Export limit exceeded: 381943 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 381943 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381943 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-76605 | 1 Fabrikar.com | 1 Fabrik Extension For Joomla | 2026-08-23 | N/A |
| Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2. | ||||
| CVE-2026-76604 | 1 Fabrikar.com | 1 Fabrik Extension For Joomla | 2026-08-23 | N/A |
| Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user provided codes. | ||||
| CVE-2026-76607 | 1 Fabrikar.com | 1 Fabrik Extension For Joomla | 2026-08-23 | N/A |
| Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2. | ||||
| CVE-2026-78115 | 1 Sourcecodester | 1 Class And Exam Timetabling System | 2026-08-23 | 5.4 Medium |
| A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /admin/edit_user_account.php of the component User Account Update. Such manipulation of the argument id/username leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2026-10053 | 1 Gitlab | 1 Gitlab | 2026-08-23 | 8.5 High |
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry. | ||||
| CVE-2026-78155 | 2026-08-23 | 9.9 Critical | ||
| privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges | ||||
| CVE-2026-78112 | 1 Itsourcecode | 1 Hospital Management System Project In Php | 2026-08-23 | 6.3 Medium |
| A flaw has been found in itsourcecode Hospital Management System Project in PHP 1.0. This impacts an unknown function of the file /viewservicetype.php. This manipulation of the argument delid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | ||||
| CVE-2026-77115 | 1 Brave | 1 Brave | 2026-08-23 | N/A |
| Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them. | ||||
| CVE-2026-77116 | 1 Brave | 1 Brave | 2026-08-23 | N/A |
| Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing a post ID in the URL. | ||||
| CVE-2026-13598 | 2026-08-23 | N/A | ||
| The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full site takeover. | ||||
| CVE-2026-14853 | 2026-08-23 | N/A | ||
| The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products. | ||||
| CVE-2026-77003 | 2026-08-23 | N/A | ||
| The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role as low as Contributor to publish posts and pages on the site without holding the publish capability. | ||||
| CVE-2026-78063 | 1 Tenda | 2 Ch22, Ch22 Firmware | 2026-08-23 | 7.4 High |
| A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. | ||||
| CVE-2026-78062 | 1 Vas3k | 1 Taxhacker | 2026-08-23 | 7.3 High |
| A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-78061 | 1 Vas3k | 1 Taxhacker | 2026-08-23 | 6.3 Medium |
| A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of the component Email Sync. Executing a manipulation of the argument host/port can lead to server-side request forgery. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance. | ||||
| CVE-2026-78060 | 1 Sourcecodester | 1 Stock Management System | 2026-08-23 | 4.3 Medium |
| A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /php_action/getOrderReport.php. Performing a manipulation of the argument clientName/clientContact results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. | ||||
| CVE-2026-78059 | 1 Sourcecodester | 1 Stock Management System | 2026-08-23 | 4.3 Medium |
| A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of the file /php_action/printOrder.php. Such manipulation of the argument clientName/clientContact leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2026-78136 | 2026-08-23 | 7.8 High | ||
| chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py. | ||||
| CVE-2026-78057 | 1 Sambitraj | 1 Student-management-system | 2026-08-23 | 6.3 Medium |
| A flaw has been found in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown part of the component Management Mutation Handler. This manipulation of the argument roll_no/name/father_name/class/mobile/email/password/remark causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-78056 | 1 Sambitraj | 1 Student-management-system | 2026-08-23 | 6.3 Medium |
| A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is some unknown functionality of the component Dashboard. The manipulation of the argument roll_no/teacher_name results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet. | ||||