Export limit exceeded: 381796 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381796 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73379 | 2026-08-18 | 6.5 Medium | ||
| Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. | ||||
| CVE-2026-73367 | 2 Supsystic, Wordpress | 2 Easy Google Maps, Wordpress | 2026-08-18 | 7.2 High |
| Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions. | ||||
| CVE-2026-73365 | 2026-08-18 | 9.3 Critical | ||
| Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. | ||||
| CVE-2026-73360 | 2 Premio, Wordpress | 2 Chaty Pro, Wordpress | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions. | ||||
| CVE-2026-73358 | 2 Wordpress, Wp.insider | 2 Wordpress, Affiliates Manager | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions. | ||||
| CVE-2026-73352 | 2 Nexcess, Wordpress | 2 Givewp, Wordpress | 2026-08-18 | 6.5 Medium |
| Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions. | ||||
| CVE-2026-73350 | 2 Psm Plugins, Wordpress | 2 Supportcandy, Wordpress | 2026-08-18 | 8.2 High |
| Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions. | ||||
| CVE-2026-73343 | 2 Aresit, Wordpress | 2 Wp Compress, Wordpress | 2026-08-18 | 10 Critical |
| Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. | ||||
| CVE-2026-73341 | 2 Metagauss, Wordpress | 2 Registrationmagic, Wordpress | 2026-08-18 | 9.8 Critical |
| Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions. | ||||
| CVE-2026-73190 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions. | ||||
| CVE-2026-73187 | 2 Gingerplugins, Wordpress | 2 Sticky Chat Widget, Wordpress | 2026-08-18 | 9.3 Critical |
| Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. | ||||
| CVE-2026-67271 | 1 Dell | 12 Powerstore 1000t, Powerstore 1200t, Powerstore 3000t and 9 more | 2026-08-18 | 9.8 Critical |
| Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and Remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet and cause a crash, that is persistent in case automatic restarts are enabled. Additionally, a more sophisticated attacker could use the same vulnerability for Remote Code execution. | ||||
| CVE-2026-67262 | 1 Dell | 12 Powerstore 1000t, Powerstore 1200t, Powerstore 3000t and 9 more | 2026-08-18 | 8.1 High |
| Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read from or write to LUNs that the host is not authorized to access, bypassing per-initiator LUN access controls and leading to protection mechanism bypass. | ||||
| CVE-2026-66679 | 2 Codepeople, Wordpress | 2 Appointment Hour Booking, Wordpress | 2026-08-18 | 6.5 Medium |
| Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions. | ||||
| CVE-2026-66644 | 2 93digital, Wordpress | 2 Typing Effect, Wordpress | 2026-08-18 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions. | ||||
| CVE-2026-66638 | 2026-08-18 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. | ||||
| CVE-2026-66635 | 2026-08-18 | 7.4 High | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions. | ||||
| CVE-2026-66622 | 2 Averta, Wordpress | 2 Depicter Slider, Wordpress | 2026-08-18 | 7.5 High |
| Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions. | ||||
| CVE-2026-63641 | 1 Magicmirrororg | 1 Magicmirror | 2026-08-18 | N/A |
| MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equivalent IP allowlist, origin, or namespace authentication checks. In a documented non-loopback deployment that relies on ipWhitelist, an unauthenticated adjacent-network client can connect directly to module Socket.IO namespaces, and js/node_helper.js dispatches arbitrary events and payloads to socketNotificationReceived. The default newsfeed and calendar helpers can make server-side requests to attacker-selected URLs, while the default updatenotification helper can reach child_process.exec when a third-party module update is pending and the attacker supplies an update command through the socket CONFIG path. This can expose internal services, manipulate module-helper state, and conditionally execute commands. This issue is fixed in version 2.37.0. | ||||
| CVE-2026-55106 | 1 Goauthentik | 1 Authentik | 2026-08-18 | 5.3 Medium |
| authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API does not enforce the object-level read-authorization filter used by the rest of the API. Any party able to reach the API, including an unauthenticated client, can invoke the diagnostic action against a configured LDAP Source. The server then connects to the upstream directory using the source's configured bind credentials and returns a bounded set of directory entries. The response exposes the distinguished names of those entries and the names of the attributes present on them, revealing directory structure, naming conventions, and the existence of specific accounts and groups, but not attribute values. Deployments without a configured LDAP Source are not affected. This issue is fixed in versions 2026.2.6 and 2026.5.5. | ||||