Search Results (83606 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-72828 1 Getgrav 1 Grav 2026-08-14 7.2 High
Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. The strip-super and accept-groups decisions are gated on a bare isSuperAdmin() check rather than a scope-aware permission check, so a least-privilege API key (scoped to api.users.write) minted on a super account can create an invitation record containing super-admin access flags. When the invitation is accepted, those flags are written verbatim to the new account, resulting in privilege escalation to a fully controlled super account.
CVE-2026-57804 2 Codexthemes, Wordpress 2 Thegem Theme Elements (for Elementor), Wordpress 2026-08-14 7.5 High
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows PHP Local File Inclusion. This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.12.1.1.
CVE-2026-19815 1 Totolink 2 A800r, A800r Firmware 2026-08-14 8.8 High
A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Executing a manipulation of the argument urlKeyword can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
CVE-2026-68793 1 Microsoft 12 365, 365 Apps, Excel and 9 more 2026-08-14 7.8 High
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-13622 2 Kubevirt, Redhat 3 Kubevirt, Container Native Virtualization, Openshift Virtualization 2026-08-14 8.8 High
A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replace a migration proxy socket with a symlink to the host CRI-O socket. Because virt-handler runs as root in the host mount namespace, absolute symlink targets resolve against the host filesystem, and the bidirectional io.Copy proxy relays attacker-controlled bytes to the container runtime, enabling full node compromise.
CVE-2026-58416 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 7.1 High
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
CVE-2026-28003 2 Wordpress, Yonifre 2 Wordpress, Maspik – Spam Blacklist 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions.
CVE-2026-28156 2 Lasso Analytics, Inc., Wordpress 2 Do Lasso, Wordpress 2026-08-14 8.5 High
Subscriber SQL Injection in Do Lasso <= 358 versions.
CVE-2026-28157 2 Lasso Analytics, Inc., Wordpress 2 Do Lasso, Wordpress 2026-08-14 7.5 High
Subscriber Path Traversal in Do Lasso <= 358 versions.
CVE-2026-28158 2 Lasso Analytics, Inc., Wordpress 2 Do Lasso, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions.
CVE-2026-28161 2 Aonetheme, Wordpress 2 Service Finder Booking, Wordpress 2026-08-14 8.8 High
Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
CVE-2026-28168 2 Imran Tauqeer, Wordpress 2 Cubewp, Wordpress 2026-08-14 8.5 High
Subscriber SQL Injection in CubeWP <= 1.1.30 versions.
CVE-2026-65580 2 Bracketweb, Wordpress 2 Agrion, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions.
CVE-2026-66431 2 Woompaloompa, Wordpress 2 Bitcoin Lightning Payment Gateway For Woocommerce (via Clink), Wordpress 2026-08-14 7.5 High
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.
CVE-2026-66463 2 Hassan Fakih, Wordpress 2 Icarry, Wordpress 2026-08-14 7.5 High
Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.
CVE-2026-66466 2 Wedevs, Wordpress 2 Storegrowth: Smart Sales Booster For Woocommerce | Bogo, Upsells, Direct Checkout, Quick View, Side Cart, Wordpress 2026-08-14 7.5 High
Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions.
CVE-2026-66468 2 Powerfulwp, Wordpress 2 Local Delivery Drivers For Woocommerce, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions.
CVE-2026-66469 2 Afonso Matos, Wordpress 2 Arvow Ai Seo Writer, Wordpress 2026-08-14 7.5 High
Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.
CVE-2026-66661 2 Onokazu, Wordpress 2 Directories Pro, Wordpress 2026-08-14 7.7 High
Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.
CVE-2026-72849 1 Budibase 2 Budibase, Server 2026-08-14 7.7 High
Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing page that auto-submits a POST request with a leaked confirmation token to bind their chat identity to a victim user's account, enabling impersonation within agent operations and inheritance of victim permissions.