Search

Search Results (371801 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-15813 1 Redhat 3 Enterprise Linux, Openshift, Openshift Container Platform 2026-08-02 6.5 Medium
A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence numbers of incoming payload fragments. An attacker can exploit this lack of verification by transmitting malformed packets with corrupted sequence parameters. Under specific conditions, this forces the packet processing layer to parse data outside the designated bounds of the internal memory structures, causing an out-of-bounds memory access or heap corruption. This behavior can result in sudden application crashes or system instability.
CVE-2026-16254 1 Redhat 3 Advanced Cluster Security, Quay, Quay 3 2026-08-02 4.3 Medium
A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an out-of-bounds access that panics the scanner. If that panic is not recovered, the Clair indexer process can crash, leading to a denial of service.
CVE-2026-15588 1 Redhat 5 Enterprise Linux, Hardened Images, Hummingbird and 2 more 2026-08-02 5.3 Medium
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.
CVE-2026-16277 1 Redhat 3 Enterprise Linux, Openshift, Openshift Container Platform 2026-08-02 6.5 Medium
A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
CVE-2026-12701 1 Redhat 8 Ansible Automation Platform, Ansible Automation Platform Developer, Ansible Automation Platform Inside and 5 more 2026-08-02 9 Critical
A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../" anywhere in the path. An authenticated administrator can craft a relative_path containing embedded traversal sequences (e.g., "looking/normal/../../../../etc/shadow") that escapes the intended export directory during FilesystemExport operations. Because the file content is also user-controlled (uploaded artifact), this allows arbitrary file write to any location writable by the Pulp service user, potentially leading to service compromise or further system exploitation.
CVE-2026-52470 1 Streamax 1 Streamax Crocus 2026-08-02 9.8 Critical
SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file
CVE-2026-6390 1 Redhat 3 Enterprise Linux, Openshift, Openshift Container Platform 2026-08-02 6.8 Medium
A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.
CVE-2026-12082 2 Praison Ai, Wordpress 2 Praison Ai Seo, Wordpress 2026-08-02 7.5 High
The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.
CVE-2026-15906 2 Codename065, Wordpress 2 Premium Packages – Sell Digital Products Securely, Wordpress 2026-08-02 6.5 Medium
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with admin-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-15794 2 Berocket, Wordpress 2 Grid/list View For Woocommerce, Wordpress 2026-08-02 6.4 Medium
The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The shortcode's all_page="1" attribute can be used to force the widget to render on any page, expanding the attack surface beyond shop and category pages.
CVE-2026-15348 2 Codename065, Wordpress 2 Premium Packages – Sell Digital Products Securely, Wordpress 2026-08-02 6.3 Medium
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via the `wpdmppdl` parameter. This is due to the `download()` function — hooked to the unauthenticated WordPress `wp` action — decoding the attacker-controlled `wpdmppdl` parameter using only `base64_decode()` and `json_decode()` with no HMAC, cryptographic signature, or nonce verification, and then issuing WordPress authentication cookies after a domain check that is trivially bypassed because both sides of the comparison are attacker-supplied values. This makes it possible for unauthenticated attackers to authenticate as any non-administrator WordPress user, including subscribers, customers, contributors, authors, editors, and shop managers, who owns an order, gaining full session-level access to that account.
CVE-2026-57373 2 Wisetr, Wordpress 2 Funnel Kit Funnel Builder Pro, Wordpress 2026-08-02 6.5 Medium
Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.
CVE-2026-57374 2 Wisetr, Wordpress 2 Funnel Kit Funnel Builder Pro, Wordpress 2026-08-02 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.
CVE-2026-59554 2 Wordpress, Ziina 2 Wordpress, Ziina 2026-08-02 7.5 High
Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
CVE-2026-65477 2 Select-themes, Wordpress 2 Tonda Core, Wordpress 2026-08-02 7.5 High
Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.
CVE-2026-65481 2 Elated-themes, Wordpress 2 Vino, Wordpress 2026-08-02 7.5 High
Contributor Local File Inclusion in Vino <= 1.9 versions.
CVE-2026-65491 2 Jonathan Daggerhart, Wordpress 2 Query Wrangler, Wordpress 2026-08-02 4.3 Medium
Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
CVE-2026-65514 2 Codepeople, Wordpress 2 Appointment Hour Booking, Wordpress 2026-08-02 6.5 Medium
Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
CVE-2026-65518 2 Scott Paterson, Wordpress 2 Accept Donations With Paypal & Stripe, Wordpress 2026-08-02 6.5 Medium
Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.
CVE-2026-12353 1 Redhat 3 Certificate System, Dogtag Certificate System, Enterprise Linux 2026-08-02 5.3 Medium
An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.