Export limit exceeded: 33413 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (33413 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16071 | 1 Redhat | 4 Build Keycloak, Jboss Data Grid, Jbosseapxp and 1 more | 2026-08-06 | 5.4 Medium |
| A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the system allows lookups for users located outside the configured search boundary, leading to the disclosure of account information from unauthorized parts of the directory and unintended importing of those users into local storage. | ||||
| CVE-2026-70430 | 1 Jenkins Project | 1 Jenkins | 2026-08-06 | 2.7 Low |
| Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators. | ||||
| CVE-2026-70433 | 2026-08-06 | 4.3 Medium | ||
| Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | ||||
| CVE-2026-70435 | 2026-08-06 | 4.2 Medium | ||
| A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | ||||
| CVE-2026-70436 | 1 Jenkins Project | 1 Jenkins External Workspace Manager Plugin | 2026-08-06 | 4.3 Medium |
| Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in workspaces they are not authorized to access. | ||||
| CVE-2026-70637 | 1 Hfiref0x | 1 Lightftp | 2026-08-06 | 5.9 Medium |
| LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by issuing LIST followed by ABOR commands without authentication. The control thread closes data_socket and file_fd descriptors while worker threads concurrently operate on the same fields in worker_thread_cleanup, allowing stale file descriptors to be reassigned by the OS and subsequently used by worker threads on unrelated resources, resulting in potential denial of service. | ||||
| CVE-2026-66712 | 2 Wordpress, Wp.insider | 2 Wordpress, Simple Membership | 2026-08-06 | 7.5 High |
| Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions. | ||||
| CVE-2026-25403 | 2 Bdthemes, Wordpress | 2 Utlimate Store Kit Elementor Addons, Wordpress | 2026-08-06 | 6.5 Medium |
| Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | ||||
| CVE-2026-28183 | 2 Publishpress, Wordpress | 2 Capabilities, Wordpress | 2026-08-06 | 7.2 High |
| Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions. | ||||
| CVE-2026-66440 | 2 Wordpress, Xplodedthemes | 2 Wordpress, Wpide - File Manager & Code Editor | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions. | ||||
| CVE-2026-66701 | 2 Cozmoslabs, Wordpress | 2 Profile Builder, Wordpress | 2026-08-06 | 5.3 Medium |
| Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions. | ||||
| CVE-2026-66706 | 2 Markjaquith, Wordpress | 2 Subscribe To Comments, Wordpress | 2026-08-06 | 5.9 Medium |
| Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions. | ||||
| CVE-2025-63822 | 2026-08-06 | 8.1 High | ||
| SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is authorized to access the target user's data. | ||||
| CVE-2025-63823 | 2026-08-06 | 9.8 Critical | ||
| My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values. | ||||
| CVE-2026-67871 | 1 Systerel | 1 S2opc | 2026-08-06 | 7.5 High |
| Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server | ||||
| CVE-2026-14313 | 2026-08-06 | 5.3 Medium | ||
| PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is vulnerable to unauthenticated missing-authorization / IDOR write. Requires WooCommerce. | ||||
| CVE-2026-14314 | 2026-08-06 | 5.3 Medium | ||
| The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated attackers to forge a token and disclose image attachments, including other customers' uploaded payment receipts, that they do not own. | ||||
| CVE-2026-14240 | 2 Tourmaster, Wordpress | 2 Tourmaster, Wordpress | 2026-08-06 | 5.3 Medium |
| The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its publicly accessible directory with no access control, allowing unauthenticated users to download the exported customers' personal information once an administrator has run an export. | ||||
| CVE-2026-16290 | 2 Profilegrid, Wordpress | 2 Profilegrid, Wordpress | 2026-08-06 | 5.3 Medium |
| The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin before 6.0.0.0's member-visibility setting. | ||||
| CVE-2026-18050 | 2026-08-06 | 7.5 High | ||
| The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The identifier is high-entropy, is disclosed only to the uploader, and the file is removed on submission or by a scheduled cleanup, so a cross-user read is not achievable by guessing alone. | ||||