Export limit exceeded: 377230 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (377230 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66461 | 2026-08-13 | 7.5 High | ||
| Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. | ||||
| CVE-2026-66455 | 2026-08-13 | 6 Medium | ||
| Subscriber Broken Access Control in ReactPress <= 3.4.0 versions. | ||||
| CVE-2026-66453 | 2 Dimitri Grassi, Wordpress | 2 Salon Booking System, Wordpress | 2026-08-13 | 9.8 Critical |
| Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. | ||||
| CVE-2026-66450 | 2 Dylan Kuhn, Wordpress | 2 Geo Mashup, Wordpress | 2026-08-13 | 8.1 High |
| Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions. | ||||
| CVE-2026-66446 | 2026-08-13 | 9.3 Critical | ||
| Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. | ||||
| CVE-2026-66444 | 2026-08-13 | 6.5 Medium | ||
| Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions. | ||||
| CVE-2026-66443 | 2 Pete Nelson, Wordpress | 2 Rest Api Log, Wordpress | 2026-08-13 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions. | ||||
| CVE-2026-66441 | 2 Multivendorx, Wordpress | 2 Multivendorx, Wordpress | 2026-08-13 | 7.5 High |
| Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions. | ||||
| CVE-2026-66436 | 2 Realmag777, Wordpress | 2 Active Products Tables For Woocommerce, Wordpress | 2026-08-13 | 9.3 Critical |
| Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. | ||||
| CVE-2026-66430 | 2026-08-13 | 8.5 High | ||
| Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | ||||
| CVE-2026-66429 | 2026-08-13 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | ||||
| CVE-2026-66424 | 2026-08-13 | 9.8 Critical | ||
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. | ||||
| CVE-2026-66378 | 1 Jfrog | 1 Artifactory | 2026-08-13 | 4.3 Medium |
| An authenticated user without repository read permission may access private NuGet metadata under specific conditions. | ||||
| CVE-2026-66377 | 1 Jfrog | 1 Artifactory | 2026-08-13 | 5.3 Medium |
| An unauthenticated user may access restricted repository information under specific conditions. | ||||
| CVE-2026-65936 | 2026-08-13 | N/A | ||
| A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below. | ||||
| CVE-2026-65935 | 2026-08-13 | N/A | ||
| Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value. See vulnerability B-E3 in the related paper below. | ||||
| CVE-2026-65934 | 2026-08-13 | N/A | ||
| An unencrypted 'pause encryption request' message causes a denial of service in the BT122 module. See vulnerability B-E10 in the related paper below. | ||||
| CVE-2026-65582 | 2 Liquidthemes, Wordpress | 2 Ai Hub, Wordpress | 2026-08-13 | 7.7 High |
| Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions. | ||||
| CVE-2026-65580 | 2026-08-13 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions. | ||||
| CVE-2026-64954 | 1 Rapid7 | 1 Velociraptor | 2026-08-13 | 8.2 High |
| Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "investigator" role). This vulnerability is an escalation from an analyst to investigator role. | ||||