Search

Search Results (353908 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-9468 1 Dazeb 1 Cline-mcp-memory-bank 2026-05-26 6.3 Medium
A security flaw has been discovered in dazeb cline-mcp-memory-bank up to 55c81b9cf6c16700983c84dc4cdea3cafa19a75f. The affected element is the function handleInitializeMemoryBank of the file src/index.ts. The manipulation of the argument projectPath results in path traversal. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-9477 1 Totolink 2 A8000ru, A8000ru Firmware 2026-05-26 9.8 Critical
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
CVE-2026-48847 1 Roundcube 1 Webmail 2026-05-26 3.7 Low
Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.
CVE-2026-9483 1 Sourcecodester 1 Student Grades Management System 2026-05-26 6.3 Medium
A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing a manipulation of the argument student_id results in improper authorization. The attack may be initiated remotely. The exploit has been made public and could be used.
CVE-2026-48849 1 Roundcube 1 Webmail 2026-05-26 4.4 Medium
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.
CVE-2026-48848 1 Roundcube 1 Webmail 2026-05-26 7.2 High
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.
CVE-2018-25369 1 Scanwith 1 Visual Ping 2026-05-26 6.2 Medium
Visual Ping 0.8.0.0 contains a buffer overflow vulnerability in input field handling that allows local attackers to crash the application by supplying oversized data. Attackers can inject malicious payloads exceeding 4108 bytes into the Host, Time Out, Packet Size, Pause, or Loops fields to trigger a denial of service condition.
CVE-2018-25375 1 Socusoft 1 Ipod Photo Slideshow 2026-05-26 8.4 High
SocuSoft iPod Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft malicious input in the Registration Name and Registration Key fields to trigger a stack-based buffer overflow and execute a reverse shell payload.
CVE-2018-25381 2 Almera Responsive Portfolio Project, Extro 2 Almera Responsive Portfolio, Responsive Portfolio 2026-05-26 7.1 High
Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multiple filter parameters. Attackers can inject malicious SQL code via the filter_type_id, filter_pid_id, and filter_search parameters in POST requests to extract sensitive database information including credentials and server details.
CVE-2026-9473 1 C-rick 1 Jimeng-mcp 2026-05-26 6.3 Medium
A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileContent/uploadCoverFile/generateImage/generateVideo of the file src/api.ts. The manipulation of the argument filePath leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-24545 2 Nikki Blight, Wordpress 2 Qr Redirector, Wordpress 2026-05-26 4.3 Medium
Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects QR Redirector: from n/a through 2.0.3.
CVE-2026-24582 2 Wordpress, Wppool 2 Wordpress, Flextable 2026-05-26 4.3 Medium
Missing Authorization vulnerability in WPPOOL FlexTable allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexTable: from n/a through 3.24.0.
CVE-2026-24592 2 Lucian Apostol, Wordpress 2 Auto Affiliate Links, Wordpress 2026-05-26 5.3 Medium
Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Affiliate Links: from n/a through 6.8.8.3.
CVE-2026-24527 2 Patterns In The Cloud, Wordpress 2 Autoship Cloud For Woocommerce Subscription Products, Wordpress 2026-05-26 4.3 Medium
Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.14.0.
CVE-2026-39436 2 Bgermann, Wordpress 2 Cformsii, Wordpress 2026-05-26 7.1 High
Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affects CformsII: from n/a through 15.1.3.
CVE-2026-45209 2 Edward Plainview, Wordpress 2 Mycryptocheckout, Wordpress 2026-05-26 7.5 High
Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MyCryptoCheckout: from n/a through 2.161.
CVE-2026-42763 2 Sepay Team, Wordpress 2 Sepay Gateway, Wordpress 2026-05-26 6.5 Medium
Missing Authorization vulnerability in SePay team SePay Gateway allows Retrieve Embedded Sensitive Data. This issue affects SePay Gateway: from n/a through 1.1.20.
CVE-2026-32389 2 Linethemes, Wordpress 2 Nanocare, Wordpress 2026-05-26 5.4 Medium
Missing Authorization vulnerability in Linethemes NanoCare allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects NanoCare: from n/a before 1.2.2.
CVE-2025-71310 1 Backdropcms 1 Gdpr Cookies Module For Backdrop Cms 2026-05-26 N/A
The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info content' field for the YouTube service. This is mitigated by the fact that an attacker must have a role with the permission "Create a GDPR Cookies Service" or "Edit any GDPR Cookies Service" and a site must have added a YouTube service as configuration.
CVE-2026-48850 1 Putty 1 Putty 2026-05-26 3.7 Low
PuTTY 0.72 before 0.84 has a double free in RSA KEX.