Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

616 CVEs · published 2026-08-13 to 2026-08-13

CVEs (616, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 476–500 of 616 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-27543 HIGH 8.1 2026-08-13 Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.
CVE-2026-27539 HIGH 7.1 2026-08-13 Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions.
CVE-2026-27538 HIGH 7.5 2026-08-13 Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
CVE-2026-27537 MEDIUM 6.5 2026-08-13 Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions.
CVE-2026-27536 HIGH 7.1 2026-08-13 Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions.
CVE-2026-27535 HIGH 7.1 2026-08-13 Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
CVE-2026-27380 HIGH 7.2 2026-08-13 Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
CVE-2026-27345 HIGH 7.5 2026-08-13 Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
CVE-2026-21832 MEDIUM 4.3 2026-08-13 HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentiall&hellip;
CVE-2026-19716 NONE Patched &mdash; 2026-08-13 Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in&hellip;
CVE-2025-62318 LOW 3.7 2026-08-13 HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be c&hellip;
CVE-2025-62315 LOW 3.4 2026-08-13 HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by th&hellip;
CVE-2025-62314 MEDIUM 5.6 2026-08-13 HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate r&hellip;
CVE-2026-73585 MEDIUM 6.3 2026-08-13 A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By &hellip;
CVE-2026-73584 MEDIUM 6.3 2026-08-13 A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `&hellip;
CVE-2026-73583 MEDIUM 6.6 2026-08-13 A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process commu&hellip;
CVE-2026-6471 HIGH Patched 7.2 2026-08-13 Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running&hellip;
CVE-2026-6470 MEDIUM Patched 4.3 2026-08-13 Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the &hellip;
CVE-2026-6469 LOW Patched 3.8 2026-08-13 Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows th&hellip;
CVE-2026-6464 HIGH Patched 8.1 2026-08-13 Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FRO&hellip;
CVE-2026-49827 CRITICAL Patched 9.8 2026-08-13 WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP fil&hellip;
CVE-2026-49478 HIGH 8.7 2026-08-13 Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects&hellip;
CVE-2026-19385 HIGH Patched 8.8 2026-08-13 Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump,&hellip;
CVE-2026-18408 HIGH Patched 8.8 2026-08-13 Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operat&hellip;
CVE-2026-18024 MEDIUM Patched 4.3 2026-08-13 Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the s&hellip;