Search

Search Results (374295 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-5134 1 Loca Software Informatics Technology 1 Cms 2026-08-07 9.8 Critical
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-64993 1 Dell 1 Rvtools 2026-08-07 6.8 Medium
Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.
CVE-2026-54489 1 Dell 1 Virtual Storage Integrator For Vmware Vsphere Client 2026-08-07 9.1 Critical
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.
CVE-2026-53975 1 Bohdan Triapitsyn 1 Openchamber 2026-08-07 9.8 Critical
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.
CVE-2026-53976 1 Bohdan Triapitsyn 1 Openchamber 2026-08-07 9.1 Critical
OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPathWithinRoot guard to read sensitive files such as the JWT signing secret, SSH private keys, API credentials, and environment variables, enabling full authentication bypass by forging session cookies on password-protected deployments.
CVE-2026-28141 2 Syed Balkhi, Wordpress 2 Nextgen Gallery, Wordpress 2026-08-07 7.1 High
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
CVE-2026-28172 2 Data443 Risk Mitigation, Inc., Wordpress 2 Tracking Code Manager, Wordpress 2026-08-07 7.1 High
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
CVE-2026-28177 2 Daniel Iser, Wordpress 2 Popup Maker, Wordpress 2026-08-07 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
CVE-2026-28179 2 Damian Góra, Wordpress 2 Fibosearch, Wordpress 2026-08-07 5.9 Medium
Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
CVE-2026-32469 2 Wordpress, Wpkube 2 Wordpress, Captcha 4wp 2026-08-07 5.3 Medium
Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
CVE-2026-65504 2 Ivanbebek, Wordpress 2 Box Now Delivery Croatia, Wordpress 2026-08-07 7.5 High
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
CVE-2026-65517 2 Scott Paterson, Wordpress 2 Easy Paypal Buy Now Button, Wordpress 2026-08-07 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.
CVE-2026-65523 2 Approveme, Wordpress 2 Formidable Forms Signature Online Contract Automation, Wordpress 2026-08-07 7.5 High
Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.
CVE-2026-65541 2 Solutioned, Wordpress 2 Staff Training, Wordpress 2026-08-07 7.3 High
Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
CVE-2026-65542 2 Rajat Varlani, Wordpress 2 Super Socializer, Wordpress 2026-08-07 8.8 High
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
CVE-2026-65543 2 Vimeodev, Wordpress 2 Vimeo, Wordpress 2026-08-07 7.5 High
Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
CVE-2026-65544 2 Rajat Varlani, Wordpress 2 Super Socializer, Wordpress 2026-08-07 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.
CVE-2026-65546 2 Qode, Wordpress 2 Qode Tours, Wordpress 2026-08-07 9.3 Critical
Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.
CVE-2026-65553 2 Wbolt.com, Wordpress 2 Spider Analyser – Wordpress搜索引擎蜘蛛分析插件, Wordpress 2026-08-07 10 Critical
Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
CVE-2026-65554 2 Lattepress, Wordpress 2 Anspress – Question And Answer, Wordpress 2026-08-07 7.1 High
Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.