Export limit exceeded: 383474 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (383474 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73396 | 2 Makewebbetter, Wordpress | 2 Hubspot For Woocommerce, Wordpress | 2026-08-21 | 7.1 High |
| Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. | ||||
| CVE-2026-73404 | 2 Stylemixthemes, Wordpress | 2 Masterstudy Lms, Wordpress | 2026-08-21 | 6.5 Medium |
| Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. | ||||
| CVE-2026-73996 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-08-21 | 9.8 Critical |
| Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. | ||||
| CVE-2026-74004 | 2 Wordpress, Wpmonks | 2 Wordpress, Gravity Booster – Styles & Layouts For Gravity Forms | 2026-08-21 | 5.4 Medium |
| Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions. | ||||
| CVE-2026-74006 | 2 Wordpress, Wptablebuilder | 2 Wordpress, Wp Table Builder | 2026-08-21 | 4.3 Medium |
| Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions. | ||||
| CVE-2026-74007 | 2 Iberezansky, Wordpress | 2 3d Flipbook – Pdf Embedder, Pdf Flipbook Viewer, Flipbook Image Gallery, Wordpress | 2026-08-21 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions. | ||||
| CVE-2026-71539 | 1 N8n | 1 N8n | 2026-08-21 | N/A |
| n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone operation allows an authenticated workflow user to swap a validated directory for a symlink before cloning, planting a crafted repository in the community node directory that loads as a custom JavaScript node after restart and executes arbitrary code on the server. This issue is fixed in versions 1.123.64, 2.29.8, and 2.30.1. | ||||
| CVE-2026-48798 | 1 Sshnet | 1 Ssh.net | 2026-08-21 | 7.1 High |
| SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the requested local directory without containment validation, allowing a malicious, compromised, or man-in-the-middle server to use ../ sequences or absolute paths to create or overwrite files anywhere writable by the client process. This issue is fixed in version 2026.0.0. | ||||
| CVE-2026-59825 | 1 Joinmastodon | 1 Mastodon | 2026-08-21 | 7.4 High |
| Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=true, disabling SSL and TLS certificate verification globally for requests made by puma web processes while sidekiq background jobs remain unaffected. This issue is fixed in versions 4.4.19 and 4.5.12. | ||||
| CVE-2026-50187 | 1 Ohmyz | 1 Ohmyzsh | 2026-08-21 | 8.8 High |
| Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a directory change into a folder containing a .env file, allowing syntactically valid shell commands in the file to execute with the current account's privileges, including without a prompt when ZSH_DOTENV_PROMPT=false or after the default prompt accepts an empty Enter response. This issue is fixed in versions released after 2026-05-28. | ||||
| CVE-2026-71574 | 1 Joomla | 1 Joomla! | 2026-08-21 | N/A |
| Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI. | ||||
| CVE-2026-73373 | 1 Joomla | 2 Joomla!, Joomla! Framework Filter Package | 2026-08-21 | N/A |
| Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution. | ||||
| CVE-2026-72532 | 1 Joomla | 1 Joomla! | 2026-08-21 | N/A |
| Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints. | ||||
| CVE-2026-73371 | 1 Joomla | 1 Joomla! | 2026-08-21 | N/A |
| Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items. | ||||
| CVE-2026-73337 | 1 Joomla | 1 Joomla! | 2026-08-21 | N/A |
| Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass 2FA checks. | ||||
| CVE-2026-71572 | 1 Joomla | 1 Joomla! | 2026-08-21 | N/A |
| Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion. | ||||
| CVE-2026-73372 | 1 Joomla | 1 Joomla! | 2026-08-21 | N/A |
| Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets. | ||||
| CVE-2026-73336 | 1 Joomla | 1 Joomla! | 2026-08-21 | N/A |
| Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs. | ||||
| CVE-2026-72531 | 1 Joomla | 1 Joomla! | 2026-08-21 | N/A |
| Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components. | ||||
| CVE-2026-71573 | 1 Joomla | 1 Joomla! | 2026-08-21 | N/A |
| Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests. | ||||