Export limit exceeded: 380203 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (380203 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-75911 | 1 Hmbown | 1 Codewhale | 2026-08-18 | 7.8 High |
| CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml file to a repository. When a user clones and opens the repository in CodeWhale, the AI model gains access to exec_shell and task_shell tools, enabling execution of arbitrary shell commands on the victim's machine without explicit user consent. | ||||
| CVE-2026-75897 | 2 Aws, Opensearch | 2 Amazon Opensearch Service, Opensearch Dashboards | 2026-08-18 | 7.5 High |
| Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request. | ||||
| CVE-2026-75874 | 1 Mozilla | 1 Firefox | 2026-08-18 | 10 Critical |
| Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154. | ||||
| CVE-2026-74990 | 1 Mozilla | 1 Firefox | 2026-08-18 | 9.8 Critical |
| Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | ||||
| CVE-2026-74972 | 1 Mozilla | 1 Firefox | 2026-08-18 | 4.3 Medium |
| Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | ||||
| CVE-2026-74971 | 1 Mozilla | 1 Firefox | 2026-08-18 | 4.3 Medium |
| Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | ||||
| CVE-2026-74967 | 1 Mozilla | 1 Firefox | 2026-08-18 | 5.4 Medium |
| Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | ||||
| CVE-2026-74951 | 1 Mozilla | 1 Firefox | 2026-08-18 | 6.5 Medium |
| Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154. | ||||
| CVE-2026-74938 | 1 Mozilla | 1 Firefox | 2026-08-18 | 9.1 Critical |
| Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | ||||
| CVE-2026-74937 | 1 Mozilla | 1 Firefox | 2026-08-18 | 8.8 High |
| Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | ||||
| CVE-2026-74046 | 2026-08-18 | 4.9 Medium | ||
| Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.py that allows authenticated cluster peers to exhaust memory by supplying a malicious synchronization archive without decompressed size limits. Attackers holding a valid cluster Fernet key can upload a small, highly compressed zip bomb archive that forces wazuh-clusterd on the master node to decompress the full payload into memory, causing memory exhaustion and service disruption. | ||||
| CVE-2026-74015 | 2026-08-18 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Readabler < 2.0.18 versions. | ||||
| CVE-2026-74009 | 2 Razorpay, Wordpress | 2 Razorpay For Woocommerce, Wordpress | 2026-08-18 | 5.3 Medium |
| Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions. | ||||
| CVE-2026-74006 | 2026-08-18 | 4.3 Medium | ||
| Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions. | ||||
| CVE-2026-74003 | 2 Rometheme, Wordpress | 2 Romethemeform For Elementor, Wordpress | 2026-08-18 | 4.3 Medium |
| Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions. | ||||
| CVE-2026-73995 | 2 Wordpress, Wpeverest | 2 Wordpress, User Registration | 2026-08-18 | 5.4 Medium |
| Subscriber Broken Authentication in User Registration <= 5.2.6 versions. | ||||
| CVE-2026-73404 | 2026-08-18 | 6.5 Medium | ||
| Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. | ||||
| CVE-2026-73398 | 2 Papaki, Wordpress | 2 Piraeus Bank Woocommerce Payment Gateway, Wordpress | 2026-08-18 | 6.5 Medium |
| Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. | ||||
| CVE-2026-73396 | 2026-08-18 | 7.1 High | ||
| Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. | ||||
| CVE-2026-73392 | 2026-08-18 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions. | ||||