Export limit exceeded: 381606 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381606 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66600 | 2 Davidlingren, Wordpress | 2 Media Library Assistant, Wordpress | 2026-08-20 | 9.1 Critical |
| Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. | ||||
| CVE-2026-66597 | 2 Melograno Venture Studio, Wordpress | 2 Wpdatatables, Wordpress | 2026-08-20 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions. | ||||
| CVE-2026-66582 | 2 Cozmoslabs, Wordpress | 2 Translatepress, Wordpress | 2026-08-20 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions. | ||||
| CVE-2026-63016 | 1 Apache | 1 Inlong | 2026-08-20 | 5.3 Medium |
| Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow upload of non-official packages. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/12095 https://github.com/apache/inlong/pull/11732 | ||||
| CVE-2026-28150 | 2 Uxper, Wordpress | 2 Golo Framework, Wordpress | 2026-08-20 | 8.1 High |
| Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions. | ||||
| CVE-2026-18102 | 1 Ibm | 1 I | 2026-08-20 | 3.5 Low |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memory due to an integer underflow during bounds checking. | ||||
| CVE-2026-17015 | 1 Ibm | 1 I | 2026-08-20 | 5.4 Medium |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read. | ||||
| CVE-2026-16932 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 8.8 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper validation of the ODMDIR environment variable. | ||||
| CVE-2026-16927 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 7.3 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-check to time-of-use (TOCTOU) race condition. | ||||
| CVE-2026-16925 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 7.1 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to improper authorization. | ||||
| CVE-2026-16924 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 7.5 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory offset during IPsec decapsulation. | ||||
| CVE-2026-16922 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 7 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-check to time-of-use (TOCTOU) race condition. | ||||
| CVE-2026-14951 | 1 Frauscher Sensortechnik | 1 Fds 102 | 2026-08-20 | 8 High |
| An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages. | ||||
| CVE-2025-36398 | 1 Ibm | 4 Ds8900f, Ds8a00, System Storage Ds8900f and 1 more | 2026-08-20 | 5.4 Medium |
| IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename. | ||||
| CVE-2025-36255 | 1 Ibm | 4 Ds8900f, Ds8a00, System Storage Ds8900f and 1 more | 2026-08-20 | 7.5 High |
| IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a user with privileged user roles due to improper privileged defined with unsafe actions. | ||||
| CVE-2025-36254 | 1 Ibm | 4 Ds8900f, Ds8a00, System Storage Ds8900f and 1 more | 2026-08-20 | 7.4 High |
| IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security authentication due to improperly encoding of DSCLI command output to obtain sensitive information or cause a denial of service. | ||||
| CVE-2025-15688 | 2 Themegoods, Wordpress | 2 Capella, Wordpress | 2026-08-20 | 9.3 Critical |
| Unauthenticated SQL Injection in Capella <= 2.5.5 versions. | ||||
| CVE-2026-76244 | 1 Eidetic-labs | 1 Stigmem | 2026-08-20 | N/A |
| stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly disabled mTLS while binding federation to non-loopback addresses expose federation traffic to cleartext interception and man-in-the-middle attacks. | ||||
| CVE-2026-54117 | 1 Microsoft | 7 Microsoft Sql Server 2025 (cu 2), Microsoft Sql Server 2025 For X64-based Systems (gdr), Sql Server 2016 and 4 more | 2026-08-20 | 9.8 Critical |
| Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-54118 | 1 Microsoft | 15 Microsoft Sql Server 2016 Service Pack 3 (gdr), Microsoft Sql Server 2016 Service Pack 3 Azure Connect Feature Pack, Microsoft Sql Server 2017 (cu 31) and 12 more | 2026-08-20 | 9.8 Critical |
| Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | ||||