Export limit exceeded: 389438 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 389438 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (389438 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-86483 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 5.4 Medium |
| In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible | ||||
| CVE-2026-86482 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 8.8 High |
| In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation | ||||
| CVE-2026-86481 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons | ||||
| CVE-2026-86480 | 1 Jetbrains | 1 Hub | 2026-09-08 | 9.8 Critical |
| In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges | ||||
| CVE-2026-86479 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 8 High |
| In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR | ||||
| CVE-2026-86478 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 9.8 Critical |
| In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address | ||||
| CVE-2026-86206 | 1 N-able | 1 N-central | 2026-09-08 | N/A |
| A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4 | ||||
| CVE-2026-84820 | 2 Unlimited-elements, Wordpress | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Wordpress | 2026-09-08 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions. | ||||
| CVE-2026-84818 | 2 100plugins, Wordpress | 2 Open User Map, Wordpress | 2026-09-08 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions. | ||||
| CVE-2026-84817 | 2 Crocoblock, Wordpress | 2 Jetformbuilder, Wordpress | 2026-09-08 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions. | ||||
| CVE-2026-83534 | 1 Dalibo | 1 Postgresql Anonymizer | 2026-09-08 | 6.4 Medium |
| PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions | ||||
| CVE-2026-81806 | 2 John Darrel, Wordpress | 2 Hide My Wp Ghost, Wordpress | 2026-09-08 | 7.2 High |
| Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09. | ||||
| CVE-2026-81798 | 2 Easy-appointments, Wordpress | 2 Easy Appointments, Wordpress | 2026-09-08 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4.0.2.1. | ||||
| CVE-2026-76963 | 1 Sap Se | 1 Sap Netweaver And Abap Platform | 2026-09-08 | 4.3 Medium |
| Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful exploitation could result in exposure of security relevant settings and internal system details, resulting in low impact on confidentiality while integrity and availability remain unaffected. | ||||
| CVE-2026-48888 | 2 Automattic, Wordpress | 2 Woocommerce, Wordpress | 2026-09-08 | 7.5 High |
| Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0. | ||||
| CVE-2026-19634 | 1 Dalibo | 1 Postgresql Anonymizer | 2026-09-08 | 6.4 Medium |
| PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() or anon.import_roles_rules(), the malicious code is executed with superuser privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later | ||||
| CVE-2026-19633 | 1 Dalibo | 1 Postgresql Anonymizer | 2026-09-08 | 8.8 High |
| PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with elevated privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later versions | ||||
| CVE-2022-51016 | 1 Pmmp | 1 Pocketmine-mp | 2026-09-08 | 6.1 Medium |
| PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cannot verify that a connecting client possesses the private key corresponding to its login token. An attacker who captures a valid login from another player's session (for example by tricking the player into connecting to an attacker-controlled server) can replay that login to impersonate the victim and pass XBOX Live authentication until the JWT token expires (typically 2-3 days). This affects servers directly reachable over the internet that are not behind a proxy with encryption enabled. Fixed in 4.0.0 and backported to 3.27.0. | ||||
| CVE-2022-51018 | 1 Pmmp | 1 Pocketmine-mp | 2026-09-08 | 6.5 Medium |
| PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author/title length. A player who obtains a writable book can create oversized NBT ('book bombs'), causing excess bandwidth consumption and server crashes (exceeding the 1 MB chunk size limit when saving region-based worlds in PM3, or exceeding the 32 KiB TAG_String limit in PM4). | ||||
| CVE-2026-77995 | 1 Miniorange.com | 1 Miniorange Oauth Client Extension For Joomla | 2026-09-08 | N/A |
| Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) < 1.2.2, Single Sign-On for Educational Institutes < 1.2.2 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins. | ||||