Export limit exceeded: 379027 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (379027 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66640 | 2026-08-18 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions. | ||||
| CVE-2026-66638 | 2026-08-18 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. | ||||
| CVE-2026-66637 | 2026-08-18 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions. | ||||
| CVE-2026-66636 | 2026-08-18 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions. | ||||
| CVE-2026-66635 | 2026-08-18 | 7.4 High | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions. | ||||
| CVE-2026-66633 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. | ||||
| CVE-2026-66629 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions. | ||||
| CVE-2026-66627 | 2026-08-18 | 9.9 Critical | ||
| Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions. | ||||
| CVE-2026-66622 | 2026-08-18 | 7.5 High | ||
| Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions. | ||||
| CVE-2026-66620 | 2026-08-18 | 7.2 High | ||
| Editor PHP Object Injection in OptionTree <= 2.7.3 versions. | ||||
| CVE-2026-75774 | 1 Karakeep-app | 1 Karakeep | 2026-08-18 | 3.7 Low |
| A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the file apps/web/server/auth.ts of the component OAuth Sign-In. This manipulation causes improper authentication. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-32553 | 2026-08-18 | 7.2 High | ||
| Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions. | ||||
| CVE-2026-32549 | 2026-08-18 | 7.5 High | ||
| Unauthenticated Broken Access Control in ThumbPress < 6.5 versions. | ||||
| CVE-2026-32547 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. | ||||
| CVE-2026-32474 | 2026-08-18 | 9.9 Critical | ||
| Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. | ||||
| CVE-2026-32473 | 2026-08-18 | 7.2 High | ||
| Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions. | ||||
| CVE-2026-32472 | 2026-08-18 | 7.5 High | ||
| Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions. | ||||
| CVE-2026-32470 | 2026-08-18 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | ||||
| CVE-2026-32468 | 2026-08-18 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. | ||||
| CVE-2026-32467 | 2026-08-18 | 6 Medium | ||
| Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. | ||||