Export limit exceeded: 378381 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 378381 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (92584 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-61960 2 Themeisle, Wordpress 2 Wp Full Stripe Free, Wordpress 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions.
CVE-2026-61974 2 Kitae-park, Wordpress 2 Mang Board Wp, Wordpress 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions.
CVE-2026-61980 2 Daan.dev, Wordpress 2 Omgf Pro, Wordpress 2026-08-13 7.5 High
Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions.
CVE-2026-61984 2 Amauri, Wordpress 2 Wpmobile.app, Wordpress 2026-08-13 7.5 High
Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions.
CVE-2026-17271 1 Ibm 1 I 2026-08-13 7.5 High
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size.
CVE-2026-18713 1 Ibm 1 I 2026-08-13 8.8 High
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.
CVE-2026-18669 1 Ibm 1 I 2026-08-13 8.8 High
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority.
CVE-2026-18235 1 Ibm 1 I 2026-08-13 8.3 High
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Control Language commands due to insufficient input validation.
CVE-2026-17418 1 Ibm 1 I 2026-08-13 8.5 High
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elements used in an SQL command.
CVE-2026-58484 2 Jovancoding, Network-ai 2 Network-ai, Network-ai 2026-08-13 7.1 High
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()` reads each backup's `_manifest.json` and trusts the manifest's `path` field. `EnvironmentManager.pruneBackups()` later passes that trusted `entry.path` directly to `rmSync(entry.path, { recursive: true, force: true })`. An attacker who can place or modify a manifest inside `data/<env>/.backups/<name>/_manifest.json` can cause `network-ai env backup prune --env <env> --keep <n>` or any code path invoking `pruneBackups()` to recursively delete an arbitrary path accessible to the Network-AI process user. This is fixed in v5.12.2. `pruneBackups()` no longer passes `entry.path` from the on-disk manifest to `rmSync`. The deletion path is recomputed from a format-validated `entry.backupId`, and a `dirname` containment check confines deletion to exactly one level under the backups directory. A poisoned manifest (e.g. `"path": "/"`) is now inert.
CVE-2026-73246 1 Kestra-io 1 Kestra 2026-08-13 7.5 High
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndpoint.java serves GET /worker without authentication and serializes the complete live Task object, which can expose commands, environment variables, HTTP headers, connection details, plaintext credentials, and execution identifiers while the main API on port 8080 remains protected. This issue is fixed in 2.0.0-rc6.
CVE-2026-72921 1 Seaweedfs 1 Seaweedfs 2026-08-13 8.1 High
SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths such as /tenant1234, /tenant1-old, and /tenant1backup, enabling cross-tenant reads and writes with a valid scoped token. This issue is fixed in version 4.24.
CVE-2026-6464 1 Postgresql 1 Postgresql 2026-08-13 8.1 High
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-69105 1 Jfrog 1 Artifactory 2026-08-13 8.1 High
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.
CVE-2026-66878 1 Redhat 2 Acm, Advanced Cluster Management For Kubernetes 2026-08-13 7.7 High
A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret contents from other namespaces into their own, leading to information disclosure.
CVE-2026-66450 2 Dylan Kuhn, Wordpress 2 Geo Mashup, Wordpress 2026-08-13 8.1 High
Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions.
CVE-2026-66443 2 Pete Nelson, Wordpress 2 Rest Api Log, Wordpress 2026-08-13 7.5 High
Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.
CVE-2026-66441 2 Multivendorx, Wordpress 2 Multivendorx, Wordpress 2026-08-13 7.5 High
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.
CVE-2026-65582 2 Liquidthemes, Wordpress 2 Ai Hub, Wordpress 2026-08-13 7.7 High
Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions.
CVE-2026-64954 1 Rapid7 1 Velociraptor 2026-08-13 8.2 High
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "investigator" role). This vulnerability is an escalation from an analyst to investigator role.