Export limit exceeded: 379111 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (379111 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-32470 | 2026-08-18 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | ||||
| CVE-2026-32467 | 2026-08-18 | 6 Medium | ||
| Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. | ||||
| CVE-2026-32464 | 2026-08-18 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. | ||||
| CVE-2026-32444 | 2026-08-18 | 9.9 Critical | ||
| Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. | ||||
| CVE-2026-32333 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions. | ||||
| CVE-2026-28570 | 2026-08-18 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions. | ||||
| CVE-2026-28568 | 2026-08-18 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. | ||||
| CVE-2026-28567 | 2026-08-18 | 7.5 High | ||
| Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions. | ||||
| CVE-2026-60112 | 2 Nasa, Nasa-ammos | 2 Ait Gui, Ait-gui | 2026-08-18 | 9.8 Critical |
| AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward arbitrary commands directly to the AIT command bus without any authentication gate between session creation and command dispatch. | ||||
| CVE-2026-74961 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. | ||||
| CVE-2026-74978 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. | ||||
| CVE-2026-74979 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. | ||||
| CVE-2026-74981 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. | ||||
| CVE-2026-74954 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. | ||||
| CVE-2026-60113 | 2 Nasa, Nasa-ammos | 2 Ait Dsn, Ait-dsn | 2026-08-18 | 9.8 Critical |
| AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials. Attackers can reach the exposed SLE endpoints to start or stop Deep Space Network communication sessions, retrieve telemetry frame data, and inject arbitrary frames into active spacecraft links. | ||||
| CVE-2026-18751 | 1 Citrix | 1 Workspace App | 2026-08-18 | N/A |
| External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607. | ||||
| CVE-2026-75852 | 1 Arcadedata | 1 Arcadedb | 2026-08-18 | 9.8 Critical |
| ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials. | ||||
| CVE-2026-74934 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. | ||||
| CVE-2026-74944 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. | ||||
| CVE-2026-74948 | 1 Mozilla | 1 Firefox | 2026-08-18 | N/A |
| Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. | ||||