Search Results (9933 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-66909 1 Apache 1 Cxf 2026-08-07 9.8 Critical
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
CVE-2026-65556 2 Mihche, Wordpress 2 Wpbruiser {no- Captcha Anti-spam}, Wordpress 2026-08-07 9.8 Critical
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
CVE-2026-65571 2 Axiomthemes, Wordpress 2 69 Clothing, Wordpress 2026-08-07 9.8 Critical
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
CVE-2026-65572 2 Axiomthemes, Wordpress 2 A.williams, Wordpress 2026-08-07 9.8 Critical
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
CVE-2026-28139 2 Wordpress, Wp-dreams 2 Wordpress, Ajax Search 2026-08-07 9.8 Critical
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
CVE-2026-16258 2026-08-07 9.8 Critical
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.
CVE-2026-65575 2026-08-06 9.8 Critical
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
CVE-2026-65581 2026-08-06 9.8 Critical
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
CVE-2026-71316 1 Nuxt 1 Nuxt 2026-08-06 7.5 High
Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /<page>/_payload.json can be returned before route middleware and page guards because import.meta.prerender is not enforced, disclosing another user's SSR data. This issue is fixed in 4.5.1.
CVE-2026-65579 2 Axiomthemes, Wordpress 2 Agricola, Wordpress 2026-08-06 9.8 Critical
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
CVE-2026-21655 3 Johnson Control, Johnson Controls, Johnsoncontrols 4 Victor, Ccure 9000, Victor Application Server and 1 more 2026-08-06 N/A
Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1.
CVE-2026-19008 1 Mf-yang 1 Openclaw-cn 2026-08-06 6.3 Medium
A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandbox-paths.ts of the component apply_patch Tool. Such manipulation leads to link following. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-65573 2 Themerex, Wordpress 2 Abelle, Wordpress 2026-08-06 9.8 Critical
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
CVE-2026-65577 2026-08-06 9.8 Critical
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
CVE-2026-65552 2 Qlstudio, Wordpress 2 Export User Data, Wordpress 2026-08-06 9.8 Critical
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
CVE-2026-65549 2026-08-06 7.2 High
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
CVE-2026-65576 2026-08-06 9.8 Critical
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
CVE-2026-65574 2026-08-06 9.8 Critical
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
CVE-2026-65578 2026-08-06 9.8 Critical
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
CVE-2026-17349 1 Pgadmin 1 Pgadmin 4 2026-08-05 9.6 Critical
/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, shared, shared_username, and the stored credential fields password, save_password, and tunnel_password. When a non-owner triggered an adhoc connect against another user's (in practice, typically an administrator's) shared server, the clone inherited that user's ownership, shared flag, and stored database credentials verbatim. pgAdmin persisted this cross-tenant, credential-bearing server row before the connection was even attempted, so it survived even when the connection subsequently failed. The non-owner could then open the newly-owned clone and pgAdmin would connect using the source user's stored database password on the non-owner's behalf, granting the non-owner use of database credentials -- and whatever database privileges they confer -- that were never their own. Fix forces the cloned adhoc record's ownership fields (user_id, shared, shared_username) and stored credential fields (password, save_password, tunnel_password) to belong to the calling user and be cleared/private before committing, regardless of the source server's ownership, sharing state, or stored credentials. A regression test asserts that an adhoc connect triggered by a non-owner against another user's shared server persists a row owned by the caller, not shared, and without the source's stored credentials. This issue affects pgAdmin 4: from 9.0 before 9.17.