Export limit exceeded: 372705 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372705 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-56290 | 1 Joomlack | 1 Page Builder Ck Extension For Joomla | 2026-07-23 | N/A |
| Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. | ||||
| CVE-2026-16360 | 1 Mozilla | 1 Firefox | 2026-07-23 | 9.8 Critical |
| Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-16412 | 1 Mozilla | 1 Firefox | 2026-07-23 | 9.8 Critical |
| Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. | ||||
| CVE-2026-57829 | 2026-07-23 | N/A | ||
| Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS. | ||||
| CVE-2026-56291 | 1 Balbooa.com | 1 Balbooa.com Balbooa Forms Extension For Joomla | 2026-07-23 | N/A |
| Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. | ||||
| CVE-2026-15646 | 2 Berocket, Wordpress | 2 Brands For Woocommerce, Wordpress | 2026-07-23 | 6.4 Medium |
| The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-25424 | 2 Mediavine, Wordpress | 2 Mediavine Control Panel, Wordpress | 2026-07-23 | 4.3 Medium |
| Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. | ||||
| CVE-2026-57384 | 2 Membershipsoftware, Wordpress | 2 Wishlist Member X, Wordpress | 2026-07-23 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions. | ||||
| CVE-2026-57735 | 2 Soflyy, Wordpress | 2 Breakdance, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions. | ||||
| CVE-2026-57809 | 2 Affiliatewp, Wordpress | 2 Affiliatewp, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions. | ||||
| CVE-2026-61950 | 2 Themetechmount, Wordpress | 2 Truebooker, Wordpress | 2026-07-23 | 9.3 Critical |
| Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. | ||||
| CVE-2026-65449 | 2 Romancode, Wordpress | 2 Mapsvg, Wordpress | 2026-07-23 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions. | ||||
| CVE-2026-65487 | 2 Themegoods, Wordpress | 2 Photography, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in Photography <= 7.7.6 versions. | ||||
| CVE-2026-65519 | 2 Gt3themes, Wordpress | 2 Photo Gallery, Wordpress | 2026-07-23 | 6.5 Medium |
| Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. | ||||
| CVE-2026-15037 | 1 Qt | 1 Qt | 2026-07-23 | N/A |
| Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12. | ||||
| CVE-2026-65512 | 2 Melapress, Wordpress | 2 Wp Activity Log, Wordpress | 2026-07-23 | 5.4 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions. | ||||
| CVE-2026-65460 | 2 Wordpress, Zarinpal | 2 Wordpress, Zarinpal Gateway | 2026-07-23 | 4.3 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions. | ||||
| CVE-2026-65453 | 2 Motovnet, Wordpress | 2 Ebook Store, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. | ||||
| CVE-2026-64625 | 1 Wwbn | 1 Avideo | 2026-07-23 | 9.8 Critical |
| AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live plugin on_publish.php endpoint despite escapeshellarg() protection. | ||||
| CVE-2026-16332 | 1 D-link | 1 Dns-320 | 2026-07-23 | 7.3 High |
| A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used. | ||||