Export limit exceeded: 377226 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (48150 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-47410 | 1 Mervinpraison | 1 Praisonai | 2026-07-27 | 9.8 Critical |
| PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcoded literal `"dev-secret-change-me"` when `PLATFORM_JWT_SECRET` is unset. A safety check exists but only fires when `PLATFORM_ENV != "dev"`; the default value of `PLATFORM_ENV` is `"dev"`, so the check is silently bypassed in any deployment that does not explicitly opt out. The attacker reads the literal from this public source file, mints a JWT with arbitrary `sub` and `email` claims, and authenticates as any existing user (including workspace owners and admins). PraisonAI Platform version 0.1.4 patches the issue. | ||||
| CVE-2026-59559 | 2 Themewant, Wordpress | 2 Rt Mega Menu – Mega Menu Builder For Elementor & Gutenberg, Wordpress | 2026-07-27 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | ||||
| CVE-2026-65561 | 2 Miniorange, Wordpress | 2 Wordpress Social Login And Register, Wordpress | 2026-07-27 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions. | ||||
| CVE-2026-65563 | 2 Themeisle, Wordpress | 2 Orbit Fox By Themeisle, Wordpress | 2026-07-27 | 5.9 Medium |
| Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions. | ||||
| CVE-2026-66434 | 2 Sayontan Sinha, Wordpress | 2 Photonic Gallery & Lightbox For Flickr, Smugmug & Others, Wordpress | 2026-07-27 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions. | ||||
| CVE-2026-66475 | 2 Acowebs, Wordpress | 2 Checkout Field Editor For Woocommerce – Checkout Manager, Wordpress | 2026-07-27 | 5.9 Medium |
| Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versions. | ||||
| CVE-2025-59180 | 1 Ericsson | 1 Packet Core Controller | 2026-07-27 | N/A |
| Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information. | ||||
| CVE-2026-66390 | 1 Apache | 1 Wicket | 2026-07-27 | 6.1 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fixes the issue. | ||||
| CVE-2026-59239 | 1 Roskus | 1 Prospero Flow Crm | 2026-07-27 | N/A |
| Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message. | ||||
| CVE-2026-14827 | 2 Calendar, Wordpress | 2 Calendar, Wordpress | 2026-07-27 | 6.8 Medium |
| The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar. | ||||
| CVE-2026-65562 | 2 Wordpress, Wpdeveloper | 2 Wordpress, Betterdocs | 2026-07-27 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions. | ||||
| CVE-2026-65557 | 2 Tychesoftwares, Wordpress | 2 Abandoned Cart Lite For Woocommerce, Wordpress | 2026-07-27 | 5.9 Medium |
| Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions. | ||||
| CVE-2026-59556 | 2 Acowebs, Wordpress | 2 Dynamic Pricing With Discount Rules For Woocommerce, Wordpress | 2026-07-27 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions. | ||||
| CVE-2026-66445 | 2 100plugins, Wordpress | 2 Open User Map, Wordpress | 2026-07-27 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions. | ||||
| CVE-2026-66448 | 2 Wordpress, Wpchill | 2 Wordpress, Gallery Photoblocks | 2026-07-27 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions. | ||||
| CVE-2026-59553 | 2 Rextheme, Wordpress | 2 Product Feed Manager, Wordpress | 2026-07-27 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions. | ||||
| CVE-2026-66433 | 2 Shapedplugin, Wordpress | 2 Location Weather, Wordpress | 2026-07-27 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions. | ||||
| CVE-2026-57396 | 2 Flintop, Wordpress | 2 Free Gifts For Woocommerce, Wordpress | 2026-07-27 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Flintop Free Gifts for WooCommerce free-gifts-for-woocommerce allows Stored XSS.This issue affects Free Gifts for WooCommerce: from n/a through <= 13.1.0. | ||||
| CVE-2026-12496 | 1 Loytec | 8 L-dali, L-gate, L-inx and 5 more | 2026-07-27 | N/A |
| Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to execute arbitrary JavaScript in an administrator's browser (session hijacking, credential theft, device reconfiguration) via a crafted `User-Agent` header in a `POST /da` request. | ||||
| CVE-2026-65764 | 1 Phoca | 1 Phoca Commander Extension For Joomla | 2026-07-27 | N/A |
| Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability. | ||||