Export limit exceeded: 16390 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 401094 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 90685 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (90685 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-66640 2 Marcus (aka @msykes), Wordpress 2 Login With Ajax, Wordpress 2026-08-21 6.5 Medium
Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.
CVE-2026-66643 2 Wordpress, Wronganswersonly 2 Wordpress, Wufoo Shortcode 2026-08-21 6.5 Medium
Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.
CVE-2026-66645 2 Wordpress, Wpdeveloper 2 Wordpress, Table Of Contents Block 2026-08-21 6.5 Medium
Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
CVE-2026-66646 2 Mythemeshop, Wordpress 2 Wp Tab Widget, Wordpress 2026-08-21 6.5 Medium
Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions.
CVE-2026-68567 2 Wordpress, Wp Grids 2 Wordpress, Convert Pro 2026-08-21 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions.
CVE-2026-73338 2 Autopay, Wordpress 2 Autopay, Wordpress 2026-08-21 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.
CVE-2026-73342 2 Magazine3, Wordpress 2 Wp Multilang, Wordpress 2026-08-21 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.
CVE-2026-73359 2 Wordpress, Wp Legal Pages 2 Wordpress, Wp Cookie Notice For Gdpr, Ccpa & Eprivacy Consent 2026-08-21 6.5 Medium
Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.
CVE-2026-73375 2 Supsystic, Wordpress 2 Ultimate Maps By Supsystic, Wordpress 2026-08-21 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
CVE-2026-73997 2 Nexcess, Wordpress 2 Starter Templates By Kadence Wp, Wordpress 2026-08-21 7.5 High
Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
CVE-2026-50161 1 Baresip 1 Re 2026-08-21 N/A
libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the websock_decode() function in src/websock/websock.c contains an integer overflow when validating a masked WebSocket frame that uses the 64-bit extended length encoding. The expression 4 + hdr->len can wrap when hdr->len is close to UINT64_MAX, causing the mbuf_get_left() bounds check to pass. The subsequent XOR unmasking loop then writes beyond the heap buffer. Applications using websock_accept() or websock_accept_proto() to implement a WebSocket server are affected, and exploitation can cause attacker-controlled heap corruption or denial of service after the HTTP WebSocket upgrade handshake. This issue is fixed in version 4.8.1.
CVE-2026-53533 1 Cole 1 Aiosmtplib 2026-08-21 N/A
aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-supplied addresses without rejecting embedded CR or LF bytes. Data after the line break is framed as additional standalone SMTP command lines, allowing an attacker who influences an envelope sender or recipient to inject commands such as MAIL FROM, RCPT TO, RSET, DATA, or AUTH. SMTP.sendmail() and SMTP.send() without a Message object pass addresses through the affected methods, while SMTP.send_message() is not affected. Successful injection can desynchronize the command-response pipeline, hang the SMTP instance, or send an arbitrary message without requiring attacker control of the SMTP server. This issue is fixed in version 5.1.1.
CVE-2026-71551 1 Super-productivity 1 Super-productivity 2026-08-21 7.8 High
Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabilities. Prior to 18.13.0, the EXEC IPC handler in electron/ipc-handlers/exec.ts accepts a command string from the renderer through the IPC.EXEC channel and executes it with child_process.exec(). The electron/preload.ts bridge exposes window.ea.exec() to renderer code, including community plugins executed with new Function(), without requiring nodeExecution permission. A confirmation dialog protects only the first execution, its persistence checkbox is selected by default, and approved commands are stored in the ALLOWED_COMMANDS value in simpleSettings for silent later execution with the desktop account's privileges. This issue is fixed in version 18.13.0.
CVE-2025-9211 1 Otalio 1 Ship Property Management System 2026-08-21 6.7 Medium
Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via persistent cross-site scripting
CVE-2026-53455 1 Ha-china 1 Blueprint-studio 2026-08-21 N/A
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio generated a shell-based Git credential helper in custom_components/blueprint_studio/backend/git_manager.py by interpolating the configured Git username and token directly into executable helper script content without validating credential values. An attacker able to set Git credentials could include newline characters or shell syntax in a username or token. When Git executed the generated credential helper, the injected shell commands ran with the operating-system privileges of Home Assistant and could access or modify Home Assistant configuration data. This issue is fixed in version 2.5.2.
CVE-2026-55426 1 Linuxfabrik 2 Lib, Monitoring-plugins 2026-08-21 7.8 High
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands. From the earliest affected releases until linuxfabrik-lib 5.0.0 and Linuxfabrik Monitoring Plugins 6.0.0, check plugins embedded user-controlled values in command strings passed to lib.shell.shell_exec(), which split strings at pipe characters and executed the resulting commands. In check-plugins/restic-check/restic-check, the --repo parameter could inject a pipe-delimited command into a constructed restic invocation, and sudo-authorized execution allowed a compromised nagios or icinga account to run that command as root. The shared library also accepted command strings and a shell parameter, while numerous plugins constructed external commands from attacker-influenced arguments. The fixes require argv lists, always use shell=False, remove pipe splitting, and reject option-like positional values through lib.shell.safe_cli_value(). These issues are fixed in linuxfabrik-lib 5.0.0 and Linuxfabrik Monitoring Plugins 6.0.0.
CVE-2026-71079 2 Oracle, Oracle Corporation 3 Mysql Connector/odbc, Mysql Connector\/odbc, Mysql Connectors 2026-08-21 6.5 Medium
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CVE-2026-52854 1 Professionalwiki 1 Maps 2026-08-21 8.6 High
Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays parameter, and resources/leaflet/jquery.leaflet.js uses the overlay name as a Leaflet layer-control label without escaping it. A wiki user with the edit permission can store malicious wikitext that causes script execution when another user previews or views the affected map. The script executes in the viewing user's browser session and can access data or perform actions available to that user. This issue is fixed in version 12.1.3.
CVE-2026-15421 2 Siteground, Wordpress 2 Speed Optimizer – The All-in-one Performance-boosting Plugin, Wordpress 2026-08-21 6.4 Medium
The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Image Tag Attributes in all versions up to, and including, 7.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the site administrator has enabled the Lazy Load Media option in the plugin settings.
CVE-2026-66358 1 Extra Innovation 2 Acmailer Cgi, Acmailer Db 2026-08-21 N/A
A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script.