Export limit exceeded: 90490 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (90490 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-54758 | 1 Notepad-plus-plus | 1 Notepad++ | 2026-08-24 | 7.8 High |
| Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the expandNppEnvironmentStrs function in PowerEditor/src/WinControls/StaticDialog/RunDlg/RunDlg.cpp copies a Notepad++ variable name between $( and ) into the fixed-size wchar_t str[MAX_PATH] stack buffer without bounding the m loop index, allowing a name of 260 or more characters to corrupt adjacent stack data, terminate the process through __report_gsfailure, and potentially execute code. This issue is fixed in version 8.9.7. | ||||
| CVE-2026-71858 | 1 Notepad-plus-plus | 1 Notepad++ | 2026-08-24 | N/A |
| Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attacker-controlled shortcuts.xml bypass the HMAC validation applied to UserDefinedCommands and can invoke Scintilla actions and the internal Open in Default Viewer command in an elevated Notepad++ process, allowing protected file modification and conditional elevated command execution when a local attacker influences settingsDir and a user triggers the macro. This issue is fixed in version 8.9.7. | ||||
| CVE-2026-66636 | 2 Marcin, Wordpress | 2 Wise Chat, Wordpress | 2026-08-24 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions. | ||||
| CVE-2026-66641 | 2 Deepen Bajracharya, Wordpress | 2 Video Conferencing With Zoom, Wordpress | 2026-08-24 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions. | ||||
| CVE-2026-66667 | 2 Wordpress, Wpdeveloper | 2 Wordpress, Templately | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions. | ||||
| CVE-2026-78211 | 1 4mosan Security Technology | 1 4mosan Gcb Doctor | 2026-08-24 | 9.8 Critical |
| 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter, thereby executing arbitrary system commands on the server. | ||||
| CVE-2026-59561 | 1 Sakura-editor | 1 Sakura | 2026-08-24 | N/A |
| Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal". | ||||
| CVE-2026-78200 | 1 Itsourcecode | 1 Library Management System | 2026-08-24 | 6.3 Medium |
| A flaw has been found in itsourcecode Library Management System 1.0. The affected element is an unknown function of the file editbooks.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | ||||
| CVE-2026-78321 | 1 Dji | 15 Air 3, Air 3s, Dji Avata 2 and 12 more | 2026-08-24 | N/A |
| The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's internal network can exhaust the server's connection pool by repeatedly requesting a stored media file, preventing the server from handling legitimate requests and causing a denial of service that prevents the DJI Fly application from retrieving photos and videos from the aircraft in QuickTransfer mode. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor. | ||||
| CVE-2026-66599 | 2 Liquid Web / Stellarwp, Wordpress | 2 Wpcomplete, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions. | ||||
| CVE-2026-32476 | 2 Amplebyte Pvt Limited, Wordpress | 2 Brave Conversion Engine (pro), Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions. | ||||
| CVE-2026-71907 | 1 Draytek | 12 Vigorap 1060c, Vigorap 1060c Firmware, Vigorap 903 and 9 more | 2026-08-24 | 7.2 High |
| Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability is caused by insufficient filtering of the selectSlaves field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface. | ||||
| CVE-2026-71909 | 1 Draytek | 12 Vigorap 1060c, Vigorap 1060c Firmware, Vigorap 903 and 9 more | 2026-08-24 | 7.2 High |
| Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface. | ||||
| CVE-2026-9254 | 1 Tp-link | 3 Archer Ax75 V1, Archer Be3600 V1, Archer Be800 V1 | 2026-08-24 | N/A |
| An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges. Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic. | ||||
| CVE-2026-16348 | 1 Tp-link | 1 Archer Be800 V1 | 2026-08-24 | N/A |
| An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection. Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices. | ||||
| CVE-2026-78541 | 1 Tp-link | 1 Archer Be3600 V1 | 2026-08-24 | N/A |
| A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during daily cloud report generation and may result in arbitrary command execution. Successful exploitation may allow command execution on the affected device with potential impact to device confidentiality, integrity, and availability. | ||||
| CVE-2026-78553 | 1 Ransomlook | 1 Ransomlook | 2026-08-24 | N/A |
| RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key file was created using the process's default permissions and umask, resulting in permissions such as 0644 under a common 022 umask. Consequently, other local users able to access the RansomLook home directory could read the application's cryptographic secret. The exposed key is security-critical because it is used to sign Flask session cookies and is also involved in the legacy API-key key derivation. An attacker who obtains the key can generate valid session cookies and impersonate an authenticated user, including an administrator. In LDAP configurations, exploitation may be particularly straightforward because the session user loader does not require the supplied username to correspond to an existing local user. Successful exploitation requires local access sufficient to read the improperly protected file, but can result in complete compromise of RansomLook's authentication and authorization controls. The patch creates new secret-key files atomically with permissions 0600 and also restricts permissions on existing key files during application startup. | ||||
| CVE-2026-28568 | 2 Mdmag, Wordpress | 2 Quill Forms, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. | ||||
| CVE-2026-28569 | 2 Sslzen, Wordpress | 2 Ssl Zen, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions. | ||||
| CVE-2026-32547 | 2 Wordplus, Wordpress | 2 Better Messages, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. | ||||