Export limit exceeded: 377230 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (377230 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-6469 | 1 Postgresql | 1 Postgresql | 2026-08-13 | 3.8 Low |
| Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | ||||
| CVE-2026-6464 | 1 Postgresql | 1 Postgresql | 2026-08-13 | 8.1 High |
| Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | ||||
| CVE-2026-69105 | 1 Jfrog | 1 Artifactory | 2026-08-13 | 8.1 High |
| An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability. | ||||
| CVE-2026-66878 | 1 Redhat | 2 Acm, Advanced Cluster Management For Kubernetes | 2026-08-13 | 7.7 High |
| A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret contents from other namespaces into their own, leading to information disclosure. | ||||
| CVE-2026-66704 | 2026-08-13 | 7.2 High | ||
| Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. | ||||
| CVE-2026-66691 | 2026-08-13 | 9.8 Critical | ||
| Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions. | ||||
| CVE-2026-66661 | 2026-08-13 | 7.7 High | ||
| Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions. | ||||
| CVE-2026-66658 | 2026-08-13 | 8.5 High | ||
| Subscriber SQL Injection in Reviewer <= 3.14.2 versions. | ||||
| CVE-2026-66657 | 2026-08-13 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions. | ||||
| CVE-2026-66656 | 2026-08-13 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions. | ||||
| CVE-2026-66654 | 2026-08-13 | 6 Medium | ||
| Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions. | ||||
| CVE-2026-66653 | 2026-08-13 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions. | ||||
| CVE-2026-66469 | 2026-08-13 | 7.5 High | ||
| Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions. | ||||
| CVE-2026-66468 | 2026-08-13 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions. | ||||
| CVE-2026-66467 | 2026-08-13 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. | ||||
| CVE-2026-66466 | 2026-08-13 | 7.5 High | ||
| Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions. | ||||
| CVE-2026-66465 | 2026-08-13 | 9.8 Critical | ||
| Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions. | ||||
| CVE-2026-66464 | 2026-08-13 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions. | ||||
| CVE-2026-66463 | 2026-08-13 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions. | ||||
| CVE-2026-66462 | 2026-08-13 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions. | ||||