Total
11010 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-60853 | 1 Oracle | 1 Helidon | 2026-08-28 | N/A | 3.7 LOW |
| Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). | |||||
| CVE-2026-78138 | 2026-08-28 | N/A | 4.3 MEDIUM | ||
| The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sales-campaign's configuration for an arbitrary post ID, allowing any authenticated user (Subscriber and above) to read the Finale Lite WordPress plugin before 2.21.0's campaign configuration and scheduling data. | |||||
| CVE-2026-19715 | 2026-08-28 | N/A | 7.5 HIGH | ||
| The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing unauthenticated users to read the OAuth tokens and authorisation codes it has issued as well as user records including password hashes when debug logging is enabled. | |||||
| CVE-2026-77017 | 2026-08-28 | N/A | 7.7 HIGH | ||
| The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed directory before serving it, allowing users with a role as low as subscriber to read arbitrary files on the server, including its configuration file and authentication secrets. | |||||
| CVE-2026-78125 | 2026-08-28 | N/A | 5.3 MEDIUM | ||
| The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in all versions up to, and including, 4.0.2, allowing unauthenticated attackers to disclose the payment status of arbitrary orders by enumerating order identifiers. | |||||
| CVE-2026-14567 | 2026-08-28 | N/A | 5.3 MEDIUM | ||
| The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address and phone number of every registered user, including administrators. | |||||
| CVE-2026-75099 | 1 Apache | 1 Allura | 2026-08-28 | N/A | 5.3 MEDIUM |
| Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through 1.19.1. Users are recommended to upgrade to version 1.20.0, which fixes the issue. | |||||
| CVE-2026-59499 | 2026-08-28 | N/A | 8.6 HIGH | ||
| : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).. This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions).: All versions without Priwall v3. | |||||
| CVE-2026-59503 | 2026-08-28 | N/A | 9.1 CRITICAL | ||
| : Exposure of Sensitive Information to an Unauthorized Actor : Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3. | |||||
| CVE-2026-21784 | 2026-08-28 | N/A | 4.8 MEDIUM | ||
| HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized external interaction and potential exploitation. | |||||
| CVE-2026-78895 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 4.3 MEDIUM |
| Information leak in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-78908 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 4.3 MEDIUM |
| Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-21758 | 2026-08-28 | N/A | 3.7 LOW | ||
| HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive information about the host environment. | |||||
| CVE-2026-79095 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 4.3 MEDIUM |
| Information leak in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79185 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 4.3 MEDIUM |
| Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79220 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 5.3 MEDIUM |
| Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79246 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 6.5 MEDIUM |
| Information leak in DataTransfer in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-79252 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 4.3 MEDIUM |
| Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-78987 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 4.3 MEDIUM |
| Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-73878 | 1 Oracle | 1 Helidon | 2026-08-28 | N/A | 7.5 HIGH |
| Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). | |||||
