Export limit exceeded: 378046 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 378046 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (378046 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73626 | 1 Jupyter | 1 Jupyterlab | 2026-08-14 | 0 Low |
| JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blocklist check was not enforced for direct callers of install(). The stock JupyterLab HTTP API and Extension Manager UI are not affected, as they perform a separate, correctly awaited check. The issue affects only deployments where a custom extension or downstream integration imports PyPIExtensionManager and calls install() directly with a package name influenced by untrusted input, an allowlist/blocklist is configured, the PyPI Extension Manager is enabled, and kernels and terminals are disabled or delegated to remote hosts. Fixed in JupyterLab 4.6.2 and 4.5.10. | ||||
| CVE-2026-73584 | 1 Redhat | 1 Enterprise Linux | 2026-08-14 | 6.3 Medium |
| A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system. | ||||
| CVE-2026-27345 | 2 Magepeople, Wordpress | 2 Taxi Booking Manager For Woocommerce, Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions. | ||||
| CVE-2026-27537 | 2 Supsysticcom, Wordpress | 2 Smart Popup By Supsystic, Wordpress | 2026-08-14 | 6.5 Medium |
| Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions. | ||||
| CVE-2026-28004 | 2 Strategy11team, Wordpress | 2 Business Directory Plugin, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions. | ||||
| CVE-2026-28008 | 2 Miniorange, Wordpress | 2 Oauth Single Sign On – Sso (oauth Client), Wordpress | 2026-08-14 | 9.8 Critical |
| Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions. | ||||
| CVE-2026-28148 | 2 Miniorange, Wordpress | 2 Headless Single Sign On, Wordpress | 2026-08-14 | 9.8 Critical |
| Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions. | ||||
| CVE-2026-28149 | 2 Miniorange, Wordpress | 2 Headless Single Sign On, Wordpress | 2026-08-14 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions. | ||||
| CVE-2026-28189 | 2 Rolandbarkerxnauwebdesign, Wordpress | 2 Participants Database, Wordpress | 2026-08-14 | 7.4 High |
| Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions. | ||||
| CVE-2026-61965 | 2 Ahmad, Wordpress | 2 Geekybot, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions. | ||||
| CVE-2026-61967 | 2 Miniorange, Wordpress | 2 Otp Verification, Wordpress | 2026-08-14 | 9.8 Critical |
| Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. | ||||
| CVE-2026-66424 | 2 Cozyvision, Wordpress | 2 Sms Alert Order Notifications, Wordpress | 2026-08-14 | 9.8 Critical |
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. | ||||
| CVE-2026-66429 | 2 Codepress It Solutions Llc, Wordpress | 2 Visitor Traffic Real Time Statistics Pro, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | ||||
| CVE-2026-66430 | 2 Codepress It Solutions Llc, Wordpress | 2 Visitor Traffic Real Time Statistics Pro, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | ||||
| CVE-2026-66444 | 2 Kendysond, Wordpress | 2 Payment Forms For Paystack, Wordpress | 2026-08-14 | 6.5 Medium |
| Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions. | ||||
| CVE-2026-66456 | 2 Bestwebsoft, Wordpress | 2 Profile Extra Fields, Wordpress | 2026-08-14 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions. | ||||
| CVE-2026-66461 | 2 Smepay, Wordpress | 2 Smepay:upi Gateway For Woocommerce, Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. | ||||
| CVE-2026-66467 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluentcommunity | 2026-08-14 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. | ||||
| CVE-2026-66653 | 2 Edge-themes, Wordpress | 2 Barista, Wordpress | 2026-08-14 | 8.1 High |
| Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions. | ||||
| CVE-2026-66656 | 2 Mikado-themes, Wordpress | 2 Foton Core, Wordpress | 2026-08-14 | 8.1 High |
| Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions. | ||||