Search

Search Results (380316 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-72840 1 Openwrt 1 Luci 2026-08-14 8.8 High
OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can append arbitrary cron entries via ubus file.write, which the default busybox crond daemon executes as root within one minute.
CVE-2026-64639 1 Webpros 1 Plesk 2026-08-14 N/A
Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.
CVE-2026-58508 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 9.1 Critical
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
CVE-2026-58507 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 5.3 Medium
Private Repository Existence Disclosure via go-get Meta Endpoint
CVE-2026-58445 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 2.7 Low
Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
CVE-2026-58444 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 4.3 Medium
Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
CVE-2026-58437 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 7.1 High
Repository Visibility Manipulation via Git Push Options
CVE-2026-55986 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 5.4 Medium
Email Management API Bypasses ManageCredentials Feature Restrictions
CVE-2026-17445 1 Ibm 1 I 2026-08-14 8.2 High
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of an attacker-supplied user profile name.
CVE-2026-17078 1 Ibm 1 I 2026-08-14 5.3 Medium
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion.
CVE-2026-16908 1 Ibm 1 I 2026-08-14 8.5 High
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vulnerability.
CVE-2026-16722 1 Ibm 1 I 2026-08-14 8.8 High
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improper privilege management.
CVE-2026-13610 2 Iqonic, Wordpress 2 Kivicare, Wordpress 2026-08-14 7.5 High
The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data.
CVE-2026-13328 2026-08-14 5.3 Medium
The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenticated users and gated only by a nonce that is publicly available to visitors, allowing unauthenticated attackers to change the status of arbitrary reservations.
CVE-2026-66454 2 Maruti Mohanty, Wordpress 2 Wp Social Avatar, Wordpress 2026-08-14 6.5 Medium
Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.
CVE-2026-66426 2 Lesterchan, Wordpress 2 Wp-stats, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions.
CVE-2026-5428 2 Wordpress, Wproyal 2 Wordpress, Royal Addons For Elementor – Addons And Templates Kit For Elementor 2026-08-14 6.4 Medium
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to and including 1.7.1056. This is due to insufficient output escaping in the render_post_thumbnail() function, where wp_kses_post() is used instead of esc_attr() for the alt attribute context. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses a page with the malicious image displayed in the media grid widget.
CVE-2026-19654 1 Redhat 1 Enterprise Linux 2026-08-14 7.5 High
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.
CVE-2026-5488 2 Smub, Wordpress 2 Exactmetrics – Google Analytics Dashboard For Wordpress (website Stats Plugin), Wordpress 2026-08-14 5.3 Medium
The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the mi-admin-nonce is localized on all admin pages (including profile.php which subscribers can access), and while other similar AJAX endpoints in the same class properly check for the exactmetrics_save_settings capability, these two endpoints only verify the nonce. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve valid Google Ads access tokens and reset Google Ads integration settings.
CVE-2026-3885 2 Gn Themes, Wordpress 2 Wp Shortcodes Plugin — Shortcodes Ultimate, Wordpress 2026-08-14 6.4 Medium
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_box' shortcode in all versions up to, and including, 7.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.