Export limit exceeded: 90511 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (90511 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-78057 | 1 Sambitraj | 1 Student-management-system | 2026-08-24 | 6.3 Medium |
| A flaw has been found in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown part of the component Management Mutation Handler. This manipulation of the argument roll_no/name/father_name/class/mobile/email/password/remark causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-77027 | 1 Fabrikar.com | 1 Fabrik Extension For Joomla | 2026-08-24 | N/A |
| Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads to an stored XSS vector. | ||||
| CVE-2026-66607 | 2 Themehunk, Wordpress | 2 Advance Product Search, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions. | ||||
| CVE-2024-34046 | 2026-08-24 | 7.5 High | ||
| The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->sctpParams->e2tCounters[IN_SUCC][MSG_COUNTER][ProcedureCode_id_RICsubscription]->Increment(). | ||||
| CVE-2024-31828 | 1 Lavalite | 2 Cms, Lavalite | 2026-08-24 | 6.1 Medium |
| Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL. | ||||
| CVE-2024-3154 | 1 Redhat | 1 Openshift | 2026-08-24 | 7.2 High |
| A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system. | ||||
| CVE-2026-28166 | 2 Goodlayers, Wordpress | 2 Tour Master, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions. | ||||
| CVE-2026-66610 | 2 Thembay, Wordpress | 2 Urna, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions. | ||||
| CVE-2026-28162 | 2 Franky, Wordpress | 2 Events Made Easy, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions. | ||||
| CVE-2026-78290 | 2 Themegrill, Wordpress | 2 Magazine Blocks, Wordpress | 2026-08-24 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions. | ||||
| CVE-2026-66917 | 1 Joomgalleryfriends.net | 1 Joomgallery Extension For Joomla | 2026-08-24 | N/A |
| Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image causing JS execution in every visitor's browser. | ||||
| CVE-2026-66623 | 2 Inisev, Wordpress | 2 Social Media & Share Icons, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions. | ||||
| CVE-2026-4561 | 2 Dvankooten, Wordpress | 2 Mc4wp: Mailchimp For Wordpress, Wordpress | 2026-08-24 | 6.4 Medium |
| The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form response message post meta fields (e.g., 'text_subscribed', 'text_error') in all versions up to, and including, 4.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-78246 | 1 Itsourcecode | 1 Online Clinic Management System | 2026-08-24 | 7.3 High |
| A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file success/login.php of the component Admin Login. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2026-76789 | 2026-08-23 | 8.8 High | ||
| The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript which will be executed in the context of an administrator viewing the Slider Hero with Video Background, Animation WordPress plugin before 9.1.3's admin area, as well as any visitor of a page embedding a slider. | ||||
| CVE-2026-50290 | 1 Asymmetric-effort | 1 Specifyjs | 2026-08-23 | N/A |
| SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, CSS value sanitization stripped `expression(` and `url(javascript:` using simple regex, but could be bypassed with CSS unicode escapes (`\65xpression(`), null bytes, or CSS comments (`exp/**/ression(`). These CSS injection vectors only work in legacy browsers (IE6-IE10). SpecifyJS targets modern browsers. Starting in version 0.2.136, CSS sanitization now normalizes unicode escapes and strips CSS comments before pattern matching. Also checks for `behavior:`, `-moz-binding`, and `-o-link` patterns. | ||||
| CVE-2026-53529 | 1 Perber | 1 Leafwiki | 2026-08-23 | N/A |
| LeafWiki is a self-hosted wiki. Prior to version 0.10.2, page titles returned by the search API could be rendered as raw HTML in the frontend. A user with editor or administrator permissions could create or modify a page title containing an HTML/JavaScript payload. When another user searched for a matching term, the payload could execute in the victim’s browser. The impact depends on deployment configuration. With `--public-access` enabled, unauthenticated visitors could be affected. In authenticated-only deployments, the issue could be used for cross-user XSS against logged-in users who can access search results. The issue has been fixed in version 0.10.2 by ensuring that author-controlled page titles in search results are not interpreted as raw HTML by the browser while preserving search result highlighting. | ||||
| CVE-2026-77115 | 1 Brave | 1 Brave | 2026-08-23 | 7.1 High |
| Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them. | ||||
| CVE-2026-19221 | 2026-08-23 | 7.2 High | ||
| The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network. | ||||
| CVE-2026-16260 | 2026-08-23 | 6.8 Medium | ||
| The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript that executes in the session of any administrator who opens the affected item. | ||||