites connected to a WPMU DEV account, which have a non-empty 64-character API key, are not affected. | ||||
| CVE-2026-18400 | 2 Metaslider, Wordpress | 2 Slider, Gallery, And Carousel By Metaslider – Image Slider, Video Slider, Wordpress | 2026-08-07 | 6.4 Medium |
| The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and including, 3.111.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The ml-slider custom post type is registered without custom capability restrictions and the ml-slider_settings meta key is unprotected, allowing Author-level users to set the malicious delay value via XML-RPC custom_fields when creating an ml-slider post. | ||||
| CVE-2025-15678 | 2 Posimyth, Wordpress | 2 Nexter Blocks, Wordpress | 2026-08-07 | 6.1 Medium |
| The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Author by default), allowing them to upload a file containing malicious JavaScript that executes when the file is accessed, leading to Stored Cross-Site Scripting. | ||||
| CVE-2026-14204 | 2 Ivan, Wordpress | 2 Google Authenticator Wordpress, Wordpress | 2026-08-07 | 6.5 Medium |
| The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out of their account. | ||||