Export limit exceeded: 398980 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (398980 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-93774 | 2 Jacob N. Breetvelt, Wordpress | 2 Wp Photo Album Plus, Wordpress | 2026-09-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions. | ||||
| CVE-2026-94391 | 2 Rustaurius, Wordpress | 2 Ultimate Faq, Wordpress | 2026-09-24 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions. | ||||
| CVE-2026-90905 | 1 Joomshaper.com | 1 Easy Store Extension For Joomla | 2026-09-24 | N/A |
| Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 - The endpoint administrator/index.php?option=com_easystore&task=appconfig.updateConfiguration updated core Joomla mail configuration (fromname, mailfrom) in configuration.php without verifying anti-CSRF tokens or checking for administrative permissions (canAdmin). A malicious site could silently modify the site's sender name and email address via forged requests from an admin's browser. Resolved by enforcing Session::checkToken('request') / Session::checkToken('post') and adding explicit administrative authorization verification via AccessControl::create()->canAdmin(). | ||||
| CVE-2026-95622 | 2026-09-24 | 6.5 Medium | ||
| A flaw was found in ModemManager. When parsing a Cell Broadcast Message, some 3GPP data-coding-scheme values (8-bit and reserved character sets) are not handled. The process hits a reachable assertion and aborts. An attacker who can deliver a crafted Cell Broadcast PDU over the radio network, or via a modem AT channel, can cause ModemManager to exit. Repeated aborts can exhaust systemd's default start limit and leave the service failed. | ||||
| CVE-2026-55632 | 1 Gocd | 1 Gocd | 2026-09-23 | 4.3 Medium |
| GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompletion while editing pipeline, template, environment, and user-preference configuration returns its users-and-roles mode to regular authenticated users without requiring an administrator role. A lower-privileged user can enumerate configured user names and available role names, which can facilitate attacks against those users. The response does not reveal which roles are assigned to each user, and the endpoint cannot modify data. This issue is fixed in version 26.1.0. | ||||
| CVE-2026-93527 | 2 Bdthemes, Wordpress | 2 Live Copy Paste For Elementor, Wordpress | 2026-09-23 | 8.5 High |
| Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions. | ||||
| CVE-2026-94179 | 2 Razorpay, Wordpress | 2 Razorpay Payment Button, Wordpress | 2026-09-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions. | ||||
| CVE-2026-94461 | 2 Metaphorcreations, Wordpress | 2 Ditty, Wordpress | 2026-09-23 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions. | ||||
| CVE-2026-94680 | 2 Radiustheme, Wordpress | 2 The Post Grid, Wordpress | 2026-09-23 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. | ||||
| CVE-2026-94684 | 2 Oceanwp, Wordpress | 2 Ocean Extra, Wordpress | 2026-09-23 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 versions. | ||||
| CVE-2026-82368 | 1 Brocade | 1 Sannav | 2026-09-23 | N/A |
| Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services. A local attacker can leverage this exposed access to transmit commands to connected Fabric OS switches under the security context of the SANnav management user. | ||||
| CVE-2026-94498 | 2 Appmysite, Wordpress | 2 Appmysite, Wordpress | 2026-09-23 | 6.5 Medium |
| Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions. | ||||
| CVE-2026-94671 | 2 Radiustheme, Wordpress | 2 The Post Grid, Wordpress | 2026-09-23 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. | ||||
| CVE-2026-94679 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluent Support | 2026-09-23 | 5.4 Medium |
| Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions. | ||||
| CVE-2026-94682 | 2 Secondlinethemes, Wordpress | 2 Podcast Importer Secondline, Wordpress | 2026-09-23 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions. | ||||
| CVE-2026-95513 | 2 Vcita, Wordpress | 2 Online Booking & Scheduling Calendar For Wordpress By Vcita, Wordpress | 2026-09-23 | 7.5 High |
| Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions. | ||||
| CVE-2026-95514 | 2 Netgsm, Wordpress | 2 Netgsm, Wordpress | 2026-09-23 | 5.3 Medium |
| Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions. | ||||
| CVE-2026-95525 | 2 Wedevs, Wordpress | 2 Wp User Frontend, Wordpress | 2026-09-23 | 6.5 Medium |
| Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions. | ||||
| CVE-2026-57168 | 2026-09-23 | N/A | ||
| ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-56120. Reason: This candidate is a duplicate of CVE-2026-56120. Notes: All CVE users should reference CVE-2026-56120 instead of this candidate. | ||||
| CVE-2026-86064 | 1 Klever-io | 1 Klever-go | 2026-09-23 | 8.6 High |
| Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured in config/node/api.yaml and registered by network/api/api.go does not require authentication. The first client message is parsed as a logger Profile in network/api/logs/logSender.go and applied process-wide through Profile.Apply, allowing a remote client to change global log levels and formatting options until the connection closes. The same connection is registered as a log observer and can receive live process logs. An attacker can suppress normal logs, increase verbosity, distort operator visibility, and access operational information without credentials. This issue is fixed in version 1.7.20. | ||||