Export limit exceeded: 387133 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 387133 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (387133 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-86288 | 1 Modelcloud | 1 Gptqmodel | 2026-09-07 | 6.3 Medium |
| A vulnerability has been found in ModelCloud GPTQModel up to 7.2.0. This vulnerability affects unknown code of the file gptqmodel/nn_modules/qlinear/tritonv2.py of the component Triton dequantization kernel. Such manipulation of the argument g_idx leads to out-of-bounds read. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.3.0 is able to resolve this issue. The name of the patch is 877c732f7d7dccd56a729844c6a5bd20f3aa8bb1. Upgrading the affected component is recommended. | ||||
| CVE-2026-78043 | 2026-09-07 | N/A | ||
| The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths | ||||
| CVE-2026-78221 | 1 Openvpn | 1 Openvpn | 2026-09-07 | N/A |
| An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs. | ||||
| CVE-2025-15489 | 2 Passster Project, Wordpress | 2 Passster, Wordpress | 2026-09-07 | 5.3 Medium |
| The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content | ||||
| CVE-2026-84849 | 2 Brightplugins, Wordpress | 2 Pre-orders For Woocommerce, Wordpress | 2026-09-07 | 6.5 Medium |
| Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions. | ||||
| CVE-2026-81295 | 2 Underconstruction Project, Wordpress | 2 Underconstruction, Wordpress | 2026-09-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions. | ||||
| CVE-2026-81773 | 2 Saturdaydrive, Wordpress | 2 Ninja Forms - File Uploads, Wordpress | 2026-09-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | ||||
| CVE-2026-84753 | 2 Getwpfunnels, Wordpress | 2 Mail Mint, Wordpress | 2026-09-07 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. | ||||
| CVE-2026-84754 | 2 Getwpfunnels, Wordpress | 2 Wpfunnels, Wordpress | 2026-09-07 | 6.5 Medium |
| Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions. | ||||
| CVE-2026-84755 | 2 Getwpfunnels, Wordpress | 2 Mail Mint, Wordpress | 2026-09-07 | 6.5 Medium |
| Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions. | ||||
| CVE-2026-84758 | 2 Strategy11team, Wordpress | 2 Business Directory Plugin, Wordpress | 2026-09-07 | 6.5 Medium |
| Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions. | ||||
| CVE-2026-84766 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluent Booking | 2026-09-07 | 5.9 Medium |
| Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions. | ||||
| CVE-2026-84769 | 2 Strategy11team, Wordpress | 2 Business Directory Plugin, Wordpress | 2026-09-07 | 6.5 Medium |
| Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions. | ||||
| CVE-2026-84812 | 2 Wordplus, Wordpress | 2 Better Messages, Wordpress | 2026-09-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions. | ||||
| CVE-2026-85302 | 2 Wordpress, Wpkoi | 2 Wordpress, Wpkoi Templates For Elementor | 2026-09-07 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects WPKoi Templates for Elementor: from n/a through 3.7.2. | ||||
| CVE-2026-85303 | 2 Magepeople, Wordpress | 2 Booking & Rental Manager, Wordpress | 2026-09-07 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking and Rental Manager: from n/a through 2.7.7. | ||||
| CVE-2026-75160 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-07 | 9.1 Critical |
| An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi. | ||||
| CVE-2026-75161 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-07 | N/A |
| An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to inject arbitrary code into the dpcheck system utility executed as root. | ||||
| CVE-2026-75162 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-07 | N/A |
| An information disclosure vulnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows any remote authenticated user, including users with the low-privileged Standard role, to retrieve the configured OPC-UA authentication credentials in cleartext via the JSON API response. | ||||
| CVE-2026-79418 | 1 Emxtecnologia | 1 Gestao X Business Suite | 2026-09-07 | N/A |
| EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the context of other authenticated users, potentially resulting in session hijacking, account takeover, and unauthorized actions. | ||||