Export limit exceeded: 369970 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 369970 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 369970 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 369970 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 369970 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 369970 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 369970 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (369970 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-57374 | 2026-07-23 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions. | ||||
| CVE-2026-60207 | 1 Oracle | 1 Weblogic Server | 2026-07-23 | 8.8 High |
| Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). | ||||
| CVE-2026-57696 | 2 Videowhisper, Wordpress | 2 Picture Gallery, Wordpress | 2026-07-23 | 7.1 High |
| Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions. | ||||
| CVE-2026-57717 | 2026-07-23 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions. | ||||
| CVE-2026-60208 | 1 Oracle | 1 Weblogic Server | 2026-07-23 | 9.1 Critical |
| Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). | ||||
| CVE-2026-57808 | 2 Saad Iqbal, Wordpress | 2 Wp Easypay, Wordpress | 2026-07-23 | 6.5 Medium |
| Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions. | ||||
| CVE-2026-57716 | 2 Videowhisper, Wordpress | 2 Broadcast Live Video, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions. | ||||
| CVE-2026-65474 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Ninja Tables | 2026-07-23 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions. | ||||
| CVE-2026-64802 | 1 Jetbrains | 1 Goland | 2026-07-23 | 7.8 High |
| In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration | ||||
| CVE-2026-64806 | 1 Jetbrains | 1 Webstorm | 2026-07-23 | 8.4 High |
| In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter | ||||
| CVE-2026-64807 | 1 Jetbrains | 1 Webstorm | 2026-07-23 | 7.8 High |
| In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration | ||||
| CVE-2026-64815 | 1 Jetbrains | 1 Intellij Idea | 2026-07-23 | 8.1 High |
| In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files | ||||
| CVE-2026-65908 | 1 Jetbrains | 1 Pycharm | 2026-07-23 | 8.6 High |
| In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open | ||||
| CVE-2026-59522 | 2 Wedevs, Wordpress | 2 Wp Erp, Wordpress | 2026-07-23 | 6.5 Medium |
| Subscriber Broken Access Control in WP ERP <= 1.17.5 versions. | ||||
| CVE-2026-65917 | 2026-07-23 | 8.8 High | ||
| CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup handlers (deleteBackup, fetchRestorePoints, and restorePoint) that allows authenticated panel users to access or manipulate other tenants' backup resources by supplying an attacker-controlled globally sequential IncJob integer ID that is never re-scoped to the authorized domain. Attackers can enumerate sequential backup IDs to read another tenant's backup metadata, irrecoverably delete another tenant's backup snapshots, or trigger unauthorized restoration of another tenant's backup job with root privileges. | ||||
| CVE-2026-61949 | 2 Bookly, Wordpress | 2 Bookly, Wordpress | 2026-07-23 | 9.3 Critical |
| Unauthenticated SQL Injection in Bookly <= 27.7 versions. | ||||
| CVE-2026-61981 | 2026-07-23 | 5.4 Medium | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions. | ||||
| CVE-2026-65454 | 2026-07-23 | 8.5 High | ||
| Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. | ||||
| CVE-2026-65467 | 2026-07-23 | 4.9 Medium | ||
| Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions. | ||||
| CVE-2026-60213 | 1 Oracle | 1 Coherence | 2026-07-23 | 6.5 Medium |
| Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence as well as unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H). | ||||