Export limit exceeded: 15060 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15060 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16503 | 1 Vps.org | 1 Supabase Template | 2026-08-03 | 9.1 Critical |
| Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration. | ||||
| CVE-2026-16534 | 2026-08-03 | 9.1 Critical | ||
| The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email. | ||||
| CVE-2026-28945 | 1 Apple | 1 Macos | 2026-08-03 | 7.1 High |
| A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to bypass network restrictions. | ||||
| CVE-2026-16289 | 2 Profilegrid, Wordpress | 2 Profilegrid, Wordpress | 2026-08-03 | 4.3 Medium |
| The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones. | ||||
| CVE-2026-43728 | 1 Apple | 1 Macos | 2026-08-03 | 7.5 High |
| This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26.6. An attacker may be able to modify the state of the Keychain. | ||||
| CVE-2026-43756 | 1 Apple | 1 Macos | 2026-08-03 | 5.5 Medium |
| A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensitive data. | ||||
| CVE-2026-43760 | 1 Apple | 1 Macos | 2026-08-03 | 8.6 High |
| An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensitive data. | ||||
| CVE-2026-18584 | 2 Gl-inet, Gl.inet | 12 E5800, E750, X2000 and 9 more | 2026-08-03 | 5.4 Medium |
| A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. | ||||
| CVE-2026-33591 | 1 Tranquil It Systems | 1 Wapt Server | 2026-08-03 | N/A |
| A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account. | ||||
| CVE-2026-56608 | 1 Hcltech | 1 Icontrol | 2026-08-03 | 3.7 Low |
| HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization. | ||||
| CVE-2026-18574 | 1 Checkpoint | 2 Multi-domain Security Management Server, Security Management Server | 2026-08-03 | N/A |
| An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation. | ||||
| CVE-2026-67335 | 1 Better-auth | 2 Better-auth\/oauth-provider, Better Auth | 2026-08-03 | 5.3 Medium |
| better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authorization code to create authenticated sessions bound to the attacker's external identity or persistently link attacker accounts to victim profiles. | ||||
| CVE-2026-58039 | 2 Nodejs, Redhat | 2 Nodejs, Hummingbird | 2026-08-03 | 4.4 Medium |
| A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**. | ||||
| CVE-2026-12695 | 2026-08-03 | 8.1 High | ||
| The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass two-factor authentication and gain access to the victim's account, including administrators. | ||||
| CVE-2026-14919 | 2026-08-03 | 9.8 Critical | ||
| The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account. | ||||
| CVE-2026-5786 | 1 Ivanti | 1 Endpoint Manager Mobile | 2026-08-03 | 8.8 High |
| An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access. | ||||
| CVE-2026-46817 | 1 Oracle | 2 E-business Suite, Payments | 2026-08-03 | 9.8 Critical |
| Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). | ||||
| CVE-2026-13897 | 1 Google | 1 Chrome | 2026-08-03 | 8.8 High |
| Insufficient policy enforcement in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-13931 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-08-03 | 6.5 Medium |
| Inappropriate implementation in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-13932 | 1 Google | 2 Android, Chrome | 2026-08-03 | 6.5 Medium |
| Inappropriate implementation in Sharing in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | ||||