Export limit exceeded: 370925 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 370925 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 370925 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 370925 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (370925 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-66004 1 Ahujasid 1 Blender-mcp 2026-07-27 5.3 Medium
BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitrary files by injecting traversal sequences in API response include keys. Attackers performing MITM attacks or prompt injection can supply malicious paths like '../../.bashrc' to overwrite sensitive files and achieve persistent code execution.
CVE-2026-66011 1 Imagemagick 1 Imagemagick 2026-07-27 3.3 Low
ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources.
CVE-2026-59527 2 Romancode, Wordpress 2 Mapsvg, Wordpress 2026-07-27 9.3 Critical
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-59533 2 Christoph Vielgrader, Wordpress 2 Relevanssi Light, Wordpress 2026-07-27 9.3 Critical
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
CVE-2026-59560 2 Roxnor, Wordpress 2 Fundengine, Wordpress 2026-07-27 6.5 Medium
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
CVE-2026-65568 2026-07-27 5 Medium
Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.
CVE-2026-66438 2026-07-27 5.3 Medium
Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.
CVE-2026-66476 2026-07-27 4.9 Medium
Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.
CVE-2026-60613 1 Oracle 1 Peoplesoft Enterprise Cs Student Records 2026-07-27 6.6 Medium
Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Student Records. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
CVE-2026-17531 1 Unitedbyai 1 Droidclaw 2026-07-27 5 Medium
A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Unsigned Scheduled Callback. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitation is known to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-16380 1 Mozilla 1 Firefox 2026-07-27 9.1 Critical
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16382 1 Mozilla 1 Firefox 2026-07-27 9.8 Critical
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16384 1 Mozilla 1 Firefox 2026-07-27 7.5 High
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16394 1 Mozilla 1 Firefox 2026-07-27 9.1 Critical
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16395 1 Mozilla 1 Firefox 2026-07-27 9.8 Critical
Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16397 1 Mozilla 1 Firefox 2026-07-27 6.5 Medium
Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.
CVE-2026-16398 1 Mozilla 1 Firefox 2026-07-27 7.5 High
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16400 1 Mozilla 1 Firefox 2026-07-27 7.5 High
Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16403 1 Mozilla 1 Firefox 2026-07-27 6.5 Medium
Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVE-2026-16404 1 Mozilla 1 Firefox 2026-07-27 7.4 High
Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.