Export limit exceeded: 369862 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (369862 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-59555 | 2026-07-23 | 10 Critical | ||
| Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. | ||||
| CVE-2026-59554 | 2026-07-23 | 7.5 High | ||
| Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions. | ||||
| CVE-2026-59547 | 2026-07-23 | 7.5 High | ||
| Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions. | ||||
| CVE-2026-59543 | 2026-07-23 | 9.9 Critical | ||
| Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions. | ||||
| CVE-2026-59542 | 2026-07-23 | 7.7 High | ||
| Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions. | ||||
| CVE-2026-59540 | 2026-07-23 | 9.8 Critical | ||
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. | ||||
| CVE-2026-59525 | 2026-07-23 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. | ||||
| CVE-2026-59517 | 2026-07-23 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions. | ||||
| CVE-2026-57717 | 2026-07-23 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions. | ||||
| CVE-2026-57716 | 2026-07-23 | 5.3 Medium | ||
| Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions. | ||||
| CVE-2026-57699 | 2026-07-23 | 7.1 High | ||
| Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions. | ||||
| CVE-2026-27422 | 2026-07-23 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions. | ||||
| CVE-2026-27399 | 2026-07-23 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions. | ||||
| CVE-2026-27372 | 2026-07-23 | 6.5 Medium | ||
| Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions. | ||||
| CVE-2026-25405 | 2026-07-23 | 8.5 High | ||
| Contributor SQL Injection in eRoom <= 1.7.1 versions. | ||||
| CVE-2026-24639 | 2026-07-23 | 4.4 Medium | ||
| Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions. | ||||
| CVE-2026-24628 | 2026-07-23 | 5.9 Medium | ||
| Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions. | ||||
| CVE-2026-24537 | 2026-07-23 | 4.3 Medium | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions. | ||||
| CVE-2025-68081 | 2026-07-23 | 5.9 Medium | ||
| Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions. | ||||
| CVE-2026-47708 | 1 Sepinetam | 1 Stata-mcp | 2026-07-23 | N/A |
| MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and CLI is directly interpolated into a Stata command string without sanitization. The security guard (`GuardValidator`) only scans the do-file content but does not validate this parameter. An attacker can inject arbitrary Stata commands (including `shell`, `python`, `erase`, etc.) by crafting a malicious `log_file_name` containing quotes, newlines, or Stata command separators. Version 1.17.3 contains a patch for the issue. | ||||