Export limit exceeded: 384591 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 48588 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (48588 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-54738 | 1 Lemmynet | 1 Lemmy | 2026-08-21 | 6.5 Medium |
| Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web ConnectionInfo::realip_remote_addr reads the first value of X-Forwarded-For as the client address used by raw_ip_key in crates/utils/src/rate_limit/mod.rs. Lemmy's bundled docker/nginx.conf uses $proxy_add_x_forwarded_for instead of $remote_addr, which appends the real client address to an X-Forwarded-For value supplied by the client. An unauthenticated attacker can therefore place a different spoofed address first on each request and receive a new rate-limit bucket, bypassing limits on POST /api/v4/account/auth/register, POST /api/v4/account/auth/login, POST /api/v4/post, POST /api/v4/comment, GET /api/v4/search, POST /api/v4/image, and POST /api/v4/account/import_settings. This permits excessive account creation, brute-force attempts, spam, scraping, uploads, and repeated imports. This issue is fixed in versions 0.19.19 and 1.0.0-beta.1. | ||||
| CVE-2026-30826 | 1 Combodo | 1 Itop | 2026-08-21 | 8 High |
| Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing OQL query functionality. This issue has been fixed in version 3.2.3. | ||||
| CVE-2026-30819 | 1 Combodo | 1 Itop | 2026-08-21 | 7.3 High |
| Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard_id in /pages/ajax.render.php. This issue has been fixed in version 3.2.3. | ||||
| CVE-2026-74800 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2026-08-21 | 9 Critical |
| SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files as assets and execute scripts with full kernel API access when the workspace owner opens the asset link. | ||||
| CVE-2026-13202 | 1 Opentext | 1 Directory Services | 2026-08-21 | N/A |
| A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue affects Opentext Directory Services: through 22.2. | ||||
| CVE-2026-33437 | 1 Stirling | 1 Stirling Pdf | 2026-08-21 | 8.1 High |
| Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, the Get Info workflow in app/core/src/main/resources/templates/security/get-info-on-pdf.html inserts untrusted PDF Title and Author metadata into the summary-text element with innerHTML, allowing a malicious PDF to execute stored cross-site scripting when a user clicks Get Info and to access browser-session data or modify page content. This issue is fixed in version 2.0.0. | ||||
| CVE-2026-63670 | 1 Apostrophecms | 1 Apostrophecms | 2026-08-21 | 6.1 Medium |
| ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included in allowedTags because a literal solidus after the raw-text end-tag name is treated as text by htmlparser2 and the ontext handler emits that content without escaping, while a browser parses the following img onerror markup as active HTML. This issue is fixed in version 2.17.6. | ||||
| CVE-2026-52606 | 1 Reportico | 1 Reportico | 2026-08-21 | 6.1 Medium |
| A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the loadTemplate parameter in conjunction with the execute_mode=PREPARE parameter of run.php. | ||||
| CVE-2026-52609 | 1 Reportico | 1 Reportico | 2026-08-21 | 6.1 Medium |
| A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the reportico_criteria parameter in conjunction with the execute_mode=CRITERIA parameter of run.php. | ||||
| CVE-2026-74902 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2026-08-21 | 8.6 High |
| SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting them into HTML via insertAdjacentHTML. Attackers can craft a malicious filename containing script payloads that execute with full OS command access when a user drags, drops, or pastes the file into the editor. | ||||
| CVE-2026-73336 | 1 Joomla | 1 Joomla! | 2026-08-21 | N/A |
| Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs. | ||||
| CVE-2026-74252 | 1 J2commerce.com | 1 J2store Extension For Joomla | 2026-08-21 | N/A |
| Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Commerce 4.1.5 is vulnerable to Stored Cross-Site Scripting (XSS) through the guest checkout billing address fields. An unauthenticated attacker exploits a filter bypass in Joomla's Input::getArray() combined with PHP's variables_order=EGPCS (Cookie overrides POST in $_REQUEST ) to store unsanitized HTML in fields such as billing_first_name. | ||||
| CVE-2026-27365 | 2 Publishpress, Wordpress | 2 Publishpress Series, Wordpress | 2026-08-21 | 5.9 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress PublishPress Series allows Stored XSS. This issue affects PublishPress Series: from n/a through 2.17.0. | ||||
| CVE-2026-18371 | 1 M-files Corporation | 1 M-files Web | 2026-08-21 | N/A |
| HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to affect web user interface contents displayed to other users. | ||||
| CVE-2026-18372 | 1 M-files Corporation | 1 M-files Web | 2026-08-21 | N/A |
| CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault administrator to inject arbitrary CSS, affecting the web user interface displayed to other vault users. | ||||
| CVE-2026-71960 | 1 Shenzhen Cudy Technology | 1 Wr3000 2.0 | 2026-08-21 | 9.1 Critical |
| Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image. Attackers can use the extracted secret to craft arbitrary JWT tokens and authenticate to the MQTT broker without legitimate credentials, gaining unauthorized access to the device's mesh networking interface. | ||||
| CVE-2026-66581 | 2 Crocoblock. Jetimpex Inc., Wordpress | 2 Jetengine, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. | ||||
| CVE-2026-77028 | 1 Yootheme.com | 1 Zoo Extension For Joomla | 2026-08-21 | N/A |
| Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66 | ||||
| CVE-2026-76612 | 1 Yootheme.com | 1 Zoo Extension For Joomla | 2026-08-21 | N/A |
| Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user supplied field elements weren't escaped, leading to a stored XSS vector. | ||||
| CVE-2026-75933 | 1 Jet Admin | 1 Jet Admin | 2026-08-21 | 7.3 High |
| Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and styles option. Injected script is executed in the context of any visiting user's domain. | ||||