Export limit exceeded: 377388 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (377388 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-49827 | 1 Smewebify | 1 Weberpmesv2 | 2026-08-14 | 9.8 Critical |
| WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registration (no invite required) and broken role middleware (CheckUserRole silently swallows RouteNotFoundException), this chain is effectively unauthenticated RCE against any default installation. The issue is patched in commit 5c54862fa044b363fd2be03d586750e81afd6818. | ||||
| CVE-2025-52640 | 1 Hcltech | 1 Aion | 2026-08-14 | 4.7 Medium |
| HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able to access or modify files beyond their intended scope, potentially resulting in unintended behavior or security impact under certain conditions. | ||||
| CVE-2025-62314 | 1 Hcltech | 1 Aion | 2026-08-14 | 5.6 Medium |
| HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions. | ||||
| CVE-2025-62318 | 1 Hcltech | 1 Aion | 2026-08-14 | 3.7 Low |
| HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions. | ||||
| CVE-2025-62315 | 1 Hcltech | 1 Aion | 2026-08-14 | 3.4 Low |
| HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions. | ||||
| CVE-2026-21832 | 1 Hcltech | 1 Aion | 2026-08-14 | 4.3 Medium |
| HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions. | ||||
| CVE-2026-28003 | 2 Wordpress, Yonifre | 2 Wordpress, Maspik – Spam Blacklist | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions. | ||||
| CVE-2026-28155 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 6.5 Medium |
| Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions. | ||||
| CVE-2026-28156 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in Do Lasso <= 358 versions. | ||||
| CVE-2026-28157 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 7.5 High |
| Subscriber Path Traversal in Do Lasso <= 358 versions. | ||||
| CVE-2026-28158 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions. | ||||
| CVE-2026-28159 | 2 Aonetheme, Wordpress | 2 Service Finder Booking, Wordpress | 2026-08-14 | 6.5 Medium |
| Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions. | ||||
| CVE-2026-28161 | 2 Aonetheme, Wordpress | 2 Service Finder Booking, Wordpress | 2026-08-14 | 8.8 High |
| Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions. | ||||
| CVE-2026-28168 | 2 Imran Tauqeer, Wordpress | 2 Cubewp, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in CubeWP <= 1.1.30 versions. | ||||
| CVE-2026-28185 | 2 Rtcamp, Wordpress | 2 Log In With Google, Wordpress | 2026-08-14 | 9.8 Critical |
| Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions. | ||||
| CVE-2026-28186 | 2 Themefic, Wordpress | 2 Travelfic Toolkit, Wordpress | 2026-08-14 | 8.1 High |
| Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions. | ||||
| CVE-2026-61978 | 2 Webhosting4ugr, Wordpress | 2 Secure Card Gateway For Epay Paycenter (piraeus Bank), Wordpress | 2026-08-14 | 6.5 Medium |
| Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions. | ||||
| CVE-2026-65580 | 2 Bracketweb, Wordpress | 2 Agrion, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions. | ||||
| CVE-2026-66431 | 2 Woompaloompa, Wordpress | 2 Bitcoin Lightning Payment Gateway For Woocommerce (via Clink), Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. | ||||
| CVE-2026-66446 | 2 If-so Dynamic Content, Wordpress | 2 If-so Dynamic Content Personalization, Wordpress | 2026-08-14 | 9.3 Critical |
| Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. | ||||