Export limit exceeded: 398757 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 42582 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (42582 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-54570 | 1 Anglesharp | 1 Anglesharp | 2026-08-21 | 6.9 Medium |
| AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnotationXmlElement in AngleSharp/Mathml/Dom/Internal/MathAnnotationXmlElement.cs is not treated as an HTML integration point when its encoding attribute is text/html or application/xhtml+xml, causing Consume in AngleSharp/Html/Parser/HtmlDomBuilder.cs to route tokens through foreign-content parsing instead of HTML parsing. A sanitizer can therefore observe a different DOM from the browser that reparses the serialized output. An attacker can combine this namespace differential with markup-breaking characters in an attribute value so that an element hidden from the sanitizer becomes active script-capable HTML after browser reparse, resulting in mutation cross-site scripting. This issue is fixed in version 1.5.0. | ||||
| CVE-2026-53453 | 1 Ha-china | 1 Blueprint-studio | 2026-08-21 | N/A |
| Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any authenticated Home Assistant user because the backend did not consistently enforce the panel's admin-only authorization boundary. Affected surfaces included the backend API, upload API, stream routes, terminal WebSocket, Blueprint Studio WebSocket subscriptions, call_service, render_template, global_replace, file and stream access paths, upload handling, and terminal helpers. A non-admin user could invoke arbitrary Home Assistant services, expose Home Assistant state through templates, modify configuration files, access streamed or downloaded configuration content, upload files, or reach terminal-related helpers. These actions could compromise the confidentiality, integrity, and availability of the Home Assistant installation. This issue is fixed in version 2.5.2. | ||||
| CVE-2026-52854 | 1 Professionalwiki | 1 Maps | 2026-08-21 | 8.6 High |
| Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays parameter, and resources/leaflet/jquery.leaflet.js uses the overlay name as a Leaflet layer-control label without escaping it. A wiki user with the edit permission can store malicious wikitext that causes script execution when another user previews or views the affected map. The script executes in the viewing user's browser session and can access data or perform actions available to that user. This issue is fixed in version 12.1.3. | ||||
| CVE-2026-70408 | 1 Extra Innovation | 2 Acmailer Cgi, Acmailer Db | 2026-08-21 | N/A |
| An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges. | ||||
| CVE-2026-73394 | 2 Stitchexpress, Wordpress | 2 Stitch Express, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions. | ||||
| CVE-2026-32552 | 2 Wordpress, Yith | 2 Wordpress, Yith Woocommerce Membership Premium | 2026-08-21 | 8.5 High |
| Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions. | ||||
| CVE-2026-73183 | 2 Get Maps Marker Pro, Wordpress | 2 Maps Marker Pro, Wordpress | 2026-08-21 | 9.3 Critical |
| Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. | ||||
| CVE-2026-73385 | 2 Outanking Team, Wordpress | 2 Outranking Plugin Options, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions. | ||||
| CVE-2026-73391 | 2 Klbtheme, Wordpress | 2 Total Donations, Wordpress | 2026-08-21 | 9.3 Critical |
| Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. | ||||
| CVE-2026-74021 | 2 Anders Norén, Wordpress | 2 Chaplin, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions. | ||||
| CVE-2026-66594 | 2 Lukeseager, Wordpress | 2 Wordpress Persistent Login, Wordpress | 2026-08-21 | 8.5 High |
| Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. | ||||
| CVE-2026-66609 | 2 Codexthemes, Wordpress | 2 Thegem (elementor), Wordpress | 2026-08-21 | 9.3 Critical |
| Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. | ||||
| CVE-2026-66647 | 2 Radiustheme, Wordpress | 2 Homlisti, Wordpress | 2026-08-21 | 6.5 Medium |
| Subscriber Broken Access Control in Homlisti <= 3.1.2 versions. | ||||
| CVE-2026-73998 | 2 Axew3, Wordpress | 2 Wp W3all Phpbb, Wordpress | 2026-08-21 | 8.5 High |
| Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. | ||||
| CVE-2026-74013 | 2 Wordpress, Wordpress.com | 2 Wordpress, Eshipper Commerce | 2026-08-21 | 8.5 High |
| Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions. | ||||
| CVE-2026-74020 | 2 Anders Norén, Wordpress | 2 Koji, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Broken Access Control in Koji <= 2.2.1 versions. | ||||
| CVE-2026-28163 | 2 Mycred, Wordpress | 2 New User Approve, Wordpress | 2026-08-21 | 5.3 Medium |
| Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects New User Approve: from n/a through 3.2.8. | ||||
| CVE-2026-77391 | 1 Sourcecodester | 2 Dynamic Input Field Generator Using Html, Css, And Php, Dynamic Input Field Generator Using Html Css And Php | 2026-08-21 | 4.3 Medium |
| A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. | ||||
| CVE-2026-77392 | 1 Sourcecodester | 2 Dynamic Input Field Generator Using Html, Css, And Php, Dynamic Input Field Generator Using Html Css And Php | 2026-08-21 | 6.3 Medium |
| A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. | ||||
| CVE-2025-14603 | 1 Vsdesk | 1 Vsdesk | 2026-08-20 | N/A |
| The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch. | ||||