Export limit exceeded: 377266 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 377266 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 377266 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (377266 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66658 | 2026-08-13 | 8.5 High | ||
| Subscriber SQL Injection in Reviewer <= 3.14.2 versions. | ||||
| CVE-2026-66657 | 2026-08-13 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions. | ||||
| CVE-2026-66656 | 2026-08-13 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions. | ||||
| CVE-2026-66653 | 2026-08-13 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions. | ||||
| CVE-2026-66467 | 2026-08-13 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. | ||||
| CVE-2026-66461 | 2026-08-13 | 7.5 High | ||
| Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. | ||||
| CVE-2026-66453 | 2 Dimitri Grassi, Wordpress | 2 Salon Booking System, Wordpress | 2026-08-13 | 9.8 Critical |
| Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. | ||||
| CVE-2026-66450 | 2 Dylan Kuhn, Wordpress | 2 Geo Mashup, Wordpress | 2026-08-13 | 8.1 High |
| Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions. | ||||
| CVE-2026-66444 | 2026-08-13 | 6.5 Medium | ||
| Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions. | ||||
| CVE-2026-66443 | 2 Pete Nelson, Wordpress | 2 Rest Api Log, Wordpress | 2026-08-13 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions. | ||||
| CVE-2026-66441 | 2 Multivendorx, Wordpress | 2 Multivendorx, Wordpress | 2026-08-13 | 7.5 High |
| Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions. | ||||
| CVE-2026-66436 | 2 Realmag777, Wordpress | 2 Active Products Tables For Woocommerce, Wordpress | 2026-08-13 | 9.3 Critical |
| Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. | ||||
| CVE-2026-66430 | 2026-08-13 | 8.5 High | ||
| Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | ||||
| CVE-2026-66429 | 2026-08-13 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | ||||
| CVE-2026-66424 | 2026-08-13 | 9.8 Critical | ||
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. | ||||
| CVE-2026-66378 | 1 Jfrog | 1 Artifactory | 2026-08-13 | 4.3 Medium |
| An authenticated user without repository read permission may access private NuGet metadata under specific conditions. | ||||
| CVE-2026-66377 | 1 Jfrog | 1 Artifactory | 2026-08-13 | 5.3 Medium |
| An unauthenticated user may access restricted repository information under specific conditions. | ||||
| CVE-2026-65582 | 2 Liquidthemes, Wordpress | 2 Ai Hub, Wordpress | 2026-08-13 | 7.7 High |
| Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions. | ||||
| CVE-2026-64954 | 1 Rapid7 | 1 Velociraptor | 2026-08-13 | 8.2 High |
| Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "investigator" role). This vulnerability is an escalation from an analyst to investigator role. | ||||
| CVE-2026-61967 | 2026-08-13 | 9.8 Critical | ||
| Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. | ||||