Search

Search Results (379216 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-47683 1 Patriksimek 1 Vm2 2026-08-18 N/A
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js does not cover Buffer.concat(list, totalLength) or Buffer.from(arrayLike) with an attacker-controlled length, allowing sandbox code to perform large synchronous host external-memory allocations that bypass the configured cap and can exhaust the host process. This issue is fixed in version 3.11.6.
CVE-2026-45791 1 Dokploy 1 Dokploy 2026-08-18 5.9 Medium
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's user.update procedure in apps/dokploy/server/api/routers/user.ts updates account.password without deleting other rows from session, allowing a compromised better-auth.session_token session to remain valid for up to three days after a password change. This issue is fixed in version 0.29.6.
CVE-2026-45790 1 Dokploy 1 Dokploy 2026-08-18 8 High
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC procedure in apps/dokploy/server/api/routers/organization.ts allows a user with member:create permission to invite an account with the owner role, while packages/server/src/services/user.ts allows a privileged self-hosted user to create an account with an arbitrary role, enabling permanent organization takeover because owner roles cannot be demoted. This issue is fixed in version 0.29.6.
CVE-2026-45532 1 Dataease 1 Dataease 2026-08-18 N/A
DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on Windows, the `FILE_SEPARATOR` is `\`, while the server only filters the `/` character during string truncation. The vulnerability has been fixed in v2.10.23. No known workarounds are available.
CVE-2026-39254 1 Steelseries 1 Gg 2026-08-18 9.8 Critical
Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, CxAudioHidDevice::DeviceGetDescriptionString components
CVE-2026-34398 1 Freecad 1 Freecad 2026-08-18 7.8 High
FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mod/BIM/bimcommands/BimProjectManager.py in the BIM Project Manager Load Template flow passes attacker-controlled FCStd Meta property values for wpposition, wpu, wpv, and wpaxis directly to eval(), allowing arbitrary Python code execution when a user loads a malicious BIM project template. This issue is fixed in version 1.1.1.
CVE-2026-32553 2 Brainstorm Force, Wordpress 2 Ottokit, Wordpress 2026-08-18 7.2 High
Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.
CVE-2026-32473 2026-08-18 7.2 High
Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions.
CVE-2026-32466 2026-08-18 8.5 High
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
CVE-2026-23922 1 Zabbix 1 Zabbix 2026-08-18 N/A
The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.
CVE-2026-16309 2026-08-18 5.3 Medium
Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects EdoWEB: before 780-g7.
CVE-2026-15748 2 Wordpress, Wpmudev 2 Wordpress, Forminator Forms – Contact Form, Payment Form & Custom Form Builder 2026-08-18 9.8 Critical
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.
CVE-2026-11817 2026-08-18 N/A
This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call GET /api/access-control/users/permissions/search?actionPrefix=dashboards: and receive permission data belonging to other organizations. The disclosed data is limited to dashboard and folder identifiers (UIDs) and per-user permission/scope mappings (which user holds which access on which dashboard). Dashboard contents, panels, query results, datasource credentials, secrets, and personal data are not exposed. This is a limited cross-organization information disclosure affecting multi-org deployments only.
CVE-2026-13072 1 Mongodb 2 Mongodb, Mongodb Server 2026-08-18 8.1 High
When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or other unintended behavior. This configuration is non-default and requires explicit enablement at startup.
CVE-2026-13073 1 Mongodb 2 Mongodb, Mongodb Server 2026-08-18 4.3 Medium
An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of service for all connected clients until the process is restarted. The issue stems from an internal engine selection inconsistency triggered by a specific combination of aggregation options.
CVE-2026-13074 1 Mongodb 2 Mongodb, Mongodb Server 2026-08-18 5.3 Medium
An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode. The server's handling of this combination results in a response loop that bypasses normal throttling, allowing a small number of connections to degrade server availability.
CVE-2026-73380 2026-08-18 9.8 Critical
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
CVE-2026-68565 2 Paolo, Wordpress 2 Geodirectory, Wordpress 2026-08-18 6.5 Medium
Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.
CVE-2026-73187 2 Gingerplugins, Wordpress 2 Sticky Chat Widget, Wordpress 2026-08-18 9.3 Critical
Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
CVE-2026-73189 2 Themeum, Wordpress 2 Wp Crowdfunding, Wordpress 2026-08-18 6.5 Medium
Subscriber Insecure Direct Object References (IDOR) in WP Crowdfunding < 2.2.1 versions.