Export limit exceeded: 14755 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (27047 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-20303 | 1 Cisco | 2 Catalyst Sd-wan Manager, Cisco Catalyst Sd-wan Controller | 2026-08-07 | 9.9 Critical |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20. | ||||
| CVE-2026-70437 | 1 Jenkins Project | 1 Jenkins Webhook Secret Credentials Provider Plugin | 2026-08-07 | 3.7 Low |
| Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token. | ||||
| CVE-2024-10302 | 1 Wso2 | 8 Wso2 Api Control Plane, Wso2 Api Manager, Wso2 Carbon Identity Recovery Management and 5 more | 2026-08-07 | 4 Medium |
| The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowing unvalidated input into user claims can lead to various security risks. Malicious or malformed data injected during signup could be processed by other parts of the application, potentially enabling attacks such as content manipulation, redirection, user interface inconsistencies, unauthorized actions, and data exposure. The actual impact depends on how the compromised data is consumed and the privileges associated with the affected users. | ||||
| CVE-2026-16316 | 2 Omicron Electronics, Omicron Electronics Gmbh | 2 Omicron Stationguard, Omicron Stationguard | 2026-08-07 | 4.3 Medium |
| OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame processing. A specially crafted SV frame can cause the affected process to terminate, disrupting alert processing for Sampled Values traffic. The vulnerability does not affect overall system availability or the processing of other traffic types, and the process is automatically restarted, and the failure is immediately reported to the user. | ||||
| CVE-2026-16731 | 2 Omicron Electronics, Omicron Electronics Gmbh | 2 Omicron Stationscout, Omicron Stationscout | 2026-08-07 | N/A |
| OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients. An attacker can gain full access to the system configuration, allowing modification, reset, or unauthorized alteration of system parameters or injecting network traffic into the connected network. | ||||
| CVE-2026-54489 | 1 Dell | 1 Virtual Storage Integrator For Vmware Vsphere Client | 2026-08-07 | 9.1 Critical |
| Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity. | ||||
| CVE-2026-65543 | 2 Vimeodev, Wordpress | 2 Vimeo, Wordpress | 2026-08-07 | 7.5 High |
| Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions. | ||||
| CVE-2026-66683 | 2 Wordpress, Wp Zone | 2 Wordpress, Custom Css And Javascript | 2026-08-07 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions. | ||||
| CVE-2026-66685 | 2 Alex, Wordpress | 2 Featured Video Plus, Wordpress | 2026-08-07 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions. | ||||
| CVE-2026-66696 | 2 Nexcess, Wordpress | 2 Gutenberg Blocks By Kadence Blocks, Wordpress | 2026-08-07 | 4.3 Medium |
| Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions. | ||||
| CVE-2026-48078 | 1 Open-reception | 1 Appointment-booking-software | 2026-08-07 | 5.3 Medium |
| OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticated `/api/tenants/{id}/schedule` endpoint returns every non-archived channel for a tenant regardless of the channel's `isPublic` flag. Channels marked `isPublic = false` are intended to be invisible to public callers; the dashboard creates them deliberately to hide internal-only services from the patient booking UI. The schedule endpoint ignores the flag entirely and discloses channel names, descriptions, IDs, agent associations, pause status, confirmation requirements, and computed slot availability for the requested date range. The asymmetry between `addAppointmentToTunnel` (which enforces `eq(channel.isPublic, true)`) and the schedule endpoint (which does not) confirms the design intent: private channels exist as a real access boundary in the booking flow, just not in the schedule disclosure. Version 1.0.5 patches the issue. | ||||
| CVE-2026-54206 | 2026-08-07 | N/A | ||
| Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to attacker-controlled SMB servers. This enables authenticated attackers to trigger the server to authenticate to arbitrary SMB endpoints, potentially exposing NTLM authentication information (such as NTLM hashes). If outbound connections to port 445 (SMB) are permitted, attackers can use this to conduct SMB relay or credential theft attacks. Exploitation of the “pathname” parameter is possible without authentication. This issue affects TeamDavid through Rollout 524. | ||||
| CVE-2026-54203 | 2026-08-07 | N/A | ||
| Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing the URL “/.well-known/mta-sts.”, the application responds with memory. By repeatedly requesting this endpoint, an attacker can access sensitive information, including user passwords. Exploitation does not require authentication. This issue affects TeamDavid through Rollout 524. | ||||
| CVE-2026-54199 | 2026-08-07 | N/A | ||
| Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the application's link storing functionality (//ServerClient_celink.htm), which is appended to the redirect target in the 302 HTTP response. If a line feed is added, this will also be added to the redirect link, resulting in the ability to control the response headers. This issue affects TeamDavid through Rollout 524. | ||||
| CVE-2026-16968 | 2 Wordpress, Wpgeodirectory | 2 Wordpress, Geodirectory | 2026-08-07 | 6.5 Medium |
| The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators. | ||||
| CVE-2026-20273 | 1 Cisco | 1 Ios Xe Software | 2026-08-07 | 8.6 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20273 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20. | ||||
| CVE-2026-13153 | 2 Wordpress, Wpdevteam | 2 Wordpress, Gutenberg Essential Blocks | 2026-08-07 | 7.5 High |
| The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product. | ||||
| CVE-2026-13154 | 2 Wordpress, Wpdevteam | 2 Wordpress, Gutenberg Essential Blocks | 2026-08-07 | 7.5 High |
| The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public. | ||||
| CVE-2025-13909 | 1 Wso2 | 7 Carbon Identity Application Authentication Framework, Email Otp Authenticator, Identity Server and 4 more | 2026-08-07 | 4.3 Medium |
| The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This failure to adequately separate user data between tenants can lead to the exposure of personally identifiable information. Successful exploitation allows an attacker to disclose personally identifiable information of users in different tenants, resulting in privacy violations and potential regulatory non-compliance. This may include unauthorized access to user details such as mobile numbers. | ||||
| CVE-2026-19169 | 1 Google | 1 Chrome | 2026-08-07 | 8.8 High |
| Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: High) | ||||