Export limit exceeded: 381931 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 381931 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 381931 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 381931 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 381931 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381931 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-10053 | 1 Gitlab | 1 Gitlab | 2026-08-23 | 8.5 High |
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry. | ||||
| CVE-2026-78155 | 2026-08-23 | 9.9 Critical | ||
| privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges | ||||
| CVE-2026-78112 | 1 Itsourcecode | 1 Hospital Management System Project In Php | 2026-08-23 | 6.3 Medium |
| A flaw has been found in itsourcecode Hospital Management System Project in PHP 1.0. This impacts an unknown function of the file /viewservicetype.php. This manipulation of the argument delid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | ||||
| CVE-2026-77115 | 1 Brave | 1 Brave | 2026-08-23 | N/A |
| Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them. | ||||
| CVE-2026-77116 | 1 Brave | 1 Brave | 2026-08-23 | N/A |
| Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-in user - Subscriber or WooCommerce Customer is enough — can read popup content they shouldn't have access to by passing a post ID in the URL. | ||||
| CVE-2026-13598 | 2026-08-23 | N/A | ||
| The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full site takeover. | ||||
| CVE-2026-14853 | 2026-08-23 | N/A | ||
| The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products. | ||||
| CVE-2026-77003 | 2026-08-23 | N/A | ||
| The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role as low as Contributor to publish posts and pages on the site without holding the publish capability. | ||||
| CVE-2026-78063 | 1 Tenda | 2 Ch22, Ch22 Firmware | 2026-08-23 | 7.4 High |
| A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. | ||||
| CVE-2026-78062 | 1 Vas3k | 1 Taxhacker | 2026-08-23 | 7.3 High |
| A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-78061 | 1 Vas3k | 1 Taxhacker | 2026-08-23 | 6.3 Medium |
| A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of the component Email Sync. Executing a manipulation of the argument host/port can lead to server-side request forgery. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance. | ||||
| CVE-2026-78060 | 1 Sourcecodester | 1 Stock Management System | 2026-08-23 | 4.3 Medium |
| A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /php_action/getOrderReport.php. Performing a manipulation of the argument clientName/clientContact results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. | ||||
| CVE-2026-78059 | 1 Sourcecodester | 1 Stock Management System | 2026-08-23 | 4.3 Medium |
| A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of the file /php_action/printOrder.php. Such manipulation of the argument clientName/clientContact leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2026-78136 | 2026-08-23 | 7.8 High | ||
| chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py. | ||||
| CVE-2026-78057 | 1 Sambitraj | 1 Student-management-system | 2026-08-23 | 6.3 Medium |
| A flaw has been found in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown part of the component Management Mutation Handler. This manipulation of the argument roll_no/name/father_name/class/mobile/email/password/remark causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-78056 | 1 Sambitraj | 1 Student-management-system | 2026-08-23 | 6.3 Medium |
| A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is some unknown functionality of the component Dashboard. The manipulation of the argument roll_no/teacher_name results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-78055 | 1 Sourcecodester | 1 Class And Exam Timetabling System | 2026-08-23 | 4.3 Medium |
| A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /BSIT2.php. The manipulation of the argument course leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. | ||||
| CVE-2026-78054 | 1 Sourcecodester | 1 Class And Exam Timetabling System | 2026-08-23 | 4.3 Medium |
| A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /BSIS1.php. Executing a manipulation of the argument course can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. | ||||
| CVE-2026-78051 | 1 Alexta69 | 1 Metube | 2026-08-22 | 5.3 Medium |
| A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the file /download/.metube/cookies.txt of the component Cookie File Handler. This manipulation causes files or directories accessible. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2026.06.20 is sufficient to resolve this issue. Patch name: ce897ee00903bf7ded406f0d7852d95dd4164add. You should upgrade the affected component. | ||||
| CVE-2026-47895 | 1 Strongswan | 1 Strongswan | 2026-08-22 | 7.5 High |
| In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed. | ||||