Export limit exceeded: 367807 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 367807 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (367807 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-8945 | 2026-09-02 | 5.3 Medium | ||
| The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API. | ||||
| CVE-2025-15692 | 2026-09-02 | 3.5 Low | ||
| The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users with the Administrator role and above to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2025-15490 | 2026-09-02 | 5.3 Medium | ||
| The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs | ||||
| CVE-2025-15489 | 2026-09-02 | 5.3 Medium | ||
| The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content | ||||
| CVE-2025-15485 | 2026-09-02 | 8.2 High | ||
| The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc | ||||
| CVE-2025-15481 | 2026-09-02 | 5.3 Medium | ||
| The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails. | ||||
| CVE-2024-3773 | 2026-09-02 | 5.9 Medium | ||
| The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | ||||
| CVE-2023-3360 | 2026-09-02 | 3.3 Low | ||
| The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog. | ||||
| CVE-2026-73841 | 1 Openchoreo | 1 Openchoreo | 2026-09-02 | 8.8 High |
| OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.1.6 and 1.2.3, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view using the caller-supplied project query parameter instead of comp.Spec.Owner.ProjectName, allowing a user with a project-scoped grant to execute commands in and read wirelogs from components owned by other projects in the same namespace. This vulnerability is fixed in 1.1.6 and 1.2.3. | ||||
| CVE-2026-14828 | 1 Zohocorp | 3 Manageengine Access Manager Plus, Manageengine Pam360, Manageengine Password Manager Pro | 2026-09-02 | 8.8 High |
| Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability. | ||||
| CVE-2026-16647 | 1 Drupal | 1 Disable Login Page | 2026-09-02 | N/A |
| Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4. | ||||
| CVE-2026-24183 | 1 Nvidia | 1 Cumulus Linux | 2026-09-02 | 7.8 High |
| NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on the system. A successful exploit of this vulnerability might lead to escalation of privileges. | ||||
| CVE-2026-49809 | 1 Dell | 2 Cyber Recovery, Powerprotect Cyber Recovery | 2026-09-02 | 6.5 Medium |
| Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | ||||
| CVE-2026-24184 | 1 Nvidia | 1 Cumulus Linux | 2026-09-02 | 7.5 High |
| NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an unauthenticated attacker on an adjacent network could cause buffer overflow by sending crafted LLDP frames. A successful exploit of this vulnerability might lead to code execution. | ||||
| CVE-2026-84122 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-09-02 | 5.4 Medium |
| Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | ||||
| CVE-2026-84123 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-09-02 | 8.8 High |
| Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | ||||
| CVE-2026-84124 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-09-02 | 5.4 Medium |
| Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | ||||
| CVE-2026-84125 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-09-02 | 5.4 Medium |
| Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | ||||
| CVE-2026-47606 | 2 Linux, Nvidia | 2 Linux Kernel, Triton Inference Server | 2026-09-02 | 6.5 Medium |
| NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure. | ||||
| CVE-2026-78603 | 1 Elastic | 1 Kibana | 2026-09-02 | 4.3 Medium |
| Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch privileges could bypass Kibana feature authorization and space access controls, resulting in the unauthorized disclosure of Fleet deployment metadata from the default Kibana space. | ||||