Export limit exceeded: 378785 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 378785 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (378785 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73482 | 1 Phplist | 1 Phplist | 2026-08-14 | 8.1 High |
| phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that is not protected by a CSRF token (the central verifyCsrfGetToken check uses enforce=false and is bypassed when the token parameter is absent). A remote attacker can trick a logged-in super-administrator into loading a crafted URL (e.g., embedded as an image in an email) to delete any non-self administrator account. | ||||
| CVE-2026-19813 | 1 Totolink | 2 A800r, A800r Firmware | 2026-08-14 | 8.8 High |
| A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. | ||||
| CVE-2026-59499 | 1 Priority | 1 Portal Generator Addon To Priority Erp (developed By Soft Solutions). | 2026-08-14 | 8.6 High |
| CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | ||||
| CVE-2026-59505 | 1 Priority | 1 Portal Generator Addon To Priority Erp (developed By Soft Solutions) | 2026-08-14 | 8.6 High |
| CWE-284: Improper Access Control | ||||
| CVE-2026-59506 | 1 Priority | 1 Portal Generator Addon To Priority Erp (developed By Soft Solutions) | 2026-08-14 | 9.3 Critical |
| CWE-306: Missing Authentication for Critical Function | ||||
| CVE-2026-49827 | 1 Smewebify | 1 Weberpmesv2 | 2026-08-14 | 9.8 Critical |
| WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registration (no invite required) and broken role middleware (CheckUserRole silently swallows RouteNotFoundException), this chain is effectively unauthenticated RCE against any default installation. The issue is patched in commit 5c54862fa044b363fd2be03d586750e81afd6818. | ||||
| CVE-2025-52640 | 1 Hcltech | 1 Aion | 2026-08-14 | 4.7 Medium |
| HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able to access or modify files beyond their intended scope, potentially resulting in unintended behavior or security impact under certain conditions. | ||||
| CVE-2025-62314 | 1 Hcltech | 1 Aion | 2026-08-14 | 5.6 Medium |
| HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions. | ||||
| CVE-2025-62318 | 1 Hcltech | 1 Aion | 2026-08-14 | 3.7 Low |
| HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions. | ||||
| CVE-2025-62315 | 1 Hcltech | 1 Aion | 2026-08-14 | 3.4 Low |
| HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions. | ||||
| CVE-2026-21832 | 1 Hcltech | 1 Aion | 2026-08-14 | 4.3 Medium |
| HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions. | ||||
| CVE-2026-28003 | 2 Wordpress, Yonifre | 2 Wordpress, Maspik – Spam Blacklist | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions. | ||||
| CVE-2026-28155 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 6.5 Medium |
| Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions. | ||||
| CVE-2026-28156 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in Do Lasso <= 358 versions. | ||||
| CVE-2026-28157 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 7.5 High |
| Subscriber Path Traversal in Do Lasso <= 358 versions. | ||||
| CVE-2026-28158 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions. | ||||
| CVE-2026-28159 | 2 Aonetheme, Wordpress | 2 Service Finder Booking, Wordpress | 2026-08-14 | 6.5 Medium |
| Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions. | ||||
| CVE-2026-28161 | 2 Aonetheme, Wordpress | 2 Service Finder Booking, Wordpress | 2026-08-14 | 8.8 High |
| Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions. | ||||
| CVE-2026-28168 | 2 Imran Tauqeer, Wordpress | 2 Cubewp, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in CubeWP <= 1.1.30 versions. | ||||
| CVE-2026-28185 | 2 Rtcamp, Wordpress | 2 Log In With Google, Wordpress | 2026-08-14 | 9.8 Critical |
| Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions. | ||||