Search

Search Results (351133 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-39458 1 F5 22 Big-ip, Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager and 19 more 2026-08-24 7.5 High
When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanced WAF DoS protection), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-78282 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
CVE-2026-78268 2026-08-24 7.5 High
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.
CVE-2026-78267 2026-08-24 9.8 Critical
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
CVE-2026-78266 2026-08-24 6.5 Medium
Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
CVE-2026-78265 2026-08-24 9.8 Critical
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
CVE-2026-78264 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
CVE-2026-78263 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
CVE-2026-78262 2026-08-24 9.8 Critical
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
CVE-2026-78259 2026-08-24 7.3 High
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
CVE-2026-32563 2026-08-24 9.8 Critical
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
CVE-2026-32561 2026-08-24 8.8 High
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
CVE-2026-32560 2026-08-24 8.8 High
Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions.
CVE-2026-32559 2026-08-24 9.9 Critical
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
CVE-2026-32556 2026-08-24 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
CVE-2026-32555 2026-08-24 9.3 Critical
Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
CVE-2026-32554 2026-08-24 9.3 Critical
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
CVE-2026-27364 2026-08-24 6.5 Medium
Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.
CVE-2026-78284 2026-08-24 8.6 High
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
CVE-2026-61241 1 Oracle 1 Internet Directory 2026-08-24 10 Critical
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).