Export limit exceeded: 47707 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (47707 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-12001 | 2026-07-27 | N/A | ||
| A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis. Successful exploitation could result in unauthorized access to privileged functions on affected devices. | ||||
| CVE-2025-59180 | 1 Ericsson | 1 Packet Core Controller | 2026-07-27 | N/A |
| Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information. | ||||
| CVE-2026-59729 | 2026-07-27 | N/A | ||
| Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped spread attribute names in renderHTMLElement. The fix for CVE-2026-54298 (GHSA-jrpj-wcv7-9fh9) added an INVALID_ATTR_NAME_CHAR guard to addAttribute() so that spread-prop attribute names containing "' >/= or whitespace are dropped. A second attribute-rendering path, renderHTMLElement() in packages/astro/src/runtime/server/render/dom.ts, has its own inline attribute loop that does not go through addAttribute() and was not updated. It interpolates the attribute name unescaped and only escapes the value, so untrusted prop keys spread onto a native-HTMLElement-subclass component can still break out of the attribute context. This issue has been fixed in version 7.0.6. | ||||
| CVE-2026-66390 | 1 Apache | 1 Wicket | 2026-07-27 | 6.1 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fixes the issue. | ||||
| CVE-2026-55579 | 2026-07-27 | 9.8 Critical | ||
| Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-512 hash stored at pheditor.php:11). There is no mechanism to force a password change on first login. Any deployment using the default credentials grants an attacker full access to the file editor, file upload, and terminal features, enabling arbitrary file read/write and remote code execution. This issue has been patched in version 2.0.6. | ||||
| CVE-2026-59239 | 1 Roskus | 1 Prospero Flow Crm | 2026-07-27 | N/A |
| Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message. | ||||
| CVE-2026-26483 | 1 Mettle | 1 Sendportal | 2026-07-27 | 6.1 Medium |
| Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The application fails to properly sanitize user-supplied input in the content parameter of the /templates endpoint, allowing an attacker to persistently inject malicious JavaScript code that is executed in the browsers of users who access the affected template. | ||||
| CVE-2026-14827 | 2 Calendar, Wordpress | 2 Calendar, Wordpress | 2026-07-27 | 6.8 Medium |
| The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar. | ||||
| CVE-2026-65562 | 2 Wordpress, Wpdeveloper | 2 Wordpress, Betterdocs | 2026-07-27 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions. | ||||
| CVE-2026-65557 | 2 Tychesoftwares, Wordpress | 2 Abandoned Cart Lite For Woocommerce, Wordpress | 2026-07-27 | 5.9 Medium |
| Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions. | ||||
| CVE-2026-59556 | 2 Acowebs, Wordpress | 2 Dynamic Pricing With Discount Rules For Woocommerce, Wordpress | 2026-07-27 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions. | ||||
| CVE-2026-66445 | 2 100plugins, Wordpress | 2 Open User Map, Wordpress | 2026-07-27 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions. | ||||
| CVE-2026-66448 | 2 Wordpress, Wpchill | 2 Wordpress, Gallery Photoblocks | 2026-07-27 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions. | ||||
| CVE-2026-14203 | 2026-07-27 | 4.8 Medium | ||
| The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid. | ||||
| CVE-2026-14190 | 2026-07-27 | 6.1 Medium | ||
| The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyone who triggers a crafted request. | ||||
| CVE-2026-13726 | 2026-07-27 | 7.1 High | ||
| The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request. | ||||
| CVE-2026-59553 | 2 Rextheme, Wordpress | 2 Product Feed Manager, Wordpress | 2026-07-27 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions. | ||||
| CVE-2026-66433 | 2 Shapedplugin, Wordpress | 2 Location Weather, Wordpress | 2026-07-27 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions. | ||||
| CVE-2026-59558 | 2 Wordpress, Wpdevelop | 2 Wordpress, Booking Calendar | 2026-07-27 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions. | ||||
| CVE-2026-57396 | 2 Flintop, Wordpress | 2 Free Gifts For Woocommerce, Wordpress | 2026-07-27 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Flintop Free Gifts for WooCommerce free-gifts-for-woocommerce allows Stored XSS.This issue affects Free Gifts for WooCommerce: from n/a through <= 13.1.0. | ||||