Vulnerabilities (CVE)

Total 398020 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-77701 2026-08-28 N/A 5.3 MEDIUM
The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create refund requests against any guest checkout order on the site.
CVE-2026-14558 2026-08-28 N/A 7.2 HIGH
The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable POP chain is present on the site.
CVE-2026-59567 2026-08-28 N/A 8.8 HIGH
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.
CVE-2026-59565 2026-08-28 N/A 8.8 HIGH
A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.
CVE-2026-53414 2026-08-28 N/A 6.5 MEDIUM
Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.
CVE-2026-53413 2026-08-28 N/A 8.3 HIGH
Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.
CVE-2026-59568 2026-08-28 N/A 9.1 CRITICAL
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
CVE-2026-53415 2026-08-28 N/A 8.3 HIGH
Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.
CVE-2026-59564 2026-08-28 N/A 9.1 CRITICAL
An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.
CVE-2026-59566 2026-08-28 N/A 8.4 HIGH
A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS.
CVE-2026-53416 2026-08-28 N/A 7.1 HIGH
Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.
CVE-2026-20090 1 Cisco 3 Enterprise Nfv Infrastructure Software, Unified Computing System, Unified Computing System E-series Software 2026-08-28 N/A 4.8 MEDIUM
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.
CVE-2026-74899 1 Jahlives 1 Openssl Encrypt 2026-08-28 N/A 9.8 CRITICAL
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via __class__.__mro__.__subclasses__() to access system functions and execute arbitrary OS commands.
CVE-2026-20089 1 Cisco 3 Enterprise Nfv Infrastructure Software, Unified Computing System, Unified Computing System E-series Software 2026-08-28 N/A 4.8 MEDIUM
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.
CVE-2025-36192 1 Ibm 4 Ds8900f, Ds8900f Firmware, Ds8a00 and 1 more 2026-08-28 N/A 6.7 MEDIUM
IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089.44.5.0 IBM System Storage DS8000 could allow a local user with authorized CCW update permissions to delete or corrupt backups due to missing authorization in IBM Safeguarded Copy / GDPS Logical corruption protection mechanisms.
CVE-2026-72771 1 N8n 1 N8n 2026-08-28 N/A 6.5 MEDIUM
n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against underlying services.
CVE-2026-72766 1 N8n 1 N8n 2026-08-28 N/A 7.5 HIGH
n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforce that its message fields are strings. A crafted non-string value supplied from a workflow expression into the text or HTML body field can be interpreted by the underlying mail library (Nodemailer) as a file path or URL, allowing arbitrary local file disclosure and server-side request forgery (SSRF). Exploitation requires a pre-existing active workflow with an unauthenticated webhook, valid SMTP credentials configured on the node, and untrusted input mapped directly into the body field; this is not a default configuration.
CVE-2026-72750 1 N8n 1 N8n 2026-08-28 N/A 8.8 HIGH
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates expression values directly into the SQL string. When a workflow author embeds untrusted, externally-controlled expression data directly in a raw SQL query, that data is not parameterized, allowing SQL injection. The fix adds an optional 'Query Parameters' field to bind values via positional placeholders.
CVE-2026-20088 1 Cisco 3 Enterprise Nfv Infrastructure Software, Unified Computing System, Unified Computing System E-series Software 2026-08-28 N/A 4.8 MEDIUM
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.
CVE-2026-20087 1 Cisco 3 Enterprise Nfv Infrastructure Software, Unified Computing System, Unified Computing System E-series Software 2026-08-28 N/A 4.8 MEDIUM
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.