Export limit exceeded: 377300 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (377300 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-28187 | 2 Echoplugins, Wordpress | 2 Knowledge Base For Documentation, Faqs With Ai Assistance, Wordpress | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211.0 versions. | ||||
| CVE-2026-55986 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| Email Management API Bypasses ManageCredentials Feature Restrictions | ||||
| CVE-2026-56750 | 1 Gitea | 1 Gitea Open Source Git Server | 2026-08-13 | N/A |
| Gitea Remember-Me Token Theft Not Invalidating Attacker Session | ||||
| CVE-2026-73643 | 1 Nodeca | 1 Js-yaml | 2026-08-13 | 7.5 High |
| js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2, parsing a small YAML document can take exponential time when an application calls load() or loadAll() on untrusted input. In src/parser/parser.ts, readFlowCollection uses restoreState and calls parseNode a second time when a flow-sequence entry is recognized as a key: value pair. If the key is a nested flow sequence of the same shape, every level is parsed twice, causing O(2^n) work and allowing an input under 200 bytes to keep one CPU busy for minutes, block the Node.js event loop, and stall the process. No anchors, aliases, merges, tags, or nondefault options are required. This issue is fixed in version 5.2.2. | ||||
| CVE-2026-73649 | 1 Shepherdwind | 1 Velocity.js | 2026-08-13 | 9.8 Critical |
| Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in src/compile/references.ts remained unfiltered. The getReferences() flow called getAttributes(), whose property access allowed an attacker-controlled template to traverse constructor.constructor to the JavaScript Function constructor. The #set handler validated only the assignment target and did not inspect the right-hand property-read expression, allowing arbitrary shell commands, environment-variable access, cloud-credential access, and internal-network access in the server process. This issue is fixed in version 2.1.7. | ||||
| CVE-2026-73037 | 1 Dayuanjiang | 1 Next-ai-draw-io | 2026-08-13 | 6.1 Medium |
| Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without escaping into HTML and JavaScript. Attackers can craft malicious URLs to execute arbitrary JavaScript in the localhost origin, enabling exfiltration of diagram sessions and API data. | ||||
| CVE-2026-17045 | 1 Ibm | 1 I | 2026-08-13 | 8.1 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized operations and access sensitive information due to improper session management. | ||||
| CVE-2026-17043 | 1 Ibm | 1 I | 2026-08-13 | 3.8 Low |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files due to path traversal. | ||||
| CVE-2026-16961 | 1 Ibm | 1 I | 2026-08-13 | 7.6 High |
| IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | ||||
| CVE-2026-16908 | 1 Ibm | 1 I | 2026-08-13 | 8.5 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vulnerability. | ||||
| CVE-2026-16898 | 1 Ibm | 1 I | 2026-08-13 | 7.8 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path. | ||||
| CVE-2026-16896 | 1 Ibm | 1 I | 2026-08-13 | 7.1 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a time-of-check time-of-use (TOCTOU) race condition. | ||||
| CVE-2026-16887 | 1 Ibm | 1 I | 2026-08-13 | 7.5 High |
| IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write. | ||||
| CVE-2026-16878 | 1 Ibm | 1 I | 2026-08-13 | 5.4 Medium |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read. | ||||
| CVE-2026-16871 | 1 Ibm | 1 I | 2026-08-13 | 4.3 Medium |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a heap buffer overflow. | ||||
| CVE-2026-16868 | 1 Ibm | 1 I | 2026-08-13 | 8.1 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized memory during ASN.1 length processing. | ||||
| CVE-2026-16867 | 1 Ibm | 1 I | 2026-08-13 | 8.1 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation. | ||||
| CVE-2026-16861 | 1 Ibm | 1 I | 2026-08-13 | 5.3 Medium |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read. | ||||
| CVE-2026-16859 | 1 Ibm | 1 I | 2026-08-13 | 5.3 Medium |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read. | ||||
| CVE-2026-46947 | 1 Oracle | 1 Advanced Outbound Telephony | 2026-08-13 | 8.8 High |
| Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Outbound Telephony. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). | ||||