Export limit exceeded: 369970 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (369970 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-24259 | 1 Apple | 1 Macos | 2026-07-23 | 9.8 Critical |
| This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check. | ||||
| CVE-2026-24537 | 2026-07-23 | 4.3 Medium | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions. | ||||
| CVE-2026-27392 | 2026-07-23 | 4.3 Medium | ||
| Contributor Broken Access Control in uListing <= 2.2.0 versions. | ||||
| CVE-2026-25466 | 2 Wordpress, Wpgmaps | 2 Wordpress, Wp Go Maps | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions. | ||||
| CVE-2026-46990 | 1 Oracle | 1 Enterprise Manager Base Platform | 2026-07-23 | 7.3 High |
| Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L). | ||||
| CVE-2026-27391 | 2026-07-23 | 5.4 Medium | ||
| Subscriber Broken Access Control in uListing <= 2.2.0 versions. | ||||
| CVE-2026-27423 | 2026-07-23 | 4.3 Medium | ||
| Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions. | ||||
| CVE-2026-57767 | 2026-07-23 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions. | ||||
| CVE-2026-59512 | 2 Piwebsolution, Wordpress | 2 Product Enquiry For Woocommerce, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions. | ||||
| CVE-2026-46989 | 1 Oracle | 1 Enterprise Manager Base Platform | 2026-07-23 | 9.1 Critical |
| Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data as well as unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L). | ||||
| CVE-2026-59525 | 2026-07-23 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. | ||||
| CVE-2026-59544 | 2026-07-23 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. | ||||
| CVE-2026-61944 | 2 Bookly, Wordpress | 2 Bookly, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions. | ||||
| CVE-2026-65463 | 2026-07-23 | 5.4 Medium | ||
| Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions. | ||||
| CVE-2026-65469 | 2026-07-23 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions. | ||||
| CVE-2026-65482 | 2026-07-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions. | ||||
| CVE-2026-65488 | 2026-07-23 | 7.1 High | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions. | ||||
| CVE-2026-65494 | 2026-07-23 | 7.1 High | ||
| Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions. | ||||
| CVE-2026-48864 | 2 Opensuse, Redhat | 9 Libsolv, Enterprise Linux, Hardened Images and 6 more | 2026-07-23 | 7.8 High |
| A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service. | ||||
| CVE-2025-10911 | 1 Redhat | 11 Discovery, Enterprise Linux, Enterprise Linux Eus and 8 more | 2026-07-23 | 5.5 Medium |
| A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash. | ||||