Search Results (95433 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-48060 1 Litestar-org 1 Litestar 2026-07-28 8.1 High
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with CSRF protection are vulnerable to HTML Injection which can be escalated to Cross Site Scripting due to the contents of the CSRF cookie being excluded from automatic escaping by the template engine when configured inline with documentation recommendations. This issue has been patched in version 2.20.0.
CVE-2026-64194 1 Nlnet Labs 1 Net Dns 2026-07-28 7.5 High
Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into itself with no depth limit. It is possible to construct a name which saturates the call stack (at least with larger TCP responses), leading to a potential Denial of Service. The guard `$link < $offset` prevents forward and circular chains, but still allows arbitrarily long backward chains. The per-offset cache (`$cache`) is populated at the start of each call and short-circuits only re-traverses of the same offset - the initial descent through a fresh chain still recurses at full depth. A crafted packet can chain two-byte compression pointers so that each one points two bytes earlier than the previous, producing a chain length of `offset / 2`. For the 14-bit pointer field (max offset 16383) this gives up to ~8191 recursive frames. For a TCP DNS message the limit is the 16-bit length field (~32767 frames). Perl's default C stack handles only a few thousand frames; beyond that the process receives SIGSEGV or similar, which is a denial-of-service for any application parsing untrusted DNS data. The vulnerability is triggered by `Net::DNS::Packet->new(\$wire)` i.e. any point where the library decodes a DNS message from the network.
CVE-2026-55973 2 Nlnetlabs, Redhat 2 Unbound, Hummingbird 2026-07-28 7.5 High
In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic '_er.' report query name. That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during 'find_closest_of_type()', it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the first garbage byte to 'dname_query_hash()' as a label length writing over the stack variable 'labuf'. One ordinary upstream response from a delegated zone the attacker controls is sufficient to terminate the daemon.
CVE-2026-13181 1 Progress 1 Telerik Ui For Asp.net Ajax 2026-07-28 8.1 High
In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments.
CVE-2026-13182 1 Progress 1 Telerik Ui For Asp.net Ajax 2026-07-28 7.5 High
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.
CVE-2026-13183 1 Progress 1 Telerik Ui For Asp.net Ajax 2026-07-28 7.5 High
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.
CVE-2026-13184 1 Progress 1 Telerik Ui For Asp.net Ajax 2026-07-28 7.5 High
In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.
CVE-2026-13185 1 Progress 1 Telerik Ui For Asp.net Ajax 2026-07-28 8.1 High
In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.
CVE-2026-13186 1 Progress 1 Telerik Ui For Asp.net Ajax 2026-07-28 8.1 High
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution.
CVE-2026-13187 1 Progress 1 Telerik Ui For Asp.net Ajax 2026-07-28 8.1 High
In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation.
CVE-2026-13189 1 Progress 1 Telerik Ui For Asp.net Ajax 2026-07-28 7.5 High
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests.
CVE-2026-15614 1 Logto-io 1 Logto 2026-07-28 7.5 High
Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window.
CVE-2026-16796 1 Aws 2 Bedrock-agentcore, Bedrock-agentcore 1.18.1 2026-07-28 7.3 High
Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mitigate this issue, users should upgrade to the patched version 1.18.1.
CVE-2026-13152 2 Silverplugins217, Wordpress 2 Custom Fields Account Registration For Woocommerce, Wordpress 2026-07-28 8.1 High
The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator role when a correspondingly named field has been configured.
CVE-2026-59532 2 Magepeople, Wordpress 2 Booking & Rental Manager, Wordpress 2026-07-28 7.5 High
Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
CVE-2026-61953 2 Quantumcloud, Wordpress 2 Simple Link Directory, Wordpress 2026-07-28 7.2 High
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
CVE-2026-61957 2 Miniorange, Wordpress 2 Otp Verification, Wordpress 2026-07-28 7.1 High
Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
CVE-2026-65437 2 Cleantalk, Wordpress 2 Spam Protection, Antispam, Firewall, Wordpress 2026-07-28 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.
CVE-2026-65442 2 Subtlewebinc, Wordpress 2 Formcraft3, Wordpress 2026-07-28 7.2 High
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
CVE-2026-13161 2 Themetechmount, Wordpress 2 Truebooker-appointment-booking, Wordpress 2026-07-28 7.5 High
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The check_ajax_referer() nonce guard does not constitute an authentication or authorization barrier because the nonce is exposed to unauthenticated visitors on TrueBooker front-end booking pages; exploitation additionally requires that the required booking fields (category, service, person, date, and time slot) be present in the alldata POST parameter so that execution reaches the vulnerable SQL query branch.