Search
Search Results (377270 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-62318 | 1 Hcltech | 1 Aion | 2026-08-14 | 3.7 Low |
| HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions. | ||||
| CVE-2025-62315 | 1 Hcltech | 1 Aion | 2026-08-14 | 3.4 Low |
| HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions. | ||||
| CVE-2026-21832 | 1 Hcltech | 1 Aion | 2026-08-14 | 4.3 Medium |
| HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions. | ||||
| CVE-2026-28003 | 2 Wordpress, Yonifre | 2 Wordpress, Maspik – Spam Blacklist | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions. | ||||
| CVE-2026-28155 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 6.5 Medium |
| Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions. | ||||
| CVE-2026-28156 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in Do Lasso <= 358 versions. | ||||
| CVE-2026-28157 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 7.5 High |
| Subscriber Path Traversal in Do Lasso <= 358 versions. | ||||
| CVE-2026-28158 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions. | ||||
| CVE-2026-28159 | 2 Aonetheme, Wordpress | 2 Service Finder Booking, Wordpress | 2026-08-14 | 6.5 Medium |
| Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions. | ||||
| CVE-2026-28161 | 2 Aonetheme, Wordpress | 2 Service Finder Booking, Wordpress | 2026-08-14 | 8.8 High |
| Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions. | ||||
| CVE-2026-28168 | 2 Imran Tauqeer, Wordpress | 2 Cubewp, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in CubeWP <= 1.1.30 versions. | ||||
| CVE-2026-28185 | 2 Rtcamp, Wordpress | 2 Log In With Google, Wordpress | 2026-08-14 | 9.8 Critical |
| Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions. | ||||
| CVE-2026-28186 | 2 Themefic, Wordpress | 2 Travelfic Toolkit, Wordpress | 2026-08-14 | 8.1 High |
| Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions. | ||||
| CVE-2026-61978 | 2 Webhosting4ugr, Wordpress | 2 Secure Card Gateway For Epay Paycenter (piraeus Bank), Wordpress | 2026-08-14 | 6.5 Medium |
| Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions. | ||||
| CVE-2026-65580 | 2 Bracketweb, Wordpress | 2 Agrion, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions. | ||||
| CVE-2026-66431 | 2 Woompaloompa, Wordpress | 2 Bitcoin Lightning Payment Gateway For Woocommerce (via Clink), Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. | ||||
| CVE-2026-66446 | 2 If-so Dynamic Content, Wordpress | 2 If-so Dynamic Content Personalization, Wordpress | 2026-08-14 | 9.3 Critical |
| Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. | ||||
| CVE-2026-66454 | 2 Maruti Mohanty, Wordpress | 2 Wp Social Avatar, Wordpress | 2026-08-14 | 6.5 Medium |
| Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions. | ||||
| CVE-2026-66455 | 2 Rockiger, Wordpress | 2 Reactpress, Wordpress | 2026-08-14 | 6 Medium |
| Subscriber Broken Access Control in ReactPress <= 3.4.0 versions. | ||||
| CVE-2026-66459 | 2 Space Codes, Wordpress | 2 Ai For Seo, Wordpress | 2026-08-14 | 6.5 Medium |
| Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions. | ||||