Export limit exceeded: 22407 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 381021 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381021 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66614 | 2026-08-20 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions. | ||||
| CVE-2026-66611 | 2026-08-20 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions. | ||||
| CVE-2026-66607 | 2026-08-20 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions. | ||||
| CVE-2026-66606 | 2026-08-20 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions. | ||||
| CVE-2026-66605 | 2026-08-20 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions. | ||||
| CVE-2026-66604 | 2026-08-20 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions. | ||||
| CVE-2026-66601 | 2026-08-20 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions. | ||||
| CVE-2026-66600 | 2026-08-20 | 9.1 Critical | ||
| Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. | ||||
| CVE-2026-66597 | 2026-08-20 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions. | ||||
| CVE-2026-66595 | 2026-08-20 | 5.9 Medium | ||
| Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions. | ||||
| CVE-2026-66594 | 2026-08-20 | 8.5 High | ||
| Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. | ||||
| CVE-2026-66593 | 2026-08-20 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions. | ||||
| CVE-2026-66592 | 2026-08-20 | 9.3 Critical | ||
| Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. | ||||
| CVE-2026-66590 | 2026-08-20 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions. | ||||
| CVE-2026-66583 | 2026-08-20 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. | ||||
| CVE-2026-66582 | 2026-08-20 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions. | ||||
| CVE-2026-74021 | 2026-08-20 | 7.5 High | ||
| Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions. | ||||
| CVE-2026-77084 | 1 N8n | 1 N8n | 2026-08-20 | N/A |
| n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git node executed certain repository-local git configuration values without neutralizing them, so any subsequent Git node operation against a repository containing a malicious value would execute it as the n8n process user. This is not reachable through the Git node's own configuration controls and requires a separate file-write vulnerability elsewhere to plant the malicious value. | ||||
| CVE-2026-77083 | 1 N8n | 1 N8n | 2026-08-20 | N/A |
| n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code node's VM sandbox did not freeze the sandbox's Function.prototype, allowing an authenticated user with the ability to create and execute workflows to pollute it from within a Code node execution and recover a reference to the host's globalThis, resulting in a sandbox escape. The full exploit chain additionally depends on specific modules being available as allowlisted imports in the deployment's configuration. The issue is fixed in versions 1.123.69, 2.33.4, and 2.34.1. | ||||
| CVE-2026-71108 | 1 Oracle | 1 Hyperion Financial Management | 2026-08-20 | 5.3 Medium |
| Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N). | ||||