Export limit exceeded: 376902 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (376902 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-28156 | 2026-08-13 | 8.5 High | ||
| Subscriber SQL Injection in Do Lasso <= 358 versions. | ||||
| CVE-2026-28155 | 2026-08-13 | 6.5 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions. | ||||
| CVE-2026-28149 | 2026-08-13 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions. | ||||
| CVE-2026-28148 | 2026-08-13 | 9.8 Critical | ||
| Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions. | ||||
| CVE-2026-28142 | 2026-08-13 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions. | ||||
| CVE-2026-28008 | 2026-08-13 | 9.8 Critical | ||
| Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions. | ||||
| CVE-2026-28004 | 2026-08-13 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions. | ||||
| CVE-2026-28003 | 2026-08-13 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions. | ||||
| CVE-2026-28001 | 2026-08-13 | 9.3 Critical | ||
| Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. | ||||
| CVE-2026-27999 | 2026-08-13 | 6.5 Medium | ||
| Subscriber Broken Access Control in Tourfic <= 2.23.1 versions. | ||||
| CVE-2026-27544 | 2026-08-13 | 10 Critical | ||
| Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. | ||||
| CVE-2026-27543 | 2026-08-13 | 8.1 High | ||
| Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions. | ||||
| CVE-2026-27539 | 2026-08-13 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions. | ||||
| CVE-2026-27538 | 2026-08-13 | 7.5 High | ||
| Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. | ||||
| CVE-2026-27537 | 2026-08-13 | 6.5 Medium | ||
| Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions. | ||||
| CVE-2026-27345 | 2026-08-13 | 7.5 High | ||
| Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions. | ||||
| CVE-2026-65665 | 1 Microsoft | 2 Sharepoint Server, Sharepoint Server 2019 | 2026-08-13 | 8.8 High |
| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-61366 | 1 Microsoft | 20 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 17 more | 2026-08-13 | 7 High |
| Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-65663 | 1 Microsoft | 3 Sharepoint Server, Sharepoint Server 2016, Sharepoint Server 2019 | 2026-08-13 | 8.8 High |
| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-64916 | 1 Microsoft | 3 Sharepoint Server, Sharepoint Server 2016, Sharepoint Server 2019 | 2026-08-13 | 4.6 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||||