Export limit exceeded: 377058 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 377058 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (377058 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-42018 1 Jfrog 1 Artifactory 2026-08-13 7.5 High
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CVE-2026-29036 1 Davegamble 1 Cjson 2026-08-13 7.5 High
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted JSON Pointer escape sequences (~0 or ~1) in patch paths. Attackers can submit malicious RFC 6902 JSON Patch input to applications using cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() to silently corrupt data or delete unintended keys, potentially bypassing authorization controls in applications that rely on JSON Patch for access-controlled data modification.
CVE-2026-28189 2026-08-13 7.4 High
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions.
CVE-2026-28188 2026-08-13 7.3 High
Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions.
CVE-2026-28186 2026-08-13 8.1 High
Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions.
CVE-2026-28185 2026-08-13 9.8 Critical
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
CVE-2026-28174 2 Arraytics, Wordpress 2 Wp Event Solution, Wordpress 2026-08-13 6.5 Medium
Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
CVE-2026-28170 2 Meril, Wordpress 2 Blog Floating Button, Wordpress 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions.
CVE-2026-28168 2026-08-13 8.5 High
Subscriber SQL Injection in CubeWP <= 1.1.30 versions.
CVE-2026-28161 2026-08-13 8.8 High
Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
CVE-2026-28159 2026-08-13 6.5 Medium
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
CVE-2026-28158 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions.
CVE-2026-28157 2026-08-13 7.5 High
Subscriber Path Traversal in Do Lasso <= 358 versions.
CVE-2026-28156 2026-08-13 8.5 High
Subscriber SQL Injection in Do Lasso <= 358 versions.
CVE-2026-28155 2026-08-13 6.5 Medium
Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.
CVE-2026-28149 2026-08-13 9.8 Critical
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
CVE-2026-28148 2026-08-13 9.8 Critical
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
CVE-2026-28142 2 Shamalli, Wordpress 2 Web Directory Free, Wordpress 2026-08-13 9.3 Critical
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
CVE-2026-28008 2026-08-13 9.8 Critical
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
CVE-2026-28004 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions.