Export limit exceeded: 404441 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (103238 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66700 | 2 Wordpress, Zaytech | 2 Wordpress, Smart Online Order For Clover | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions. | ||||
| CVE-2026-47299 | 1 Microsoft | 2 Azure Monitor Agent, Azure Monitor Agent Linux Extension | 2026-08-13 | 7.2 High |
| Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-16863 | 1 Ibm | 1 I | 2026-08-13 | 7.7 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read. | ||||
| CVE-2026-16904 | 1 Ibm | 1 I | 2026-08-13 | 8.1 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper privilege management during monitor owner reassignment. | ||||
| CVE-2026-16931 | 1 Ibm | 1 I | 2026-08-13 | 7.5 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper handling of zero-length TCP options. | ||||
| CVE-2026-28173 | 2 Arraytics, Wordpress | 2 Wp Event Solution, Wordpress | 2026-08-13 | 7.1 High |
| Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions. | ||||
| CVE-2026-28175 | 2 Wordpress, Wp-buy | 2 Wordpress, Visitor Traffic Real Time Statistics | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions. | ||||
| CVE-2026-28176 | 2 Booking Activities Team, Wordpress | 2 Booking Activities, Wordpress | 2026-08-13 | 8.8 High |
| Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions. | ||||
| CVE-2026-17248 | 1 Ibm | 1 I | 2026-08-13 | 7.1 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special elements in an OS command. | ||||
| CVE-2026-61960 | 2 Themeisle, Wordpress | 2 Wp Full Stripe Free, Wordpress | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions. | ||||
| CVE-2026-61974 | 2 Kitae-park, Wordpress | 2 Mang Board Wp, Wordpress | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions. | ||||
| CVE-2026-61980 | 2 Daan.dev, Wordpress | 2 Omgf Pro, Wordpress | 2026-08-13 | 7.5 High |
| Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions. | ||||
| CVE-2026-61984 | 2 Amauri, Wordpress | 2 Wpmobile.app, Wordpress | 2026-08-13 | 7.5 High |
| Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions. | ||||
| CVE-2026-17271 | 1 Ibm | 1 I | 2026-08-13 | 7.5 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size. | ||||
| CVE-2026-18713 | 1 Ibm | 1 I | 2026-08-13 | 8.8 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands. | ||||
| CVE-2026-18669 | 1 Ibm | 1 I | 2026-08-13 | 8.8 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority. | ||||
| CVE-2026-18235 | 1 Ibm | 1 I | 2026-08-13 | 8.3 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Control Language commands due to insufficient input validation. | ||||
| CVE-2026-17418 | 1 Ibm | 1 I | 2026-08-13 | 8.5 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elements used in an SQL command. | ||||
| CVE-2026-58484 | 2 Jovancoding, Network-ai | 2 Network-ai, Network-ai | 2026-08-13 | 7.1 High |
| Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()` reads each backup's `_manifest.json` and trusts the manifest's `path` field. `EnvironmentManager.pruneBackups()` later passes that trusted `entry.path` directly to `rmSync(entry.path, { recursive: true, force: true })`. An attacker who can place or modify a manifest inside `data/<env>/.backups/<name>/_manifest.json` can cause `network-ai env backup prune --env <env> --keep <n>` or any code path invoking `pruneBackups()` to recursively delete an arbitrary path accessible to the Network-AI process user. This is fixed in v5.12.2. `pruneBackups()` no longer passes `entry.path` from the on-disk manifest to `rmSync`. The deletion path is recomputed from a format-validated `entry.backupId`, and a `dirname` containment check confines deletion to exactly one level under the backups directory. A poisoned manifest (e.g. `"path": "/"`) is now inert. | ||||
| CVE-2026-73246 | 1 Kestra-io | 1 Kestra | 2026-08-13 | 7.5 High |
| Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndpoint.java serves GET /worker without authentication and serializes the complete live Task object, which can expose commands, environment variables, HTTP headers, connection details, plaintext credentials, and execution identifiers while the main API on port 8080 remains protected. This issue is fixed in 2.0.0-rc6. | ||||