Export limit exceeded: 95570 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (95570 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-55066 | 1 Go-vikunja | 1 Vikunja | 2026-08-28 | 7.1 High |
| Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks accepts a body supplied task_id but TaskBucket.CanUpdate in pkg/models/kanban_task_bucket.go authorizes only the project, view, and bucket from the URL. updateTaskBucket then calls Task.ReadOne without a separate task permission check, returns the victim task contents, and can update the task done state when the attacker chooses a done bucket. Because task identifiers are global sequential values, an authenticated user can enumerate cross-tenant tasks and modify their completion metadata through both the v1 and v2 routes that share this model. This issue is fixed in version 2.4.0. | ||||
| CVE-2026-18904 | 1 Ibm | 1 Langflow Oss | 2026-08-28 | 8.2 High |
| IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers. | ||||
| CVE-2026-18899 | 1 Ibm | 1 Langflow Oss | 2026-08-28 | 7.5 High |
| IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal. | ||||
| CVE-2026-18891 | 1 Ibm | 1 Langflow Oss | 2026-08-28 | 8.2 High |
| IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication. | ||||
| CVE-2026-18729 | 1 Ibm | 1 Langflow Oss | 2026-08-28 | 8.8 High |
| IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code. | ||||
| CVE-2026-71110 | 1 Oracle | 1 Helidon | 2026-08-28 | 8.1 High |
| Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.18, 3.0.0-3.2.17 and 4.0.0-4.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). | ||||
| CVE-2026-17203 | 1 Ibm | 1 Administration Runtime Expert For I | 2026-08-28 | 7.5 High |
| IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement. | ||||
| CVE-2026-16821 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-28 | 7 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability. | ||||
| CVE-2026-76886 | 1 Wireshark | 1 Wireshark | 2026-08-28 | 8.1 High |
| C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-75005 | 1 Apache | 1 Apisix | 2026-08-28 | 7.5 High |
| Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes. This issue affects Apache APISIX: 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue. | ||||
| CVE-2026-82072 | 1 Google | 1 Chrome | 2026-08-28 | 8.8 High |
| Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-32556 | 2 Pixelyoursite Professional, Wordpress | 2 Boost, Wordpress | 2026-08-28 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions. | ||||
| CVE-2026-32560 | 2 Liquidthemes, Wordpress | 2 Magicai For Wordpress - Ai Text, Image, Chat, Code, And Voice Generator, Wordpress | 2026-08-28 | 8.8 High |
| Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions. | ||||
| CVE-2026-78268 | 2 Extend Themes, Wordpress | 2 Lead Generation Contact Widget & Ai Chatbot: Chat Button, Phone Call, Telegram, Email – Siteleads, Wordpress | 2026-08-28 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions. | ||||
| CVE-2026-66766 | 1 Sap Se | 1 Sap S/4hana (manage Supply Protection) | 2026-08-28 | 7.5 High |
| SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful exploitation could exhaust system resources and make the service unavailable, resulting in a high impact on availability. There is no impact on confidentiality and integrity. | ||||
| CVE-2026-78685 | 1 Le-yan | 1 Medical Practice Management System | 2026-08-28 | 8.8 High |
| Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Unauthenticated remote attackers can execute arbitrary OS commamnds via a crafted HTML page. | ||||
| CVE-2026-16601 | 2 Creativemindssolutions, Wordpress | 2 Cm Map Locations – Visualize And Share Your Locations In A Few Clicks, Wordpress | 2026-08-28 | 8.8 High |
| The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Limited Arbitrary File Upload in all versions up to, and including, 2.1.8 via the uploadMedia function. This is due to insufficient file type validation in the upload handler, which performs incomplete extension filtering without MIME-type checks or upload capability verification before passing attacker-supplied files to move_uploaded_file(). This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. The required nonce is exposed to any logged-in Subscriber via the CMLOC_Editor_Images JavaScript object on the front-end location editor page. | ||||
| CVE-2026-67578 | 1 Furuno Electric | 1 Fa-50 | 2026-08-28 | 7.5 High |
| FA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network can manipulate the product's settings screen to alter some configuration parameters. | ||||
| CVE-2026-78576 | 2 Readabler, Wordpress | 2 Readabler, Wordpress | 2026-08-28 | 7.5 High |
| The Readabler plugin for WordPress is vulnerable to SQL Injection in all versions up to 2.0.18 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-75037 | 1 Ilya-zlobintsev | 1 Lact | 2026-08-28 | 7 High |
| Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. This issue affects LACT through 0.10.0. Fixed by commit d0478fe42c2219454e272f96b1cbd29ab37ee566. | ||||