Export limit exceeded: 377270 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (377270 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-70547 | 1 Jfrog | 1 Artifactory | 2026-08-13 | 4.3 Medium |
| An authenticated user without repository read permission may access package metadata under specific conditions. | ||||
| CVE-2026-70467 | 1 Fortinet | 1 Fortisiem | 2026-08-13 | 3.4 Low |
| A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here> | ||||
| CVE-2026-6821 | 1 Gitlab | 1 Gitlab | 2026-08-13 | 4.3 Medium |
| GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to bypass IP-based access restrictions and read limited merge request information from a private project due to missing authorization checks in a merge requests API endpoint. | ||||
| CVE-2026-6469 | 1 Postgresql | 1 Postgresql | 2026-08-13 | 3.8 Low |
| Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | ||||
| CVE-2026-6464 | 1 Postgresql | 1 Postgresql | 2026-08-13 | 8.1 High |
| Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | ||||
| CVE-2026-69105 | 1 Jfrog | 1 Artifactory | 2026-08-13 | 8.1 High |
| An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability. | ||||
| CVE-2026-66878 | 1 Redhat | 2 Acm, Advanced Cluster Management For Kubernetes | 2026-08-13 | 7.7 High |
| A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret contents from other namespaces into their own, leading to information disclosure. | ||||
| CVE-2026-66704 | 2026-08-13 | 7.2 High | ||
| Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. | ||||
| CVE-2026-66658 | 2026-08-13 | 8.5 High | ||
| Subscriber SQL Injection in Reviewer <= 3.14.2 versions. | ||||
| CVE-2026-66657 | 2026-08-13 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions. | ||||
| CVE-2026-66656 | 2026-08-13 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions. | ||||
| CVE-2026-66653 | 2026-08-13 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions. | ||||
| CVE-2026-66467 | 2026-08-13 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. | ||||
| CVE-2026-66461 | 2026-08-13 | 7.5 High | ||
| Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. | ||||
| CVE-2026-66453 | 2 Dimitri Grassi, Wordpress | 2 Salon Booking System, Wordpress | 2026-08-13 | 9.8 Critical |
| Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. | ||||
| CVE-2026-66450 | 2 Dylan Kuhn, Wordpress | 2 Geo Mashup, Wordpress | 2026-08-13 | 8.1 High |
| Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions. | ||||
| CVE-2026-66444 | 2026-08-13 | 6.5 Medium | ||
| Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions. | ||||
| CVE-2026-66443 | 2 Pete Nelson, Wordpress | 2 Rest Api Log, Wordpress | 2026-08-13 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions. | ||||
| CVE-2026-66441 | 2 Multivendorx, Wordpress | 2 Multivendorx, Wordpress | 2026-08-13 | 7.5 High |
| Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions. | ||||
| CVE-2026-66436 | 2 Realmag777, Wordpress | 2 Active Products Tables For Woocommerce, Wordpress | 2026-08-13 | 9.3 Critical |
| Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. | ||||