Export limit exceeded: 375455 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (375455 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-19379 | 2 Efm, Iptime | 2 Iptime Ax8004m, Ax8004m | 2026-08-11 | 7.3 High |
| A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-17540 | 2 Filemanagerpro, Wordpress | 2 File Manager, Wordpress | 2026-08-11 | N/A |
| The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service. | ||||
| CVE-2026-17541 | 2 Filemanagerpro, Wordpress | 2 File Manager, Wordpress | 2026-08-11 | 7.5 High |
| The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them. | ||||
| CVE-2026-17542 | 2 Filemanagerpro, Wordpress | 2 File Manager, Wordpress | 2026-08-11 | 7.5 High |
| The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data. | ||||
| CVE-2026-15237 | 2 Motopress Hotel Booking, Wordpress | 2 Motopress Hotel Booking, Wordpress | 2026-08-11 | N/A |
| The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid. | ||||
| CVE-2026-19049 | 2 Prosolution, Wordpress | 2 Prosolution Wp Client, Wordpress | 2026-08-11 | N/A |
| The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the database and to delete the records the ProSolution WP Client WordPress plugin before 2.0.9 stores. | ||||
| CVE-2026-19053 | 2 Prosolution, Wordpress | 2 Prosolution Wp Client, Wordpress | 2026-08-11 | 9.1 Critical |
| The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection. | ||||
| CVE-2026-15229 | 2 Pinpoint, Wordpress | 2 Pinpoint Booking System, Wordpress | 2026-08-11 | N/A |
| The Pinpoint Booking System WordPress plugin through 2.9.9.6.9 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation. | ||||
| CVE-2026-14211 | 2 Ameliabooking, Wordpress | 2 Booking For Appointments And Events Calendar, Wordpress | 2026-08-11 | N/A |
| The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers. | ||||
| CVE-2026-19075 | 2 Plugins360, Wordpress | 2 All-in-one Video Gallery, Wordpress | 2026-08-11 | N/A |
| All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back to the requester. | ||||
| CVE-2026-19077 | 2 Duplicate Post Project, Wordpress | 2 Duplicate Post, Wordpress | 2026-08-11 | N/A |
| The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Duplicate Post WordPress plugin before 1.5.5 access to permanently delete arbitrary posts on the site, including those belonging to other users. | ||||
| CVE-2026-19089 | 2 Tychesoftwares, Wordpress | 2 Product Input Fields For Woocommerce, Wordpress | 2026-08-11 | N/A |
| The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on servers that do not honour the directory's access rules. | ||||
| CVE-2026-57279 | 1 Cybozu | 1 Cybozu Garoon | 2026-08-11 | N/A |
| Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of a user logged in to the product. | ||||
| CVE-2026-21078 | 1 Samsung | 1 Smart Switch | 2026-08-11 | N/A |
| Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity. | ||||
| CVE-2026-21079 | 1 Samsung | 1 Smart Switch | 2026-08-11 | N/A |
| Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data. | ||||
| CVE-2026-21080 | 1 Samsung | 1 Smart Switch | 2026-08-11 | N/A |
| Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. | ||||
| CVE-2026-21083 | 1 Samsung | 1 Smart Switch | 2026-08-11 | N/A |
| Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data. | ||||
| CVE-2026-21084 | 1 Samsung | 1 Smartthings | 2026-08-11 | N/A |
| Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information. | ||||
| CVE-2026-72577 | 1 Nasa | 1 Fprime | 2026-08-11 | 9.8 Critical |
| Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask application in src/fprime_gds/flask/app.py applies no authentication to any endpoint. | ||||
| CVE-2026-72585 | 1 Grafana | 1 Grafana | 2026-08-11 | 6.5 Medium |
| An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact points (receivers) without the required alert.notifications.receivers.protected:write permission. | ||||