Export limit exceeded: 380297 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (380297 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-75897 2 Aws, Opensearch 2 Amazon Opensearch Service, Opensearch Dashboards 2026-08-18 7.5 High
Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request.
CVE-2026-75874 1 Mozilla 1 Firefox 2026-08-18 10 Critical
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
CVE-2026-74990 1 Mozilla 1 Firefox 2026-08-18 9.8 Critical
Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
CVE-2026-74972 1 Mozilla 1 Firefox 2026-08-18 4.3 Medium
Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
CVE-2026-74971 1 Mozilla 1 Firefox 2026-08-18 4.3 Medium
Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
CVE-2026-74951 1 Mozilla 1 Firefox 2026-08-18 6.5 Medium
Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.
CVE-2026-74046 2026-08-18 4.9 Medium
Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.py that allows authenticated cluster peers to exhaust memory by supplying a malicious synchronization archive without decompressed size limits. Attackers holding a valid cluster Fernet key can upload a small, highly compressed zip bomb archive that forces wazuh-clusterd on the master node to decompress the full payload into memory, causing memory exhaustion and service disruption.
CVE-2026-74015 2026-08-18 9.3 Critical
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
CVE-2026-74009 2 Razorpay, Wordpress 2 Razorpay For Woocommerce, Wordpress 2026-08-18 5.3 Medium
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.
CVE-2026-74006 2026-08-18 4.3 Medium
Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
CVE-2026-74003 2 Rometheme, Wordpress 2 Romethemeform For Elementor, Wordpress 2026-08-18 4.3 Medium
Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
CVE-2026-73995 2 Wordpress, Wpeverest 2 Wordpress, User Registration 2026-08-18 5.4 Medium
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
CVE-2026-73404 2026-08-18 6.5 Medium
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
CVE-2026-73398 2 Papaki, Wordpress 2 Piraeus Bank Woocommerce Payment Gateway, Wordpress 2026-08-18 6.5 Medium
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
CVE-2026-73396 2026-08-18 7.1 High
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
CVE-2026-73392 2026-08-18 9.3 Critical
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
CVE-2026-73382 2 Geminilabs, Wordpress 2 Site Reviews, Wordpress 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
CVE-2026-73379 2026-08-18 6.5 Medium
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
CVE-2026-73377 2026-08-18 7.5 High
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
CVE-2026-73367 2 Supsystic, Wordpress 2 Easy Google Maps, Wordpress 2026-08-18 7.2 High
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.