Search

Search Results (377301 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-65582 2 Liquidthemes, Wordpress 2 Ai Hub, Wordpress 2026-08-13 7.7 High
Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions.
CVE-2026-64954 1 Rapid7 1 Velociraptor 2026-08-13 8.2 High
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "investigator" role). This vulnerability is an escalation from an analyst to investigator role.
CVE-2026-57858 1 Cal.com 1 Cal.com Self-hosted (cal.diy) 2026-08-13 8.9 High
Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to the affected public booking page, enabling session cookie theft, forged authenticated requests, and wormable propagation by chaining with CSRF-able endpoints to persist payloads on additional events.
CVE-2026-48771 1 Ishankjha740 1 Ishankportfolio 2026-08-13 8.2 High
ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly secured client-side database configuration and insufficient access control policies. Applications using publicly exposed database credentials or permissive database rules may allow unauthorised users to read, modify, or abuse stored form submission data. This could impact personally identifiable information (PII) submitted through the website contact form, including names, email addresses, phone numbers, and messages. The issue has been patched in version 1.0.1. Users unable to upgrade immediately can reduce risk by disabling public read/write database access, rotating exposed API keys, restricting database policies to authenticated requests only, moving sensitive operations to secure backend/serverless functions, and/or monitoring database activity logs for suspicious access.
CVE-2026-48762 1 Baptistearno 1 Typebot.io 2026-08-13 5.4 Medium
TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a user-supplied audio URL using `fetch()` without applying the SSRF protection that exists elsewhere in the codebase. An attacker can direct the server to make HTTP requests to arbitrary internal addresses and localhost. The fetched content is passed to the OpenAI Whisper API and the transcription result is returned to the attacker. Version 3.16.0 fixes the issue.
CVE-2026-48702 2026-08-13 7.5 High
Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file into in-memory buffers without bounding the total decompressed size. The existing `max_apk_metadata_size` check (default 1MB) is only applied to individual tar entry header sizes after decompression completes, so it does not prevent a decompression bomb from consuming unbounded heap memory. An attacker can craft a gzip stream that compresses at a ~1000:1 ratio (e.g., 2MB compressed zeros → 2GB decompressed). When submitted as spec.package.content in an Alpine `ProposedEntry`, the server decompresses the full payload into memory during request processing, triggering a fatal Go runtime out-of-memory error or OS OOM-kill that cannot be caught by the server's recover() middleware. This is reachable via two unauthenticated endpoints, `POST /api/v1/log/entries (createLogEntry)` and `POST /api/v1/log/entries/retrieve (searchLogQuery)`. Both invoke `V001Entry.Canonicalize()` → `fetchExternalEntities()` → `apk.Unmarshal(packageData)`, which performs the unbounded decompression. Version 1.5.2 patches the issue. There is no effective workaround. Setting `max_request_body_size` reduces but does not eliminate exposure due to the ~1000:1 compression ratio (a 1MB body limit still allows ~1GB heap allocation). Setting `max_apk_metadata_size` has no effect on this vulnerability since the check is applied after decompression.
CVE-2026-48046 1 Truelockmc 1 Streambert 2026-08-13 N/A
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process download and execute an arbitrary binary, resulting in remote code execution. Version 2.5.0 contains a patch.
CVE-2026-47229 1 Admidio 1 Admidio 2026-08-13 5.4 Medium
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm_csrf_token` on every state-changing branch except `enable`. The `enable` case loads the SAML or OIDC client by UUID, calls `$client->enable($enabled)`, and persists the new state with no token check. Because the action is reachable via plain GET parameters, a third-party page can trick an authenticated administrator into disabling (or silently re-enabling) any configured SAML or OIDC client. Disabling an SSO client breaks every downstream relying-party application that authenticates through it. Version 5.0.10 contains a fix.
CVE-2026-42018 1 Jfrog 1 Artifactory 2026-08-13 7.5 High
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CVE-2026-29036 1 Davegamble 1 Cjson 2026-08-13 7.5 High
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted JSON Pointer escape sequences (~0 or ~1) in patch paths. Attackers can submit malicious RFC 6902 JSON Patch input to applications using cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() to silently corrupt data or delete unintended keys, potentially bypassing authorization controls in applications that rely on JSON Patch for access-controlled data modification.
CVE-2026-28174 2 Arraytics, Wordpress 2 Wp Event Solution, Wordpress 2026-08-13 6.5 Medium
Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
CVE-2026-28170 2 Meril, Wordpress 2 Blog Floating Button, Wordpress 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions.
CVE-2026-28142 2 Shamalli, Wordpress 2 Web Directory Free, Wordpress 2026-08-13 9.3 Critical
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
CVE-2026-27544 2 Quarka, Wordpress 2 Qa Analytics, Wordpress 2026-08-13 10 Critical
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
CVE-2026-27543 2 Fluxbuilder, Wordpress 2 Mstore Api, Wordpress 2026-08-13 8.1 High
Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.
CVE-2026-27538 2 Wordpress, Wpdirectorykit 2 Wordpress, Wp Directory Kit 2026-08-13 7.5 High
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
CVE-2026-27536 2 Pluginops, Wordpress 2 Mailchimp Subscribe Form, Wordpress 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions.
CVE-2026-27535 2 Solacewp, Wordpress 2 Solace Extra, Wordpress 2026-08-13 7.1 High
Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
CVE-2026-27380 2 Magepeopleteam, Wordpress 2 Car Rental Manager, Wordpress 2026-08-13 7.2 High
Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
CVE-2026-19716 1 Maalfer 1 Pentestify 2026-08-13 N/A
Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the username with escapeHTML() before interpolating it into the onclick attribute of the account deletion button, but the browser HTML-decodes attribute values before the JavaScript engine parses the handler, allowing an encoded single quote (') to break out of the string literal and inject arbitrary JavaScript that executes when the victim clicks the delete button for that account.