Export limit exceeded: 381470 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381470 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-49796 | 1 Redhat | 16 Cert Manager, Discovery, Enterprise Linux and 13 more | 2026-08-21 | 9.1 Critical |
| A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory. | ||||
| CVE-2025-49794 | 1 Redhat | 15 Cert Manager, Enterprise Linux, Hummingbird and 12 more | 2026-08-21 | 9.1 Critical |
| A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors. | ||||
| CVE-2026-73354 | 2 Reichertbrothers, Wordpress | 2 Simplyrets Real Estate Idx, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions. | ||||
| CVE-2026-73364 | 2 Wordpress, Wpdesk | 2 Wordpress, Flexible Subscriptions | 2026-08-21 | 9.8 Critical |
| Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. | ||||
| CVE-2026-73384 | 2 Cmsminds, Wordpress | 2 Pay With Contact Form 7, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions. | ||||
| CVE-2026-73385 | 2 Outanking Team, Wordpress | 2 Outranking Plugin Options, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions. | ||||
| CVE-2026-73387 | 2 Smartdatasoft, Wordpress | 2 Resido, Wordpress | 2026-08-21 | 8.1 High |
| Unauthenticated Local File Inclusion in Resido <= 1.5 versions. | ||||
| CVE-2026-73389 | 2 The4, Wordpress | 2 Kalles Addons, Wordpress | 2026-08-21 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. | ||||
| CVE-2026-73390 | 2 Klbtheme, Wordpress | 2 Total Donations, Wordpress | 2026-08-21 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. | ||||
| CVE-2026-73391 | 2 Klbtheme, Wordpress | 2 Total Donations, Wordpress | 2026-08-21 | 9.3 Critical |
| Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. | ||||
| CVE-2025-6032 | 1 Redhat | 3 Enterprise Linux, Openshift, Rhel Eus | 2026-08-21 | 8.3 High |
| A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack. | ||||
| CVE-2026-77066 | 1 Omnivore-app | 1 Omnivore | 2026-08-21 | 5 Medium |
| The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. The same file guards the subscribe path with validateUrl(), which rejects private and reserved ranges through the private-ip library, and createPageSaveRequest applies the same check, so the omission is specific to this resolver. An authenticated user can direct the server to request arbitrary internal endpoints. The response is parsed as a feed or as HTML and the resolver returns the resulting url, title, description and type fields, so disclosure is limited to feed-shaped metadata and to link elements advertising RSS or Atom feeds; requests that do not parse still distinguish reachable ports from unreachable ones through the resulting error. | ||||
| CVE-2026-77067 | 1 Omnivore-app | 1 Omnivore | 2026-08-21 | 5 Medium |
| The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file imports no validation helper. When a subscribed event fires, callWebhook in packages/api/src/jobs/call_webhook.ts issues axios.request with that url, the method and Content-Type recorded on the webhook, and a JSON body carrying the event data, so an authenticated user can make the server send repeated attacker-shaped requests to internal endpoints, including link-local metadata addresses. The request is blind: callWebhook discards the result and writes only a success line or the axios error to the server log, so the response is not returned through the API. | ||||
| CVE-2026-74021 | 2 Anders Norén, Wordpress | 2 Chaplin, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions. | ||||
| CVE-2025-15637 | 2 Edge Themes, Wordpress | 2 Shuffle, Wordpress | 2026-08-21 | 8.1 High |
| Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. | ||||
| CVE-2026-66590 | 2 Tagembed, Wordpress | 2 Tagembed, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions. | ||||
| CVE-2026-66594 | 2 Lukeseager, Wordpress | 2 Wordpress Persistent Login, Wordpress | 2026-08-21 | 8.5 High |
| Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. | ||||
| CVE-2026-66598 | 2 Kingtech Llc., Wordpress | 2 B2bking Premium, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions. | ||||
| CVE-2026-66605 | 2 Hasthemes, Wordpress | 2 Swatchly – Woocommerce Variation Swatches For Products, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions. | ||||
| CVE-2026-66606 | 2 Themegrill, Wordpress | 2 Smartsmtp, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions. | ||||