Search Results (379067 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-73359 2026-08-18 6.5 Medium
Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.
CVE-2026-73356 2026-08-18 8.2 High
Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.
CVE-2026-73351 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.
CVE-2026-73342 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.
CVE-2026-73339 2026-08-18 9.3 Critical
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
CVE-2026-73189 2026-08-18 6.5 Medium
Subscriber Insecure Direct Object References (IDOR) in WP Crowdfunding < 2.2.1 versions.
CVE-2026-73181 2026-08-18 7.5 High
Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.
CVE-2026-68565 2026-08-18 6.5 Medium
Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.
CVE-2026-68517 1 Nicolargo 1 Glances 2026-08-18 6.5 Medium
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list containing the wildcard to retain cors_credentials and expose authenticated REST API data to an untrusted website visited by a previously authenticated user. This issue is fixed in 4.5.6.
CVE-2026-66667 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions.
CVE-2026-66645 2026-08-18 6.5 Medium
Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
CVE-2026-66639 2026-08-18 6.5 Medium
Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions.
CVE-2026-66634 2026-08-18 4.3 Medium
Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.
CVE-2026-66621 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions.
CVE-2026-65974 1 Frappe 1 Erpnext 2026-08-18 9.9 Critical
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forcing restrict_globals, allowing server-side template injection and remote code execution. This issue is fixed in versions 15.111.0 and 16.22.0.
CVE-2026-64865 1 Quantumnous 1 New-api 2026-08-18 N/A
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_modules can race relay billing because controller/user.go calls User.Update and updateUserCache performs a full RedisHSetObj write to user:.Quota, overwriting concurrent HINCRBY deductions and allowing an authenticated user to keep cached quota artificially high. This issue is fixed in version 1.0.0-rc.16.
CVE-2026-59909 1 Dell 1 Objectscale 2026-08-18 7.1 High
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
CVE-2026-59902 1 Netty 1 Netty 2026-08-18 7.5 High
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing unauthenticated peers to exhaust memory with large SCTP fragments. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.
CVE-2026-56684 2026-08-18 7.5 High
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger CLIENT KILL, causing connTLSClose to delete the iterator's cached next node and producing a use-after-free that can crash the server or potentially allow remote code execution when TLS is enabled. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.
CVE-2026-56090 1 Dell 1 Objectscale 2026-08-18 7.3 High
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.