Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
38,402 matching · page 249/769Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-19047(opens NVD record) | Medium | 5.3 | A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/executeCommand of the file src/ludusMCP/cliWrapper.ts of the component ludus_cli_execute. Performing a manipulation of the argument command/args results in command injection. The attack needs to be approached locally. The project was informed of the problem early through an issue report but has not responded yet. | Aug 6, 2026 |
| CVE-2026-19046(opens NVD record) | Low | 3.3 | A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesSearch.ts of the component ludus_environment_guides_search. Such manipulation of the argument guide_name leads to path traversal. Local access is required to approach this attack. The project was informed of the problem early through an issue report but has not responded yet. | Aug 6, 2026 |
| CVE-2026-18427(opens NVD record) | High | 7.5 | @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching and before delegating to the send layer. As a result, an unauthenticated attacker could request a file protected by a route based guard using a non canonical path form that misses the guarded route yet resolves back onto the protected file, disclosing its contents. Applications that protect a subtree of the static root with a route based guard are affected, while applications relying on the allowedPath option are not. This is fixed in @fastify/static 10.1.3, which canonicalizes the pathname, including rejecting backslashes, on the path used for routing and serving. | Aug 6, 2026 |
| CVE-2026-18359(opens NVD record) | High | 8.5 | Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metadata service, via the mets_uri or iiif_uri parameter of POST /api/documents/{pk}/imports/, because the IMPORT_ALLOWED_DOMAINS setting defaults to '*' and no address filtering, redirect cap or timeout is applied | Aug 6, 2026 |
| CVE-2026-18277(opens NVD record) | High | 7.1 | Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via a POST request, because the ownership check is placed in get_context_data() and therefore runs only on the GET rendering path | Aug 6, 2026 |
| CVE-2026-18276(opens NVD record) | Medium | 4.3 | Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls and object_pk values of a join-room message, which are passed to group_add without an access check | Aug 6, 2026 |
| CVE-2026-18275(opens NVD record) | Medium | 6.5 | Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to run segmentation and transcription against other users' document parts, overwriting their content, via part primary keys supplied to a many=True related field whose queryset restriction was applied to the ManyRelatedField instead of its child_relation and therefore had no effect | Aug 6, 2026 |
| CVE-2026-18258(opens NVD record) | High | 8.8 | Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the global model manager instead of the request-scoped queryset | Aug 6, 2026 |
| CVE-2026-70646(opens NVD record) | High | 7.5 | aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON payloads that will ultimately be rejected, leading to unnecessary CPU and memory consumption. Version 3.0.7 fixes the issue. Some workarounds are available. Restrict request body size at the reverse proxy or web framework, rate-limit webhook endpoints, and/or reject oversized requests before JSON parsing. | Aug 6, 2026 |
| CVE-2026-70637(opens NVD record) | Medium | 5.9 | LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by issuing LIST followed by ABOR commands without authentication. The control thread closes data_socket and file_fd descriptors while worker threads concurrently operate on the same fields in worker_thread_cleanup, allowing stale file descriptors to be reassigned by the OS and subsequently used by worker threads on unrelated resources, resulting in potential denial of service. | Aug 6, 2026 |
| CVE-2026-67261(opens NVD record) | Critical | 9.8 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it allows an unauthenticated remote attacker to achieve arbitrary code execution as root, potentially compromising the entire VSI deployment and underlying infrastructure. Dell recommends customers to upgrade at the earliest opportunity. | Aug 6, 2026 |
| CVE-2026-66712(opens NVD record) | High | 7.5 | Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions. | Aug 6, 2026 |
| CVE-2026-66711(opens NVD record) | High | 7.1 | Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions. | Aug 6, 2026 |
| CVE-2026-66710(opens NVD record) | High | 8.1 | Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions. | Aug 6, 2026 |
| CVE-2026-66709(opens NVD record) | Critical | 9.1 | Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions. | Aug 6, 2026 |
| CVE-2026-66708(opens NVD record) | High | 8.2 | Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions. | Aug 6, 2026 |
| CVE-2026-66707(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions. | Aug 6, 2026 |
| CVE-2026-66706(opens NVD record) | Medium | 5.9 | Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions. | Aug 6, 2026 |
| CVE-2026-66705(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions. | Aug 6, 2026 |
| CVE-2026-66703(opens NVD record) | Medium | 6.5 | Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions. | Aug 6, 2026 |
| CVE-2026-66702(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions. | Aug 6, 2026 |
| CVE-2026-66701(opens NVD record) | Medium | 5.3 | Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions. | Aug 6, 2026 |
| CVE-2026-66699(opens NVD record) | Medium | 5.3 | Custom role Broken Access Control in Dokan <= 5.0.10 versions. | Aug 6, 2026 |
| CVE-2026-66696(opens NVD record) | Medium | 4.3 | Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions. | Aug 6, 2026 |
| CVE-2026-66695(opens NVD record) | Medium | 6.5 | Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions. | Aug 6, 2026 |
| CVE-2026-66694(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions. | Aug 6, 2026 |
| CVE-2026-66692(opens NVD record) | Medium | 4.3 | Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions. | Aug 6, 2026 |
| CVE-2026-66690(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions. | Aug 6, 2026 |
| CVE-2026-66688(opens NVD record) | Medium | 6.5 | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions. | Aug 6, 2026 |
| CVE-2026-66686(opens NVD record) | Medium | 6.5 | Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions. | Aug 6, 2026 |
| CVE-2026-66685(opens NVD record) | Medium | 5.3 | Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions. | Aug 6, 2026 |
| CVE-2026-66684(opens NVD record) | Medium | 5.3 | Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions. | Aug 6, 2026 |
| CVE-2026-66683(opens NVD record) | Medium | 5.3 | Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions. | Aug 6, 2026 |
| CVE-2026-66681(opens NVD record) | Medium | 4.3 | Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions. | Aug 6, 2026 |
| CVE-2026-66678(opens NVD record) | Medium | 4.3 | Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions. | Aug 6, 2026 |
| CVE-2026-66665(opens NVD record) | Critical | 10.0 | Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. | Aug 6, 2026 |
| CVE-2026-66664(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions. | Aug 6, 2026 |
| CVE-2026-66663(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. | Aug 6, 2026 |
| CVE-2026-66662(opens NVD record) | Critical | 9.8 | Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions. | Aug 6, 2026 |
| CVE-2026-66470(opens NVD record) | High | 7.1 | Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions. | Aug 6, 2026 |
| CVE-2026-66457(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions. | Aug 6, 2026 |
| CVE-2026-66452(opens NVD record) | Medium | 6.5 | Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions. | Aug 6, 2026 |
| CVE-2026-66451(opens NVD record) | Medium | 6.5 | Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions. | Aug 6, 2026 |
| CVE-2026-66447(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions. | Aug 6, 2026 |
| CVE-2026-66440(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions. | Aug 6, 2026 |
| CVE-2026-66439(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions. | Aug 6, 2026 |
| CVE-2026-66425(opens NVD record) | Medium | 6.5 | Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 versions. | Aug 6, 2026 |
| CVE-2026-65581(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. | Aug 6, 2026 |
| CVE-2026-65579(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions. | Aug 6, 2026 |
| CVE-2026-65578(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in Agora <= 1.9 versions. | Aug 6, 2026 |