Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
33,325 matching · page 9/667Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-68566(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. | Aug 20, 2026 |
| CVE-2026-68564(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions. | Aug 20, 2026 |
| CVE-2026-66682(opens NVD record) | Critical | 9.8 | Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. | Aug 20, 2026 |
| CVE-2026-66680(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions. | Aug 20, 2026 |
| CVE-2026-66677(opens NVD record) | High | 7.6 | Subscriber Broken Authentication in Leyka <= 3.32.3 versions. | Aug 20, 2026 |
| CVE-2026-66673(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions. | Aug 20, 2026 |
| CVE-2026-66672(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. | Aug 20, 2026 |
| CVE-2026-66649(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions. | Aug 20, 2026 |
| CVE-2026-66647(opens NVD record) | Medium | 6.5 | Subscriber Broken Access Control in Homlisti <= 3.1.2 versions. | Aug 20, 2026 |
| CVE-2026-66616(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions. | Aug 20, 2026 |
| CVE-2026-66615(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions. | Aug 20, 2026 |
| CVE-2026-66614(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions. | Aug 20, 2026 |
| CVE-2026-66612(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions. | Aug 20, 2026 |
| CVE-2026-66611(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions. | Aug 20, 2026 |
| CVE-2026-66609(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. | Aug 20, 2026 |
| CVE-2026-66607(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions. | Aug 20, 2026 |
| CVE-2026-66606(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions. | Aug 20, 2026 |
| CVE-2026-66605(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions. | Aug 20, 2026 |
| CVE-2026-66604(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions. | Aug 20, 2026 |
| CVE-2026-66601(opens NVD record) | Medium | 6.5 | Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions. | Aug 20, 2026 |
| CVE-2026-66600(opens NVD record) | Critical | 9.1 | Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. | Aug 20, 2026 |
| CVE-2026-66598(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions. | Aug 20, 2026 |
| CVE-2026-66597(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions. | Aug 20, 2026 |
| CVE-2026-66595(opens NVD record) | Medium | 5.9 | Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions. | Aug 20, 2026 |
| CVE-2026-66594(opens NVD record) | High | 8.5 | Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. | Aug 20, 2026 |
| CVE-2026-66593(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions. | Aug 20, 2026 |
| CVE-2026-66592(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. | Aug 20, 2026 |
| CVE-2026-66590(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions. | Aug 20, 2026 |
| CVE-2026-66586(opens NVD record) | Medium | 6.6 | Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions. | Aug 20, 2026 |
| CVE-2026-66583(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. | Aug 20, 2026 |
| CVE-2026-66582(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions. | Aug 20, 2026 |
| CVE-2026-66581(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. | Aug 20, 2026 |
| CVE-2026-28150(opens NVD record) | High | 8.1 | Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions. | Aug 20, 2026 |
| CVE-2025-62307(opens NVD record) | Medium | 5.4 | HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing. | Aug 20, 2026 |
| CVE-2025-53999(opens NVD record) | Medium | 6.5 | Unauthenticated Broken Access Control in Altair <= 5.2.2 versions. | Aug 20, 2026 |
| CVE-2025-15689(opens NVD record) | Critical | 9.8 | Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. | Aug 20, 2026 |
| CVE-2025-15688(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in Capella <= 2.5.5 versions. | Aug 20, 2026 |
| CVE-2025-15637(opens NVD record) | High | 8.1 | Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. | Aug 20, 2026 |
| CVE-2026-77067(opens NVD record) | Medium | 5.0 | The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file imports no validation helper. When a subscribed event fires, callWebhook in packages/api/src/jobs/call_webhook.ts issues axios.request with that url, the method and Content-Type recorded on the webhook, and a JSON body carrying the event data, so an authenticated user can make the server send repeated attacker-shaped requests to internal endpoints, including link-local metadata addresses. The request is blind: callWebhook discards the result and writes only a success line or the axios error to the server log, so the response is not returned through the API. | Aug 20, 2026 |
| CVE-2026-77066(opens NVD record) | Medium | 5.0 | The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. The same file guards the subscribe path with validateUrl(), which rejects private and reserved ranges through the private-ip library, and createPageSaveRequest applies the same check, so the omission is specific to this resolver. An authenticated user can direct the server to request arbitrary internal endpoints. The response is parsed as a feed or as HTML and the resolver returns the resulting url, title, description and type fields, so disclosure is limited to feed-shaped metadata and to link elements advertising RSS or Atom feeds; requests that do not parse still distinguish reachable ports from unreachable ones through the resulting error. | Aug 20, 2026 |
| CVE-2026-77026(opens NVD record) | Unscored | — | Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions. | Aug 20, 2026 |
| CVE-2026-73199(opens NVD record) | Medium | 6.5 | A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending a malformed Lightweight Directory Access Protocol (LDAP) extended operation. By omitting the request value for the `JOIN_OID` in the `ipa-enrollment` extended operation, an attacker can trigger a server crash, potentially causing a denial of service. | Aug 20, 2026 |
| CVE-2026-73198(opens NVD record) | High | 7.5 | A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsiveness, and a denial of service (DoS) condition. | Aug 20, 2026 |
| CVE-2026-73197(opens NVD record) | High | 7.5 | A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service. | Aug 20, 2026 |
| CVE-2026-73196(opens NVD record) | Medium | 4.3 | A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming excessive CPU and memory resources. This can lead to a denial of service, degrading the availability of the IPA service. | Aug 20, 2026 |
| CVE-2026-13097(opens NVD record) | Critical | 9.1 | A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise. | Aug 20, 2026 |
| CVE-2026-11861(opens NVD record) | Critical | 9.6 | A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain. | Aug 20, 2026 |
| CVE-2026-18917(opens NVD record) | High | 7.8 | A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation. | Aug 20, 2026 |
| CVE-2026-77014(opens NVD record) | Medium | 5.3 | A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB. | Aug 20, 2026 |
| CVE-2026-76610(opens NVD record) | Unscored | — | Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by unauthenticated users. | Aug 20, 2026 |