Search

Search Results (372740 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-16412 1 Mozilla 1 Firefox 2026-07-23 9.8 Critical
Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
CVE-2026-57829 2026-07-23 N/A
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.
CVE-2026-56291 1 Balbooa.com 1 Balbooa.com Balbooa Forms Extension For Joomla 2026-07-23 N/A
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
CVE-2026-15646 2 Berocket, Wordpress 2 Brands For Woocommerce, Wordpress 2026-07-23 6.4 Medium
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-25424 2 Mediavine, Wordpress 2 Mediavine Control Panel, Wordpress 2026-07-23 4.3 Medium
Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.
CVE-2026-57384 2 Membershipsoftware, Wordpress 2 Wishlist Member X, Wordpress 2026-07-23 6.5 Medium
Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.
CVE-2026-57735 2 Soflyy, Wordpress 2 Breakdance, Wordpress 2026-07-23 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.
CVE-2026-57809 2 Affiliatewp, Wordpress 2 Affiliatewp, Wordpress 2026-07-23 7.1 High
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.
CVE-2026-61950 2 Themetechmount, Wordpress 2 Truebooker, Wordpress 2026-07-23 9.3 Critical
Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
CVE-2026-65449 2 Romancode, Wordpress 2 Mapsvg, Wordpress 2026-07-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.
CVE-2026-65487 2 Themegoods, Wordpress 2 Photography, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
CVE-2026-65519 2 Gt3themes, Wordpress 2 Photo Gallery, Wordpress 2026-07-23 6.5 Medium
Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.
CVE-2026-15037 1 Qt 1 Qt 2026-07-23 N/A
Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.
CVE-2026-65512 2 Melapress, Wordpress 2 Wp Activity Log, Wordpress 2026-07-23 5.4 Medium
Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions.
CVE-2026-65460 2 Wordpress, Zarinpal 2 Wordpress, Zarinpal Gateway 2026-07-23 4.3 Medium
Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.
CVE-2026-65453 2 Motovnet, Wordpress 2 Ebook Store, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
CVE-2026-64625 1 Wwbn 1 Avideo 2026-07-23 9.8 Critical
AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live plugin on_publish.php endpoint despite escapeshellarg() protection.
CVE-2026-16332 1 D-link 1 Dns-320 2026-07-23 7.3 High
A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.
CVE-2026-15811 1 Redhat 2 Enterprise Linux, Openshift 2026-07-23 5.8 Medium
A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability.
CVE-2026-15145 2 Wordpress, Wpdevteam 2 Wordpress, Essential Addons For Elementor – Popular Elementor Templates & Widgets 2026-07-23 6.4 Medium
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.