Export limit exceeded: 386988 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (3421 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66583 | 2 Wordpress, Wpmudev | 2 Wordpress, Forminator Forms | 2026-08-21 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. | ||||
| CVE-2026-75987 | 1 Splware | 1 Esproc | 2026-08-21 | 7.3 High |
| A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStream.readUnshared of the file src/main/java/com/scudata/parallel/SocketData.java. Performing a manipulation results in deserialization. Remote exploitation of the attack is possible. | ||||
| CVE-2026-18285 | 1 Aeon | 1 Aeon | 2026-08-21 | N/A |
| Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Aeon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the load_rehab_pile_dataset method. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28749. | ||||
| CVE-2026-77646 | 1 Ptc | 2 Flexplm, Windchill Pdmlink | 2026-08-21 | N/A |
| A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. | ||||
| CVE-2026-60412 | 1 Oracle | 1 Outside In Technology | 2026-08-21 | 7.8 High |
| Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). | ||||
| CVE-2026-60392 | 1 Oracle | 1 Outside In Technology | 2026-08-21 | 7.8 High |
| Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). | ||||
| CVE-2026-77645 | 1 Ptc | 2 Flexplm, Windchill Pdmlink | 2026-08-21 | N/A |
| A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. | ||||
| CVE-2026-77651 | 1 Droundy | 1 Arrayref | 2026-08-21 | 9.8 Critical |
| The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution. | ||||
| CVE-2026-77650 | 1 Droundy | 1 Append-only-vec | 2026-08-21 | 9.8 Critical |
| The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution. | ||||
| CVE-2026-77649 | 1 Droundy | 1 Internment | 2026-08-21 | 9.8 Critical |
| The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution. | ||||
| CVE-2026-49817 | 1 Dell | 2 Command Update, Dell Command Update (dcu) | 2026-08-21 | 7.8 High |
| Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | ||||
| CVE-2026-49816 | 1 Dell | 2 Command Update, Dell Command Update (dcu) | 2026-08-21 | 7.8 High |
| Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | ||||
| CVE-2026-66620 | 2 Derek Herman, Wordpress | 2 Optiontree, Wordpress | 2026-08-21 | 7.2 High |
| Editor PHP Object Injection in OptionTree <= 2.7.3 versions. | ||||
| CVE-2026-73376 | 2 Supsystic, Wordpress | 2 Ultimate Maps By Supsystic, Wordpress | 2026-08-21 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. | ||||
| CVE-2026-73397 | 2 Wordpress, Youzify | 2 Wordpress, Youzify | 2026-08-21 | 9.8 Critical |
| Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. | ||||
| CVE-2026-73364 | 2 Wordpress, Wpdesk | 2 Wordpress, Flexible Subscriptions | 2026-08-21 | 9.8 Critical |
| Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. | ||||
| CVE-2026-73389 | 2 The4, Wordpress | 2 Kalles Addons, Wordpress | 2026-08-21 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. | ||||
| CVE-2026-66672 | 2 Monkeysan, Wordpress | 2 Flatastic, Wordpress | 2026-08-21 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. | ||||
| CVE-2026-74968 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-20 | 5.4 Medium |
| Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | ||||
| CVE-2026-74012 | 2 Steve Burge, Wordpress | 2 Taxopress, Wordpress | 2026-08-20 | 8.8 High |
| Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0. | ||||