Export limit exceeded: 33687 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 33687 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (33687 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16620 | 2026-08-06 | 7.5 High | ||
| The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in "Select" price mode, allowing an unauthenticated visitor to add such a product to the cart at an arbitrary value below the merchant-defined allowed prices and commit a real order at that price (revenue loss / underpriced orders). This is a distinct, unfixed vector from CVE-2025-12115, whose 2.2.0 fix only addressed applying a custom price to products where Name Your Price is disabled and left the Select-mode allowlist unenforced through 2.2.4. | ||||
| CVE-2026-15208 | 2 Registrationmagic, Wordpress | 2 Registrationmagic, Wordpress | 2026-08-06 | 5.3 Medium |
| The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, payee, or prior use against the registration it is finalising: its server-side check only confirms the capture status is COMPLETED. An unauthenticated attacker can therefore finalise an expensive paid registration with any genuinely-completed low-value capture, and replay a single capture across unlimited registrations because captures are not de-duplicated. | ||||
| CVE-2024-39024 | 2026-08-06 | N/A | ||
| In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution. | ||||
| CVE-2026-12584 | 2026-08-06 | 7.5 High | ||
| The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own orders without paying. | ||||
| CVE-2026-12501 | 2026-08-06 | 5.3 Medium | ||
| The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, nor that the paid amount matches the order total, before marking a booking as paid, allowing unauthenticated attackers to mark bookings as fully paid using a token payment made to an attacker-controlled account. | ||||
| CVE-2026-10524 | 2026-08-06 | 7.5 High | ||
| The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are added to the cart through one of its public REST API endpoints, allowing unauthenticated users to set arbitrary product prices and complete WooCommerce orders at manipulated totals. | ||||
| CVE-2025-6508 | 1 Wso2 | 2 Api Manager, Wso2 Api Manager | 2026-08-06 | 4.3 Medium |
| The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to be loaded, overriding the existing API definitions within the Publisher portal. By exploiting this vulnerability, malicious actors can deceive users into interacting with these overwritten API definitions. This could lead to the exposure of sensitive information or the initiation of unintended requests to backend services. | ||||
| CVE-2026-63508 | 1 Microsoft | 1 Planetary Computer Pro | 2026-08-06 | 10 Critical |
| Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-50515 | 1 Microsoft | 1 Azure Service Bus | 2026-08-06 | 9.9 Critical |
| Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-56162 | 1 Microsoft | 1 Azure Sql Database | 2026-08-06 | 10 Critical |
| Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-62830 | 1 Microsoft | 1 Azure Sre Agent | 2026-08-06 | 9.9 Critical |
| Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-70332 | 1 Microsoft | 1 Sharepoint Online | 2026-08-06 | 9.6 Critical |
| Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | ||||
| CVE-2026-68823 | 1 Microsoft | 1 Azure Confidential Ledger | 2026-08-06 | 9.1 Critical |
| Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-49163 | 1 Microsoft | 1 Application Insights Profiler | 2026-08-06 | 8.8 High |
| Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-62836 | 1 Microsoft | 1 Azure Sql Managed Instance | 2026-08-06 | 8.7 High |
| Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-15805 | 2026-08-06 | N/A | ||
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||||
| CVE-2026-17264 | 2026-08-06 | 4.3 Medium | ||
| Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write, which may allow an attacker to remotely execute arbitrary code. | ||||
| CVE-2026-34191 | 1 Apache | 1 Portable Runtime Utility | 2026-08-06 | 9.1 Critical |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3 | ||||
| CVE-2026-71555 | 2026-08-06 | 4.1 Medium | ||
| PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS does not send a Cross-Origin-Opener-Policy response header, so pages opened by PILOS via a link that opens a new browsing context (e.g., target="_blank") retain a window.opener reference back to the originating PILOS tab. A malicious destination page reached this way can use window.opener to navigate or manipulate the original PILOS tab, a technique known as reverse tabnabbing, potentially redirecting an authenticated user to a phishing page that mimics PILOS. This issue is fixed in version 4.14.1. | ||||
| CVE-2026-71554 | 2026-08-06 | 5.3 Medium | ||
| h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1. | ||||