Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
39,118 matching · page 330/783Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-59556(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions. | Jul 27, 2026 |
| CVE-2026-59553(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions. | Jul 27, 2026 |
| CVE-2026-59552(opens NVD record) | High | 7.2 | Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | Jul 27, 2026 |
| CVE-2026-59551(opens NVD record) | High | 8.5 | Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | Jul 27, 2026 |
| CVE-2026-59550(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions. | Jul 27, 2026 |
| CVE-2026-59549(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | Jul 27, 2026 |
| CVE-2026-59548(opens NVD record) | High | 7.5 | Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions. | Jul 27, 2026 |
| CVE-2026-59546(opens NVD record) | High | 7.4 | Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions. | Jul 27, 2026 |
| CVE-2026-59539(opens NVD record) | High | 7.5 | Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions. | Jul 27, 2026 |
| CVE-2026-59538(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions. | Jul 27, 2026 |
| CVE-2026-59537(opens NVD record) | High | 7.6 | Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions. | Jul 27, 2026 |
| CVE-2026-59536(opens NVD record) | High | 7.5 | Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions. | Jul 27, 2026 |
| CVE-2026-59535(opens NVD record) | High | 7.3 | Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions. | Jul 27, 2026 |
| CVE-2026-59534(opens NVD record) | High | 7.5 | Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions. | Jul 27, 2026 |
| CVE-2026-59533(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions. | Jul 27, 2026 |
| CVE-2026-59532(opens NVD record) | High | 7.5 | Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions. | Jul 27, 2026 |
| CVE-2026-59531(opens NVD record) | High | 7.5 | Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions. | Jul 27, 2026 |
| CVE-2026-59530(opens NVD record) | High | 7.5 | Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions. | Jul 27, 2026 |
| CVE-2026-59529(opens NVD record) | High | 7.5 | Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions. | Jul 27, 2026 |
| CVE-2026-59528(opens NVD record) | High | 7.5 | Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions. | Jul 27, 2026 |
| CVE-2026-59527(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | Jul 27, 2026 |
| CVE-2026-10819(opens NVD record) | Medium | 6.5 | Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost Advisory ID: MMSA-2026-00695 | Jul 27, 2026 |
| CVE-2026-10600(opens NVD record) | Medium | 4.3 | Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on the server via repeatedly uploading small documents that are cheap to upload but expensive to extract, saturating the shared extraction worker pool.. Mattermost Advisory ID: MMSA-2026-00694 | Jul 27, 2026 |
| CVE-2025-59181(opens NVD record) | Unscored | — | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users. | Jul 27, 2026 |
| CVE-2025-59180(opens NVD record) | Unscored | — | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information. | Jul 27, 2026 |
| CVE-2025-59178(opens NVD record) | Unscored | — | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system. | Jul 27, 2026 |
| CVE-2025-59177(opens NVD record) | Unscored | — | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret through error messages. | Jul 27, 2026 |
| CVE-2025-59172(opens NVD record) | Unscored | — | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root. | Jul 27, 2026 |
| CVE-2026-65879(opens NVD record) | Critical | 9.8 | Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms. | Jul 27, 2026 |
| CVE-2026-65878(opens NVD record) | Unscored | — | Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager. | Jul 27, 2026 |
| CVE-2026-65877(opens NVD record) | Unscored | — | Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector. | Jul 27, 2026 |
| CVE-2026-65876(opens NVD record) | Unscored | — | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector. | Jul 27, 2026 |
| CVE-2026-65766(opens NVD record) | Unscored | — | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector. | Jul 27, 2026 |
| CVE-2026-61511(opens NVD record) | Critical | 9.8 | vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication. | Jul 27, 2026 |
| CVE-2026-17514(opens NVD record) | Medium | 5.3 | A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract.js. This manipulation causes path traversal. The attack requires local access. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. | Jul 27, 2026 |
| CVE-2026-17513(opens NVD record) | Low | 3.3 | A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function ggml_ftype_to_ggml_type of the file ggml/src/ggml.c. The manipulation of the argument ftype results in reachable assertion. The attack requires a local approach. The project was informed of the problem early through an issue report but has not responded yet. | Jul 27, 2026 |
| CVE-2026-15003(opens NVD record) | Medium | 5.6 | A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing. | Jul 27, 2026 |
| CVE-2026-59690(opens NVD record) | High | 8.0 | A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise. | Jul 27, 2026 |
| CVE-2026-59689(opens NVD record) | High | 8.0 | An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise. | Jul 27, 2026 |
| CVE-2026-59688(opens NVD record) | High | 8.4 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise. | Jul 27, 2026 |
| CVE-2026-59687(opens NVD record) | High | 8.4 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise. | Jul 27, 2026 |
| CVE-2026-59686(opens NVD record) | High | 8.4 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise. | Jul 27, 2026 |
| CVE-2026-56538(opens NVD record) | Low | 3.5 | An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users. | Jul 27, 2026 |
| CVE-2026-56537(opens NVD record) | Low | 3.5 | HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by improper handling of request data. | Jul 27, 2026 |
| CVE-2026-17512(opens NVD record) | Low | 3.3 | A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the file src/whisper.cpp. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The pull request to fix this issue awaits acceptance. | Jul 27, 2026 |
| CVE-2026-12991(opens NVD record) | Unscored | — | The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and manipulate packets between the legitimate operator and the robot. This allows the attacker to disconnect the original controller, establish unauthorized communications, and prevent the operator from regaining control of the device, seriously compromising the confidentiality, integrity, and availability (CIA) of operations. | Jul 27, 2026 |
| CVE-2026-12990(opens NVD record) | Unscored | — | An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session. This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational security. | Jul 27, 2026 |
| CVE-2026-12989(opens NVD record) | Unscored | — | A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization mechanisms, the attacker can view real-time camera feeds, control the robot’s movements, manage sensors (GPS, RTK, SAM, LIDAR), and execute critical operational commands (Play, Pause, Stop, E-Stop). Successful exploitation completely compromises the confidentiality, integrity, and physical security of the system. | Jul 27, 2026 |
| CVE-2026-66053(opens NVD record) | Medium | 5.9 | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603 | Jul 27, 2026 |
| CVE-2026-58662(opens NVD record) | Critical | 9.1 | Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. | Jul 27, 2026 |