Vulnerabilities (CVE)

Total 398504 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-73185 2026-08-20 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
CVE-2026-66680 2026-08-20 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
CVE-2026-66677 2026-08-20 N/A 7.6 HIGH
Subscriber Broken Authentication in Leyka <= 3.32.3 versions.
CVE-2026-66668 2026-08-20 N/A 8.5 HIGH
Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.
CVE-2026-66647 2026-08-20 N/A 6.5 MEDIUM
Subscriber Broken Access Control in Homlisti <= 3.1.2 versions.
CVE-2026-66616 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.
CVE-2026-66613 2026-08-20 N/A 9.8 CRITICAL
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
CVE-2026-66611 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.
CVE-2026-66609 2026-08-20 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
CVE-2026-66604 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.
CVE-2026-66601 2026-08-20 N/A 6.5 MEDIUM
Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
CVE-2026-66595 2026-08-20 N/A 5.9 MEDIUM
Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.
CVE-2026-66594 2026-08-20 N/A 8.5 HIGH
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
CVE-2026-66586 2026-08-20 N/A 6.6 MEDIUM
Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
CVE-2026-66583 2026-08-20 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
CVE-2026-44188 2026-08-20 N/A 5.3 MEDIUM
A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote attacker to maintain persistent access to the Ansible Lightspeed instance. If an attacker exfiltrates a valid OAuth (Open Authorization) access token before a user logs out, they can continue to authenticate and access sensitive data. This is because the application fails to invalidate the token on the backend, leaving it valid until its natural expiration. This can lead to unauthorized read access to Ansible resources such as inventories, playbooks, and configuration data.
CVE-2026-32802 2026-08-20 N/A 5.3 MEDIUM
Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
CVE-2026-20359 2026-08-20 N/A 9.9 CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities trackled by CVE-2026-20359 are related to insufficiently protected credentials issues that are grouped under the Common Weakness Enumeration (CWE) CWE-522.
CVE-2026-20318 2026-08-20 N/A 9.6 CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20318 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20.
CVE-2026-20317 2026-08-20 N/A 10.0 CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20317 are related to improper authentication issues that are grouped under the Common Weakness Enumeration (CWE) CWE-287.