Export limit exceeded: 382036 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (382036 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-78279 | 2026-08-24 | 5.4 Medium | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions. | ||||
| CVE-2026-78278 | 2026-08-24 | 5.3 Medium | ||
| Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions. | ||||
| CVE-2026-78277 | 2026-08-24 | 4.9 Medium | ||
| Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions. | ||||
| CVE-2026-78272 | 2026-08-24 | 5.4 Medium | ||
| Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions. | ||||
| CVE-2026-78270 | 2026-08-24 | 7.6 High | ||
| Author SQL Injection in FluentCRM Pro <= 3.1.12 versions. | ||||
| CVE-2026-78290 | 2026-08-24 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions. | ||||
| CVE-2026-78280 | 2026-08-24 | 4.3 Medium | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions. | ||||
| CVE-2026-78269 | 2026-08-24 | 6.4 Medium | ||
| Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions. | ||||
| CVE-2026-78258 | 2026-08-24 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions. | ||||
| CVE-2026-66623 | 2026-08-24 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions. | ||||
| CVE-2026-66599 | 2026-08-24 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions. | ||||
| CVE-2026-66584 | 2026-08-24 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions. | ||||
| CVE-2026-78291 | 2026-08-24 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions. | ||||
| CVE-2026-15567 | 1 Redhat | 7 Fuse, Jboss Enterprise Application Platform, Jboss Enterprise Application Platform Expansion Pack and 4 more | 2026-08-24 | 7.5 High |
| A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size. | ||||
| CVE-2026-15565 | 1 Redhat | 12 Build Of Apache Camel For Spring Boot, Camel Spring Boot, Data Grid 8 and 9 more | 2026-08-24 | 7.5 High |
| A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service attack without authentication and using only a standard WebSocket handshake. | ||||
| CVE-2026-15563 | 1 Redhat | 4 Jboss Enterprise Application Platform, Jboss Enterprise Application Platform Els, Jboss Enterprise Application Platform Expansion Pack and 1 more | 2026-08-24 | 7.4 High |
| A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations. | ||||
| CVE-2026-15562 | 1 Redhat | 5 Jboss-remoting, Jboss Enterprise Application Platform, Jboss Enterprise Application Platform Els and 2 more | 2026-08-24 | 7.5 High |
| A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to denial of service. | ||||
| CVE-2026-15561 | 1 Redhat | 4 Jboss Enterprise Application Platform, Jboss Enterprise Application Platform Els, Jboss Enterprise Application Platform Expansion Pack and 1 more | 2026-08-24 | 7.5 High |
| A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service. | ||||
| CVE-2026-15556 | 1 Redhat | 4 Jboss Enterprise Application Platform, Jboss Enterprise Application Platform Els, Jboss Enterprise Application Platform Expansion Pack and 1 more | 2026-08-24 | 8.1 High |
| A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application. | ||||
| CVE-2026-15555 | 1 Redhat | 4 Jboss Enterprise Application Platform, Jboss Enterprise Application Platform Els, Jboss Enterprise Application Platform Expansion Pack and 1 more | 2026-08-24 | 8.8 High |
| A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on every cluster node. | ||||