Search

Search Results (376982 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-66436 2 Realmag777, Wordpress 2 Active Products Tables For Woocommerce, Wordpress 2026-08-13 9.3 Critical
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
CVE-2026-66432 2026-08-13 7.5 High
Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions.
CVE-2026-66430 2026-08-13 8.5 High
Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
CVE-2026-66429 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
CVE-2026-66424 2026-08-13 9.8 Critical
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
CVE-2026-66378 1 Jfrog 1 Artifactory 2026-08-13 4.3 Medium
An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
CVE-2026-66377 1 Jfrog 1 Artifactory 2026-08-13 5.3 Medium
An unauthenticated user may access restricted repository information under specific conditions.
CVE-2026-65936 2026-08-13 N/A
A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information.  See vulnerability B-E4 in the related paper below.
CVE-2026-65935 2026-08-13 N/A
Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value.  See vulnerability B-E3 in the related paper below.
CVE-2026-65934 2026-08-13 N/A
An unencrypted 'pause encryption request' message causes a denial of service in the BT122 module.  See vulnerability B-E10 in the related paper below.
CVE-2026-65582 2 Liquidthemes, Wordpress 2 Ai Hub, Wordpress 2026-08-13 7.7 High
Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions.
CVE-2026-65580 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions.
CVE-2026-64954 1 Rapid7 1 Velociraptor 2026-08-13 8.2 High
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "investigator" role). This vulnerability is an escalation from an analyst to investigator role.
CVE-2026-61979 2026-08-13 8.1 High
Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
CVE-2026-61978 2026-08-13 6.5 Medium
Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.
CVE-2026-61969 2026-08-13 9.3 Critical
Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
CVE-2026-61967 2026-08-13 9.8 Critical
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
CVE-2026-61965 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions.
CVE-2026-61962 2026-08-13 10 Critical
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
CVE-2026-57858 1 Cal.com 1 Cal.com Self-hosted (cal.diy) 2026-08-13 8.9 High
Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to the affected public booking page, enabling session cookie theft, forged authenticated requests, and wormable propagation by chaining with CSRF-able endpoints to persist payloads on additional events.