Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
33,917 matching · page 61/679Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-66635(opens NVD record) | High | 7.4 | Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions. | Aug 18, 2026 |
| CVE-2026-66634(opens NVD record) | Medium | 4.3 | Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions. | Aug 18, 2026 |
| CVE-2026-66633(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. | Aug 18, 2026 |
| CVE-2026-66629(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions. | Aug 18, 2026 |
| CVE-2026-66627(opens NVD record) | Critical | 9.9 | Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions. | Aug 18, 2026 |
| CVE-2026-66622(opens NVD record) | High | 7.5 | Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions. | Aug 18, 2026 |
| CVE-2026-66621(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions. | Aug 18, 2026 |
| CVE-2026-66620(opens NVD record) | High | 7.2 | Editor PHP Object Injection in OptionTree <= 2.7.3 versions. | Aug 18, 2026 |
| CVE-2026-66046(opens NVD record) | High | 7.5 | Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options. | Aug 18, 2026 |
| CVE-2026-63639(opens NVD record) | High | 8.8 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1. | Aug 18, 2026 |
| CVE-2026-63632(opens NVD record) | Low | 3.3 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer than two dimensions because B_shape[1], A_shape[0], or A_shape[1] is accessed without a rank check, potentially causing a process crash during an opset 7 to 6 downgrade. This issue is fixed in version 1.22.0. | Aug 18, 2026 |
| CVE-2026-61407(opens NVD record) | High | 8.8 | Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation. | Aug 18, 2026 |
| CVE-2026-59949(opens NVD record) | Medium | 6.5 | yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1. | Aug 18, 2026 |
| CVE-2026-59940(opens NVD record) | Critical | 9.8 | Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side effects with plugins enabled and potentially unintended server-side invocation or remote code execution when downstream frameworks register callable wrappers. This issue is fixed in version 1.5.3. | Aug 18, 2026 |
| CVE-2026-59825(opens NVD record) | High | 7.4 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=true, disabling SSL and TLS certificate verification globally for requests made by puma web processes while sidekiq background jobs remain unaffected. This issue is fixed in versions 4.4.19 and 4.5.12. | Aug 18, 2026 |
| CVE-2026-56684(opens NVD record) | High | 7.5 | Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger CLIENT KILL, causing connTLSClose to delete the iterator's cached next node and producing a use-after-free that can crash the server or potentially allow remote code execution when TLS is enabled. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1. | Aug 18, 2026 |
| CVE-2026-50187(opens NVD record) | High | 8.8 | Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a directory change into a folder containing a .env file, allowing syntactically valid shell commands in the file to execute with the current account's privileges, including without a prompt when ZSH_DOTENV_PROMPT=false or after the default prompt accepts an empty Enter response. This issue is fixed in versions released after 2026-05-28. | Aug 18, 2026 |
| CVE-2026-50139(opens NVD record) | Medium | 5.9 | goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent requests all read the same `Downloaded`/`DownloadLimit` snapshot, all pass the check, and all are served — exceeding the operator's intended cap. Version 2.1.0 patches the issue. | Aug 18, 2026 |
| CVE-2026-50138(opens NVD record) | High | 8.1 | goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP port. The WebDAV port is wired straight to `golang.org/x/net/webdav.Handler` with no equivalent guard, so an authenticated WebDAV client can `PUT`, `DELETE`, `MKCOL`, `MOVE`, and `COPY` despite the operator's stated intent. Version 2.1.0 patches the issue. | Aug 18, 2026 |
| CVE-2026-48798(opens NVD record) | High | 7.1 | SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the requested local directory without containment validation, allowing a malicious, compromised, or man-in-the-middle server to use ../ sequences or absolute paths to create or overwrite files anywhere writable by the client process. This issue is fixed in version 2026.0.0. | Aug 18, 2026 |
| CVE-2026-45733(opens NVD record) | High | 8.3 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quick_search.ts and apps/client/src/services/note_autocomplete.ts, allowing a stored payload to execute automatically when a victim opens a new tab or uses Ctrl+J and, because Electron enables nodeIntegration and disables contextIsolation, run operating-system commands as the victim. This issue is fixed in version 0.103.0. | Aug 18, 2026 |
| CVE-2026-32553(opens NVD record) | High | 7.2 | Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions. | Aug 18, 2026 |
| CVE-2026-32549(opens NVD record) | High | 7.5 | Unauthenticated Broken Access Control in ThumbPress < 6.5 versions. | Aug 18, 2026 |
| CVE-2026-32547(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. | Aug 18, 2026 |
| CVE-2026-32481(opens NVD record) | High | 7.5 | Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions. | Aug 18, 2026 |
| CVE-2026-32474(opens NVD record) | Critical | 9.9 | Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. | Aug 18, 2026 |
| CVE-2026-32473(opens NVD record) | High | 7.2 | Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions. | Aug 18, 2026 |
| CVE-2026-32472(opens NVD record) | High | 7.5 | Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions. | Aug 18, 2026 |
| CVE-2026-32470(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | Aug 18, 2026 |
| CVE-2026-18534(opens NVD record) | High | 7.4 | ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk. | Aug 18, 2026 |
| CVE-2026-73692(opens NVD record) | Unscored | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 18, 2026 |
| CVE-2026-50575(opens NVD record) | High | 7.7 | BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Version 3.0.0-alpha contains a patch. No known workarounds are available. | Aug 18, 2026 |
| CVE-2026-32468(opens NVD record) | High | 7.5 | Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. | Aug 18, 2026 |
| CVE-2026-32467(opens NVD record) | Medium | 6.0 | Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. | Aug 18, 2026 |
| CVE-2026-32466(opens NVD record) | High | 8.5 | Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. | Aug 18, 2026 |
| CVE-2026-32465(opens NVD record) | High | 8.8 | Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions. | Aug 18, 2026 |
| CVE-2026-32464(opens NVD record) | High | 8.1 | Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. | Aug 18, 2026 |
| CVE-2026-32463(opens NVD record) | Critical | 9.9 | Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. | Aug 18, 2026 |
| CVE-2026-32444(opens NVD record) | Critical | 9.9 | Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. | Aug 18, 2026 |
| CVE-2026-32333(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions. | Aug 18, 2026 |
| CVE-2026-28571(opens NVD record) | High | 7.5 | Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions. | Aug 18, 2026 |
| CVE-2026-28570(opens NVD record) | High | 8.1 | Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions. | Aug 18, 2026 |
| CVE-2026-28569(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions. | Aug 18, 2026 |
| CVE-2026-28568(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions. | Aug 18, 2026 |
| CVE-2026-28567(opens NVD record) | High | 7.5 | Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions. | Aug 18, 2026 |
| CVE-2026-28192(opens NVD record) | Critical | 9.6 | Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions. | Aug 18, 2026 |
| CVE-2026-28191(opens NVD record) | High | 8.8 | Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions. | Aug 18, 2026 |
| CVE-2026-24301(opens NVD record) | High | 8.8 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. | Aug 18, 2026 |
| CVE-2026-17084(opens NVD record) | Unscored | — | The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0. | Aug 18, 2026 |
| CVE-2026-75874(opens NVD record) | Critical | 10.0 | Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154. | Aug 18, 2026 |