Vulnerabilities (CVE)

Total 397901 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-81767 2026-08-28 N/A 7.5 HIGH
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
CVE-2026-81761 2026-08-28 N/A 4.3 MEDIUM
Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.
CVE-2026-81760 2026-08-28 N/A 7.1 HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2.
CVE-2026-81759 2026-08-28 N/A 5.4 MEDIUM
Contributor Broken Access Control in WpEvently <= 5.5.0 versions.
CVE-2026-81757 2026-08-28 N/A 7.2 HIGH
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
CVE-2026-81299 2026-08-28 N/A 4.3 MEDIUM
Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.
CVE-2026-81285 2026-08-28 N/A 7.5 HIGH
Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.
CVE-2026-81284 2026-08-28 N/A 4.3 MEDIUM
Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
CVE-2026-81276 2026-08-28 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.
CVE-2026-80433 2026-08-28 N/A 7.5 HIGH
Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
CVE-2026-79988 2026-08-28 N/A N/A
The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities.
CVE-2026-79256 1 Google 2 Android, Chrome 2026-08-28 N/A 8.3 HIGH
Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-78618 2026-08-28 N/A N/A
A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially crafted request.
CVE-2026-78617 2026-08-28 N/A N/A
WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed attempts, but this setting is not enabled by default.
CVE-2026-78616 2026-08-28 N/A N/A
A Stored Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's Trusted CA certificate configuration allows an authenticated administrator to execute arbitrary JavaScript in another authenticated administrator's web browser by saving a carefully crafted certificate.
CVE-2026-78615 2026-08-28 N/A N/A
A Reflected Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's report detail page allows an attacker to execute arbitrary JavaScript in a authenticated user's browser with a specially crafted URL.
CVE-2026-78614 2026-08-28 N/A N/A
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
CVE-2026-78613 2026-08-28 N/A N/A
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
CVE-2026-78612 2026-08-28 N/A N/A
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
CVE-2026-78610 2026-08-28 N/A N/A
WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can change that administrator's passphrase to an attacker-chosen value without the administrator's consent.