Total 381323 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-73993 2 Roxnor, Wordpress 2 Fundengine, Wordpress 2026-08-20 9.8 Critical
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
CVE-2026-73992 2 Jonathan Daggerhart, Wordpress 2 Query Wrangler, Wordpress 2026-08-20 9.9 Critical
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
CVE-2026-72847 2026-08-20 4.6 Medium
broot renders each file and directory name in its interactive tree view exactly as read from the filesystem. Names are converted with a plain to_string_lossy() call in src/tree_build/builder.rs and in TreeLine::unprune in src/tree/tree_line.rs, and no control-character filtering exists anywhere in the code, even though the doc comment on the TreeLine name field states that some characters may have been stripped. Any local user who can create a file can therefore place an escape sequence in its name and have it written unmodified to the terminal of anyone who browses that directory, between broot's own styling codes. A reported proof of concept used an OSC 52 clipboard-write sequence and captured the raw bytes broot wrote to its pty, confirming the sequence reaches the terminal unstripped. What an injected OSC or CSI sequence can then do depends on the terminal emulator in use. Browsing a directory is broot's primary function and carries no expectation that the content is trusted.
CVE-2026-72844 2026-08-20 6.3 Medium
The Lean 4 kernel does not verify that the structure named in a projection expression matches the type of the value being projected, and environment::add_inductive in src/kernel/inductive.cpp did not type check the nested inductive applications that are replaced by auxiliary types, so their parametric arguments escaped checking. A metaprogram running in the Lean process can register an ill-typed nested inductive whose constructor applies a .proj C 0 projection to a value of the unrelated type W, and the kernel admits the declaration through the ordinary checked addDecl path at maximum kernel checking, without sorry, unsafeCast, debug.skipKernelTC, addDeclWithoutChecking, FFI, or a modified .olean file. The result is a type confusion yielding a proof of False that carries no axioms, from which any proposition can be derived. The published proof of concept additionally pads two expressions until their hashes and approximate depths collide, which defeats kernel caching; that is the technique used to reach the flaw, not its cause. Exploitation requires running a metaprogram in-process, for example by building a project or importing a malicious Lake dependency.
CVE-2026-68566 2 Repute Infosystems, Wordpress 2 Bookingpress Appointment Booking Pro, Wordpress 2026-08-20 9.3 Critical
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
CVE-2026-66682 2 Tychesoftwares, Wordpress 2 Abandoned Cart Pro For Woocommerce, Wordpress 2026-08-20 9.8 Critical
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
CVE-2026-66673 2026-08-20 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.
CVE-2026-66649 2 E-plugins, Wordpress 2 Directory Pro, Wordpress 2026-08-20 9.3 Critical
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
CVE-2026-66615 2 Eric Teubert, Wordpress 2 Podlove Podcast Publisher, Wordpress 2026-08-20 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.
CVE-2026-66605 2026-08-20 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions.
CVE-2026-66600 2 Davidlingren, Wordpress 2 Media Library Assistant, Wordpress 2026-08-20 9.1 Critical
Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
CVE-2026-66597 2 Melograno Venture Studio, Wordpress 2 Wpdatatables, Wordpress 2026-08-20 7.1 High
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.
CVE-2026-66593 2026-08-20 9.3 Critical
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
CVE-2026-66590 2026-08-20 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.
CVE-2026-66582 2 Cozmoslabs, Wordpress 2 Translatepress, Wordpress 2026-08-20 7.1 High
Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.
CVE-2026-63044 2026-08-20 N/A
Server-Side Request Forgery (SSRF) vulnerability in Apache InLong.  Any authenticated user (no admin role required) can cause the InLong Manager server to make outbound HTTP requests or TCP connections to arbitrary internal hosts and ports. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/12130 .
CVE-2026-62594 1 Oracle 1 Siebel Crm Integration 2026-08-20 7.7 High
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Integration. CVSS 3.1 Base Score 7.7 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H).
CVE-2026-61341 1 Oracle 1 Siebel Crm Cloud Applications 2026-08-20 8.8 High
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2026-61330 1 Oracle 1 Siebel Crm Cloud Applications 2026-08-20 8.8 High
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 22.3-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2026-52610 2026-08-20 9.1 Critical
An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user by specifying a filename in the "saveTemplate" parameter in conjuction with "execute_mode=PREPARE" parameter in the "run.php" endpoint.