Export limit exceeded: 381945 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 381945 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381945 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73367 | 2 Supsystic, Wordpress | 2 Easy Google Maps, Wordpress | 2026-08-18 | 7.2 High |
| Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions. | ||||
| CVE-2026-73365 | 2026-08-18 | 9.3 Critical | ||
| Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. | ||||
| CVE-2026-73360 | 2 Premio, Wordpress | 2 Chaty Pro, Wordpress | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions. | ||||
| CVE-2026-73358 | 2 Wordpress, Wp.insider | 2 Wordpress, Affiliates Manager | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions. | ||||
| CVE-2026-73352 | 2 Nexcess, Wordpress | 2 Givewp, Wordpress | 2026-08-18 | 6.5 Medium |
| Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions. | ||||
| CVE-2026-73350 | 2 Psm Plugins, Wordpress | 2 Supportcandy, Wordpress | 2026-08-18 | 8.2 High |
| Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions. | ||||
| CVE-2026-73343 | 2 Aresit, Wordpress | 2 Wp Compress, Wordpress | 2026-08-18 | 10 Critical |
| Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. | ||||
| CVE-2026-73341 | 2 Metagauss, Wordpress | 2 Registrationmagic, Wordpress | 2026-08-18 | 9.8 Critical |
| Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions. | ||||
| CVE-2026-73190 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions. | ||||
| CVE-2026-73187 | 2 Gingerplugins, Wordpress | 2 Sticky Chat Widget, Wordpress | 2026-08-18 | 9.3 Critical |
| Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. | ||||
| CVE-2026-67271 | 1 Dell | 12 Powerstore 1000t, Powerstore 1200t, Powerstore 3000t and 9 more | 2026-08-18 | 9.8 Critical |
| Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and Remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet and cause a crash, that is persistent in case automatic restarts are enabled. Additionally, a more sophisticated attacker could use the same vulnerability for Remote Code execution. | ||||
| CVE-2026-67262 | 1 Dell | 12 Powerstore 1000t, Powerstore 1200t, Powerstore 3000t and 9 more | 2026-08-18 | 8.1 High |
| Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read from or write to LUNs that the host is not authorized to access, bypassing per-initiator LUN access controls and leading to protection mechanism bypass. | ||||
| CVE-2026-66679 | 2 Codepeople, Wordpress | 2 Appointment Hour Booking, Wordpress | 2026-08-18 | 6.5 Medium |
| Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions. | ||||
| CVE-2026-66644 | 2 93digital, Wordpress | 2 Typing Effect, Wordpress | 2026-08-18 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions. | ||||
| CVE-2026-66638 | 2026-08-18 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. | ||||
| CVE-2026-66635 | 2026-08-18 | 7.4 High | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions. | ||||
| CVE-2026-66622 | 2 Averta, Wordpress | 2 Depicter Slider, Wordpress | 2026-08-18 | 7.5 High |
| Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions. | ||||
| CVE-2026-63641 | 1 Magicmirrororg | 1 Magicmirror | 2026-08-18 | N/A |
| MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equivalent IP allowlist, origin, or namespace authentication checks. In a documented non-loopback deployment that relies on ipWhitelist, an unauthenticated adjacent-network client can connect directly to module Socket.IO namespaces, and js/node_helper.js dispatches arbitrary events and payloads to socketNotificationReceived. The default newsfeed and calendar helpers can make server-side requests to attacker-selected URLs, while the default updatenotification helper can reach child_process.exec when a third-party module update is pending and the attacker supplies an update command through the socket CONFIG path. This can expose internal services, manipulate module-helper state, and conditionally execute commands. This issue is fixed in version 2.37.0. | ||||
| CVE-2026-59244 | 1 Apache | 1 Airflow | 2026-08-18 | 6.5 Medium |
| Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in cleartext to any user with access to that task's Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type. | ||||
| CVE-2026-58076 | 1 Apache | 1 Airflow | 2026-08-18 | 8.8 High |
| Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, so a Dag author could place a value there that causes an arbitrary callable to be imported and invoked -- for example `subprocess.check_output`, or `builtins.eval` on the `builtins`-prefixed variant. The code runs in the **Scheduler**, which reconstructs serialized Dags in its normal loop with no request involved, and in the **API server**, on any authenticated read of the Dag such as `GET /api/v2/dags/{dag_id}/details`. Both are components the Airflow security model states must never execute Dag-author code, and both hold the metadata database credentials and the JWT signing secret. No non-default configuration is required. This is a **different sink from CVE-2026-33264**, which covered only the trigger branch of the same deserializer: deployments that upgraded in response to that advisory are still affected through the exception branch and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later, which restricts the imported class to a subclass of `BaseException`. | ||||