Export limit exceeded: 10404 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10404 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-63684 | 1 Regularlabs.com | 3 Content Templater Extension For Joomla, Rereplacer Extension For Joomla, Snippets Extension For Joomla | 2026-07-23 | N/A |
| Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend users or CSRF attacks could expose, create or modify extension configuration and items. | ||||
| CVE-2026-64791 | 1 Regularlabs.com | 1 Regular Labs Extension Manager Extension For Joomla | 2026-07-23 | N/A |
| Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could install, update or remove extensions. | ||||
| CVE-2026-63280 | 1 Regularlabs.com | 4 Advanced Module Manager Extension For Joomla, Conditional Content Extension For Joomla, Content Templater Pro Extension For Joomla and 1 more | 2026-07-23 | N/A |
| Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens and component/mapped-item permissions. | ||||
| CVE-2026-61217 | 1 Oracle | 1 Security Service | 2026-07-23 | 6.4 Medium |
| Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Security Service. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Security Service accessible data as well as unauthorized access to critical data or complete access to all Oracle Security Service accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N). | ||||
| CVE-2026-63265 | 1 Regularlabs.com | 23 Advanced Module Manager Extension For Joomla, Articles Anywhere Extension For Joomla, Articles Field Extension For Joomla and 20 more | 2026-07-23 | N/A |
| Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted server-generated form configuration. Authenticated lower-privileged users or CSRF attacks could invoke lookups or mutations outside their authorization. | ||||
| CVE-2026-64876 | 1 Regularlabs.com | 1 Geoip Extension For Joomla | 2026-07-23 | N/A |
| Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates. | ||||
| CVE-2026-65757 | 1 Regularlabs.com | 1 Modules Anywhere Extension For Joomla | 2026-07-23 | N/A |
| Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens. | ||||
| CVE-2026-64871 | 1 Regularlabs.com | 1 Cache Cleaner Extension For Joomla | 2026-07-23 | N/A |
| Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid token and cache-management permission. | ||||
| CVE-2026-57785 | 2 Apustheme, Wordpress | 2 Apuslisting, Wordpress | 2026-07-23 | 8.8 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions. | ||||
| CVE-2026-65464 | 2 Nexcess, Wordpress | 2 Givewp, Wordpress | 2026-07-23 | 5.4 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions. | ||||
| CVE-2026-65471 | 2 Avada Studio, Wordpress | 2 Avada Core, Wordpress | 2026-07-23 | 9.6 Critical |
| Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions. | ||||
| CVE-2026-65536 | 2 Mahdi Yousefi, Wordpress | 2 افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری), Wordpress | 2026-07-23 | 6.5 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions. | ||||
| CVE-2026-65539 | 2 Bimal Rekhadiya, Wordpress | 2 Kwayy Html Sitemap, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions. | ||||
| CVE-2026-65540 | 2 Metin Saraç, Wordpress | 2 Popup For Cf7 With Sweet Alert, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions. | ||||
| CVE-2026-62563 | 1 Oracle | 1 Work In Process | 2026-07-23 | 5.4 Medium |
| Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Work in Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Work in Process accessible data as well as unauthorized read access to a subset of Oracle Work in Process accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N). | ||||
| CVE-2026-61097 | 1 Oracle | 1 Banking Trade Finance Process Management | 2026-07-23 | 9.6 Critical |
| Vulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applications (component: Common). Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Trade Finance Process Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Trade Finance Process Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance Process Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Trade Finance Process Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Trade Finance Process Management. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L). | ||||
| CVE-2026-61082 | 1 Oracle | 3 Mysql Connector/j, Mysql Connector\/j, Mysql Connectors | 2026-07-23 | 6.5 Medium |
| Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). | ||||
| CVE-2026-13946 | 1 Google | 1 Chrome | 2026-07-23 | 4.3 Medium |
| Inappropriate implementation in ScriptInjections in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-61981 | 2026-07-23 | 5.4 Medium | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions. | ||||
| CVE-2026-57626 | 2 Mailpoet, Wordpress | 2 Mailpoet, Wordpress | 2026-07-23 | 7.1 High |
| Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0. | ||||