Total
397901 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-81767 | 2026-08-28 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions. | |||||
| CVE-2026-81761 | 2026-08-28 | N/A | 4.3 MEDIUM | ||
| Subscriber Broken Access Control in WpEvently <= 5.5.0 versions. | |||||
| CVE-2026-81760 | 2026-08-28 | N/A | 7.1 HIGH | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2. | |||||
| CVE-2026-81759 | 2026-08-28 | N/A | 5.4 MEDIUM | ||
| Contributor Broken Access Control in WpEvently <= 5.5.0 versions. | |||||
| CVE-2026-81757 | 2026-08-28 | N/A | 7.2 HIGH | ||
| Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions. | |||||
| CVE-2026-81299 | 2026-08-28 | N/A | 4.3 MEDIUM | ||
| Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions. | |||||
| CVE-2026-81285 | 2026-08-28 | N/A | 7.5 HIGH | ||
| Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions. | |||||
| CVE-2026-81284 | 2026-08-28 | N/A | 4.3 MEDIUM | ||
| Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions. | |||||
| CVE-2026-81276 | 2026-08-28 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions. | |||||
| CVE-2026-80433 | 2026-08-28 | N/A | 7.5 HIGH | ||
| Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions. | |||||
| CVE-2026-79988 | 2026-08-28 | N/A | N/A | ||
| The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities. | |||||
| CVE-2026-79256 | 1 Google | 2 Android, Chrome | 2026-08-28 | N/A | 8.3 HIGH |
| Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-78618 | 2026-08-28 | N/A | N/A | ||
| A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially crafted request. | |||||
| CVE-2026-78617 | 2026-08-28 | N/A | N/A | ||
| WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed attempts, but this setting is not enabled by default. | |||||
| CVE-2026-78616 | 2026-08-28 | N/A | N/A | ||
| A Stored Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's Trusted CA certificate configuration allows an authenticated administrator to execute arbitrary JavaScript in another authenticated administrator's web browser by saving a carefully crafted certificate. | |||||
| CVE-2026-78615 | 2026-08-28 | N/A | N/A | ||
| A Reflected Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's report detail page allows an attacker to execute arbitrary JavaScript in a authenticated user's browser with a specially crafted URL. | |||||
| CVE-2026-78614 | 2026-08-28 | N/A | N/A | ||
| WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests. | |||||
| CVE-2026-78613 | 2026-08-28 | N/A | N/A | ||
| WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests. | |||||
| CVE-2026-78612 | 2026-08-28 | N/A | N/A | ||
| WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests. | |||||
| CVE-2026-78610 | 2026-08-28 | N/A | N/A | ||
| WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can change that administrator's passphrase to an attacker-chosen value without the administrator's consent. | |||||
