Total
398504 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-76372 | 2026-08-20 | N/A | 6.6 MEDIUM | ||
| In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the scan network action in a Safe Mode playbook while that action is listed as read-only, which could allow for command execution or other changes on a target system through Nmap Scripting Engine scripts. The vulnerability is possible because the Nmap Scanner connector action manifest classifies the scan network action as read-only even though the action accepts script parameters that can perform write operations. For more information see Manage settings for a playbook in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-cloud/build-playbooks/manage-playbooks-and-playbook-settings/manage-settings-for-a-playbook-in-splunk-soar-cloud) in the Splunk documentation. | |||||
| CVE-2026-76371 | 2026-08-20 | N/A | 2.7 LOW | ||
| In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the add listitem action in a Safe Mode playbook while that action is listed as read-only, which could allow for unauthorized changes to file lists. The vulnerability is possible because the FireAMP connector action manifest classifies the add listitem action as read-only even though the action updates file lists. For more information see Manage settings for a playbook in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-cloud/build-playbooks/manage-playbooks-and-playbook-settings/manage-settings-for-a-playbook-in-splunk-soar-cloud) in the Splunk documentation. | |||||
| CVE-2026-74014 | 2026-08-20 | N/A | 9.9 CRITICAL | ||
| Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions. | |||||
| CVE-2026-74001 | 2026-08-20 | N/A | 9.8 CRITICAL | ||
| Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. | |||||
| CVE-2026-73993 | 2026-08-20 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | |||||
| CVE-2026-73992 | 2026-08-20 | N/A | 9.9 CRITICAL | ||
| Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions. | |||||
| CVE-2026-72845 | 2026-08-20 | N/A | N/A | ||
| Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |||||
| CVE-2026-68566 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. | |||||
| CVE-2026-66682 | 2026-08-20 | N/A | 9.8 CRITICAL | ||
| Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. | |||||
| CVE-2026-66673 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions. | |||||
| CVE-2026-66649 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions. | |||||
| CVE-2026-66615 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions. | |||||
| CVE-2026-66605 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions. | |||||
| CVE-2026-66600 | 2026-08-20 | N/A | 9.1 CRITICAL | ||
| Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. | |||||
| CVE-2026-66597 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions. | |||||
| CVE-2026-66593 | 2026-08-20 | N/A | 9.3 CRITICAL | ||
| Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions. | |||||
| CVE-2026-66590 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions. | |||||
| CVE-2026-66582 | 2026-08-20 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions. | |||||
| CVE-2026-54118 | 1 Microsoft | 5 Sql Server 2016, Sql Server 2017, Sql Server 2019 and 2 more | 2026-08-20 | N/A | 9.8 CRITICAL |
| Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-54117 | 1 Microsoft | 5 Sql Server 2016, Sql Server 2017, Sql Server 2019 and 2 more | 2026-08-20 | N/A | 9.8 CRITICAL |
| Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | |||||
