Export limit exceeded: 374105 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (374105 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-63822 | 2026-08-06 | 8.1 High | ||
| SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is authorized to access the target user's data. | ||||
| CVE-2025-63823 | 2026-08-06 | 9.8 Critical | ||
| My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values. | ||||
| CVE-2026-14313 | 2026-08-06 | 5.3 Medium | ||
| PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is vulnerable to unauthenticated missing-authorization / IDOR write. Requires WooCommerce. | ||||
| CVE-2026-14314 | 2026-08-06 | 5.3 Medium | ||
| The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated attackers to forge a token and disclose image attachments, including other customers' uploaded payment receipts, that they do not own. | ||||
| CVE-2026-14240 | 2 Tourmaster, Wordpress | 2 Tourmaster, Wordpress | 2026-08-06 | 5.3 Medium |
| The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its publicly accessible directory with no access control, allowing unauthenticated users to download the exported customers' personal information once an administrator has run an export. | ||||
| CVE-2026-16290 | 2 Profilegrid, Wordpress | 2 Profilegrid, Wordpress | 2026-08-06 | 5.3 Medium |
| The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin before 6.0.0.0's member-visibility setting. | ||||
| CVE-2026-18050 | 2026-08-06 | 7.5 High | ||
| The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The identifier is high-entropy, is disclosed only to the uploader, and the file is removed on submission or by a scheduled cleanup, so a cross-user read is not achievable by guessing alone. | ||||
| CVE-2026-13153 | 2026-08-06 | 7.5 High | ||
| The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product. | ||||
| CVE-2026-13154 | 2026-08-06 | 7.5 High | ||
| The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public. | ||||
| CVE-2026-61961 | 2 Wordpress, Wpdeveloper | 2 Wordpress, Embedpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. | ||||
| CVE-2026-66708 | 2 Boldgrid, Wordpress | 2 Total Upkeep, Wordpress | 2026-08-06 | 8.2 High |
| Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions. | ||||
| CVE-2026-66709 | 2 Webappick, Wordpress | 2 Ctx Feed, Wordpress | 2026-08-06 | 9.1 Critical |
| Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions. | ||||
| CVE-2026-66710 | 2 E2pdf, Wordpress | 2 E2pdf, Wordpress | 2026-08-06 | 8.1 High |
| Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions. | ||||
| CVE-2026-28178 | 2 Codesupplyco, Wordpress | 2 Powerkit, Wordpress | 2026-08-06 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions. | ||||
| CVE-2026-32548 | 2 Surecart, Wordpress | 2 Surecart, Wordpress | 2026-08-06 | 5.3 Medium |
| Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions. | ||||
| CVE-2026-7406 | 1 Autodesk | 3 Autocad, Autocad Lt, Revit | 2026-08-06 | 7.8 High |
| A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | ||||
| CVE-2026-7405 | 1 Autodesk | 3 Autocad, Autocad Lt, Revit | 2026-08-06 | 5.5 Medium |
| A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service | ||||
| CVE-2026-61982 | 2 Jp-secure, Wordpress | 2 Siteguard Wp Plugin, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. | ||||
| CVE-2026-65509 | 2 Wordpress, Wpdatatables | 2 Wordpress, Wpdatatables | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. | ||||
| CVE-2026-19023 | 2026-08-06 | N/A | ||
| Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.3.0 allows attackers to cause a denial of service via a variable-length string dataset with more than one element dumped in binary mode, which corrupts the per-element stride calculation and causes subsequent elements to be read from a misaligned offset and dereferenced as a pointer. | ||||