Search

Search Results (374095 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-39024 2026-08-06 N/A
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
CVE-2026-12584 2026-08-06 7.5 High
The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own orders without paying.
CVE-2026-12501 2026-08-06 5.3 Medium
The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, nor that the paid amount matches the order total, before marking a booking as paid, allowing unauthenticated attackers to mark bookings as fully paid using a token payment made to an attacker-controlled account.
CVE-2026-10524 2026-08-06 7.5 High
The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are added to the cart through one of its public REST API endpoints, allowing unauthenticated users to set arbitrary product prices and complete WooCommerce orders at manipulated totals.
CVE-2025-6508 1 Wso2 2 Api Manager, Wso2 Api Manager 2026-08-06 4.3 Medium
The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to be loaded, overriding the existing API definitions within the Publisher portal. By exploiting this vulnerability, malicious actors can deceive users into interacting with these overwritten API definitions. This could lead to the exposure of sensitive information or the initiation of unintended requests to backend services.
CVE-2026-62873 1 Microsoft 1 365 Admin Center 2026-08-06 9.8 Critical
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-63508 1 Microsoft 1 Planetary Computer Pro 2026-08-06 10 Critical
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-50515 1 Microsoft 1 Azure Service Bus 2026-08-06 9.9 Critical
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
CVE-2026-56162 1 Microsoft 1 Azure Sql Database 2026-08-06 10 Critical
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-65667 1 Microsoft 1 Teams 2026-08-06 10 Critical
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62830 1 Microsoft 1 Azure Sre Agent 2026-08-06 9.9 Critical
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
CVE-2026-56161 1 Microsoft 1 Azure Logic Apps 2026-08-06 9.6 Critical
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
CVE-2026-70332 1 Microsoft 1 Sharepoint Online 2026-08-06 9.6 Critical
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-68823 1 Microsoft 1 Azure Confidential Ledger 2026-08-06 9.1 Critical
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
CVE-2026-49163 1 Microsoft 1 Application Insights Profiler 2026-08-06 8.8 High
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.
CVE-2026-59115 1 Microsoft 1 Entra Provisioning Service 2026-08-06 9.9 Critical
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
CVE-2026-62918 1 Microsoft 1 Teams 2026-08-06 7.5 High
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-50481 1 Microsoft 1 Azure Active Directory 2026-08-06 9.9 Critical
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
CVE-2026-59118 1 Microsoft 1 Power-apps 2026-08-06 9.3 Critical
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-65668 1 Microsoft 1 Office Purview Ediscovery 2026-08-06 8.8 High
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.