Export limit exceeded: 382270 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (382270 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-39458 | 1 F5 | 22 Big-ip, Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager and 19 more | 2026-08-24 | 7.5 High |
| When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanced WAF DoS protection), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | ||||
| CVE-2026-78282 | 2026-08-24 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions. | ||||
| CVE-2026-78268 | 2026-08-24 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions. | ||||
| CVE-2026-78267 | 2026-08-24 | 9.8 Critical | ||
| Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions. | ||||
| CVE-2026-78266 | 2026-08-24 | 6.5 Medium | ||
| Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions. | ||||
| CVE-2026-78265 | 2026-08-24 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions. | ||||
| CVE-2026-78264 | 2026-08-24 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions. | ||||
| CVE-2026-78263 | 2026-08-24 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions. | ||||
| CVE-2026-78262 | 2026-08-24 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions. | ||||
| CVE-2026-78259 | 2026-08-24 | 7.3 High | ||
| Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions. | ||||
| CVE-2026-32563 | 2026-08-24 | 9.8 Critical | ||
| Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | ||||
| CVE-2026-32561 | 2026-08-24 | 8.8 High | ||
| Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions. | ||||
| CVE-2026-32560 | 2026-08-24 | 8.8 High | ||
| Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions. | ||||
| CVE-2026-32559 | 2026-08-24 | 9.9 Critical | ||
| Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions. | ||||
| CVE-2026-32556 | 2026-08-24 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions. | ||||
| CVE-2026-32555 | 2026-08-24 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Boost <= 2.0.4 versions. | ||||
| CVE-2026-32554 | 2026-08-24 | 9.3 Critical | ||
| Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions. | ||||
| CVE-2026-27364 | 2026-08-24 | 6.5 Medium | ||
| Subscriber Broken Access Control in Style Kits <= 2.6.5 versions. | ||||
| CVE-2026-78284 | 2026-08-24 | 8.6 High | ||
| Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions. | ||||
| CVE-2026-61241 | 1 Oracle | 1 Internet Directory | 2026-08-24 | 10 Critical |
| Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). | ||||