Search

Search Results (377270 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-70547 1 Jfrog 1 Artifactory 2026-08-13 4.3 Medium
An authenticated user without repository read permission may access package metadata under specific conditions.
CVE-2026-70467 1 Fortinet 1 Fortisiem 2026-08-13 3.4 Low
A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
CVE-2026-6821 1 Gitlab 1 Gitlab 2026-08-13 4.3 Medium
GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to bypass IP-based access restrictions and read limited merge request information from a private project due to missing authorization checks in a merge requests API endpoint.
CVE-2026-6469 1 Postgresql 1 Postgresql 2026-08-13 3.8 Low
Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-6464 1 Postgresql 1 Postgresql 2026-08-13 8.1 High
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-69105 1 Jfrog 1 Artifactory 2026-08-13 8.1 High
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.
CVE-2026-66878 1 Redhat 2 Acm, Advanced Cluster Management For Kubernetes 2026-08-13 7.7 High
A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret contents from other namespaces into their own, leading to information disclosure.
CVE-2026-66704 2026-08-13 7.2 High
Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.
CVE-2026-66658 2026-08-13 8.5 High
Subscriber SQL Injection in Reviewer <= 3.14.2 versions.
CVE-2026-66657 2026-08-13 8.1 High
Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions.
CVE-2026-66656 2026-08-13 8.1 High
Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions.
CVE-2026-66653 2026-08-13 8.1 High
Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions.
CVE-2026-66467 2026-08-13 6.5 Medium
Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.
CVE-2026-66461 2026-08-13 7.5 High
Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.
CVE-2026-66453 2 Dimitri Grassi, Wordpress 2 Salon Booking System, Wordpress 2026-08-13 9.8 Critical
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
CVE-2026-66450 2 Dylan Kuhn, Wordpress 2 Geo Mashup, Wordpress 2026-08-13 8.1 High
Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions.
CVE-2026-66444 2026-08-13 6.5 Medium
Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.
CVE-2026-66443 2 Pete Nelson, Wordpress 2 Rest Api Log, Wordpress 2026-08-13 7.5 High
Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.
CVE-2026-66441 2 Multivendorx, Wordpress 2 Multivendorx, Wordpress 2026-08-13 7.5 High
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.
CVE-2026-66436 2 Realmag777, Wordpress 2 Active Products Tables For Woocommerce, Wordpress 2026-08-13 9.3 Critical
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.