Export limit exceeded: 37161 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (37161 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66439 | 2 Berocket, Wordpress | 2 Advanced Ajax Product Filters, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions. | ||||
| CVE-2026-19061 | 1 Insta | 1 Instaknxserviceapp | 2026-08-06 | 3.7 Low |
| A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a manipulation can lead to insufficient verification of data authenticity. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation is known to be difficult. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-65545 | 2 Jordy Meow, Wordpress | 2 Ai-engine, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions. | ||||
| CVE-2026-65560 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions. | ||||
| CVE-2026-65577 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. | ||||
| CVE-2026-66457 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions. | ||||
| CVE-2026-18427 | 2026-08-06 | 7.5 High | ||
| @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching and before delegating to the send layer. As a result, an unauthenticated attacker could request a file protected by a route based guard using a non canonical path form that misses the guarded route yet resolves back onto the protected file, disclosing its contents. Applications that protect a subtree of the static root with a route based guard are affected, while applications relying on the allowedPath option are not. This is fixed in @fastify/static 10.1.3, which canonicalizes the pathname, including rejecting backslashes, on the path used for routing and serving. | ||||
| CVE-2026-3430 | 2026-08-06 | 8.6 High | ||
| The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail. | ||||
| CVE-2026-66678 | 2 Justinkruit, Wordpress | 2 Advanced Custom Fields:font Awesome Field, Wordpress | 2026-08-06 | 4.3 Medium |
| Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions. | ||||
| CVE-2026-66684 | 2 Akshaymenariya, Wordpress | 2 Export Import Menus, Wordpress | 2026-08-06 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions. | ||||
| CVE-2026-66688 | 2 Brainstormforce, Wordpress | 2 Ultimate Addons For Elementor, Wordpress | 2026-08-06 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions. | ||||
| CVE-2026-56699 | 1 Wazuh | 1 Wazuh | 2026-08-06 | N/A |
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Per Wazuh's Security Policy, vulnerabilities affecting only non-GA versions are not eligible for a CVE ID. | ||||
| CVE-2026-66694 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions. | ||||
| CVE-2026-28146 | 2 Unlimited-elements, Wordpress | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Wordpress | 2026-08-06 | 6.5 Medium |
| Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions. | ||||
| CVE-2026-66702 | 2 Rank Math Seo, Wordpress | 2 Rank Math Seo, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions. | ||||
| CVE-2026-34501 | 1 Apache | 1 Portable Runtime Utility | 2026-08-06 | 7.5 High |
| Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue. | ||||
| CVE-2026-66692 | 2 Colissimo, Wordpress | 2 Colissimo Officiel : Méthodes De Livraison Pour Woocommerce, Wordpress | 2026-08-06 | 4.3 Medium |
| Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions. | ||||
| CVE-2026-66695 | 2 Boldgrid, Wordpress | 2 W3 Total Cache, Wordpress | 2026-08-06 | 6.5 Medium |
| Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions. | ||||
| CVE-2026-66703 | 2 Properfraction, Wordpress | 2 Mailoptin, Wordpress | 2026-08-06 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions. | ||||
| CVE-2026-6235 | 2 Sendmachine, Wordpress | 2 Sendmachine For Wordpress, Wordpress | 2026-08-06 | 9.8 Critical |
| The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the plugin's SMTP configuration, which can be leveraged to intercept all outbound emails from the site (including password reset emails). | ||||