Export limit exceeded: 370925 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 370925 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 370925 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 370925 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (370925 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66004 | 1 Ahujasid | 1 Blender-mcp | 2026-07-27 | 5.3 Medium |
| BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitrary files by injecting traversal sequences in API response include keys. Attackers performing MITM attacks or prompt injection can supply malicious paths like '../../.bashrc' to overwrite sensitive files and achieve persistent code execution. | ||||
| CVE-2026-66011 | 1 Imagemagick | 1 Imagemagick | 2026-07-27 | 3.3 Low |
| ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources. | ||||
| CVE-2026-59527 | 2 Romancode, Wordpress | 2 Mapsvg, Wordpress | 2026-07-27 | 9.3 Critical |
| Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | ||||
| CVE-2026-59533 | 2 Christoph Vielgrader, Wordpress | 2 Relevanssi Light, Wordpress | 2026-07-27 | 9.3 Critical |
| Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions. | ||||
| CVE-2026-59560 | 2 Roxnor, Wordpress | 2 Fundengine, Wordpress | 2026-07-27 | 6.5 Medium |
| Subscriber Broken Access Control in FundEngine <= 1.7.8 versions. | ||||
| CVE-2026-65568 | 2026-07-27 | 5 Medium | ||
| Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions. | ||||
| CVE-2026-66438 | 2026-07-27 | 5.3 Medium | ||
| Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions. | ||||
| CVE-2026-66476 | 2026-07-27 | 4.9 Medium | ||
| Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions. | ||||
| CVE-2026-60613 | 1 Oracle | 1 Peoplesoft Enterprise Cs Student Records | 2026-07-27 | 6.6 Medium |
| Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Student Records. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H). | ||||
| CVE-2026-17531 | 1 Unitedbyai | 1 Droidclaw | 2026-07-27 | 5 Medium |
| A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Unsigned Scheduled Callback. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitation is known to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-16380 | 1 Mozilla | 1 Firefox | 2026-07-27 | 9.1 Critical |
| Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-16382 | 1 Mozilla | 1 Firefox | 2026-07-27 | 9.8 Critical |
| Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-16384 | 1 Mozilla | 1 Firefox | 2026-07-27 | 7.5 High |
| Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-16394 | 1 Mozilla | 1 Firefox | 2026-07-27 | 9.1 Critical |
| Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-16395 | 1 Mozilla | 1 Firefox | 2026-07-27 | 9.8 Critical |
| Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-16397 | 1 Mozilla | 1 Firefox | 2026-07-27 | 6.5 Medium |
| Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16398 | 1 Mozilla | 1 Firefox | 2026-07-27 | 7.5 High |
| Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-16400 | 1 Mozilla | 1 Firefox | 2026-07-27 | 7.5 High |
| Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-16403 | 1 Mozilla | 1 Firefox | 2026-07-27 | 6.5 Medium |
| Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | ||||
| CVE-2026-16404 | 1 Mozilla | 1 Firefox | 2026-07-27 | 7.4 High |
| Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153. | ||||