Export limit exceeded: 377349 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (377349 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-59506 1 Priority 1 Portal Generator Addon To Priority Erp (developed By Soft Solutions) 2026-08-14 9.3 Critical
CWE-306: Missing Authentication for Critical Function
CVE-2026-49827 1 Smewebify 1 Weberpmesv2 2026-08-14 9.8 Critical
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registration (no invite required) and broken role middleware (CheckUserRole silently swallows RouteNotFoundException), this chain is effectively unauthenticated RCE against any default installation. The issue is patched in commit 5c54862fa044b363fd2be03d586750e81afd6818.
CVE-2025-52640 1 Hcltech 1 Aion 2026-08-14 4.7 Medium
HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able to access or modify files beyond their intended scope, potentially resulting in unintended behavior or security impact under certain conditions.
CVE-2025-62314 1 Hcltech 1 Aion 2026-08-14 5.6 Medium
HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions.
CVE-2025-62318 1 Hcltech 1 Aion 2026-08-14 3.7 Low
HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions.
CVE-2025-62315 1 Hcltech 1 Aion 2026-08-14 3.4 Low
HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions.
CVE-2026-21832 1 Hcltech 1 Aion 2026-08-14 4.3 Medium
HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions.
CVE-2026-28003 2 Wordpress, Yonifre 2 Wordpress, Maspik – Spam Blacklist 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions.
CVE-2026-28155 2 Lasso Analytics, Inc., Wordpress 2 Do Lasso, Wordpress 2026-08-14 6.5 Medium
Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.
CVE-2026-28156 2 Lasso Analytics, Inc., Wordpress 2 Do Lasso, Wordpress 2026-08-14 8.5 High
Subscriber SQL Injection in Do Lasso <= 358 versions.
CVE-2026-28157 2 Lasso Analytics, Inc., Wordpress 2 Do Lasso, Wordpress 2026-08-14 7.5 High
Subscriber Path Traversal in Do Lasso <= 358 versions.
CVE-2026-28158 2 Lasso Analytics, Inc., Wordpress 2 Do Lasso, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions.
CVE-2026-28159 2 Aonetheme, Wordpress 2 Service Finder Booking, Wordpress 2026-08-14 6.5 Medium
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
CVE-2026-28161 2 Aonetheme, Wordpress 2 Service Finder Booking, Wordpress 2026-08-14 8.8 High
Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
CVE-2026-28168 2 Imran Tauqeer, Wordpress 2 Cubewp, Wordpress 2026-08-14 8.5 High
Subscriber SQL Injection in CubeWP <= 1.1.30 versions.
CVE-2026-28185 2 Rtcamp, Wordpress 2 Log In With Google, Wordpress 2026-08-14 9.8 Critical
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
CVE-2026-28186 2 Themefic, Wordpress 2 Travelfic Toolkit, Wordpress 2026-08-14 8.1 High
Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions.
CVE-2026-61978 2 Webhosting4ugr, Wordpress 2 Secure Card Gateway For Epay Paycenter (piraeus Bank), Wordpress 2026-08-14 6.5 Medium
Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.
CVE-2026-65580 2 Bracketweb, Wordpress 2 Agrion, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions.
CVE-2026-66431 2 Woompaloompa, Wordpress 2 Bitcoin Lightning Payment Gateway For Woocommerce (via Clink), Wordpress 2026-08-14 7.5 High
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.