Search Results (103011 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-102406 1 Elastic 1 Kibana 2026-10-06 8.8 High
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data interception. In this context, "tenant" refers to a user or team sharing the same Kibana deployment, not a separate Elastic Cloud organization or customer. Kibana's Fleet package installation process allowed a user holding delegated Fleet package-management privileges, without direct Elasticsearch administrative privileges, to claim a data stream identifier already in use by another tenant. Because ownership of that identifier was not verified before Fleet applied the uploaded package's generated index and ingest-pipeline settings to already-existing infrastructure, an attacker could redirect an existing tenant's data stream through infrastructure under their control. This exposed the affected tenant's subsequently ingested data to unauthorized disclosure and modification, and prevented that data from reaching its intended destination. Interception could continue even after the malicious package was removed, requiring separate remediation of the affected infrastructure.
CVE-2026-105149 1 Moosocial 1 Moosocial 2026-10-06 7.3 High
A security flaw has been discovered in mooSocial up to 3.2.4. This issue affects some unknown processing of the file /stores/all-products. Performing a manipulation of the argument rating results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-105089 1 Wwbn 1 Avideo 2026-10-06 8.7 High
WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe src attributes to execute JavaScript in victims' browsers.
CVE-2026-105170 1 Kishor-23 1 Food-waste-management-system 2026-10-06 7.3 High
A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file admin/signup.php of the component Admin Signup. This manipulation of the argument sign causes missing authentication. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-105166 1 Kishor-23 2 Food-waste-management-system, Food Waste Management System 2026-10-06 7.3 High
A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of the file fooddonateform.php of the component Food Donation Form. Performing a manipulation of the argument image-choice results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-39758 2 Midtrans, Wordpress-extensions 2 Midtrans-woocommerce, Midtrans-woocommerce 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Midtrans-WooCommerce <= 2.32.3 versions.
CVE-2026-39765 2 Webappick, Wordpress-extensions 2 Challan, Challan 2026-10-06 7.2 High
Shop Manager Privilege Escalation in Challan <= 3.7.88 versions.
CVE-2026-39766 2 Reputeinfosystems, Wordpress-extensions 2 Arforms, Arforms 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.
CVE-2026-39769 2 Iqonicdesign, Wordpress-extensions 2 Graphina, Graphina 2026-10-06 7.5 High
Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions.
CVE-2026-39771 2 Mightynetworks Vs Buddyboss, Wordpress-extensions 2 Buddyboss Platform, Buddyboss Platform 2026-10-06 8.5 High
Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions.
CVE-2026-39774 2 Tourfic Ai Studio, Wordpress-extensions 2 Tourfic Pro, Tourfic Pro 2026-10-06 8.8 High
Unauthenticated Privilege Escalation in Tourfic Pro <= 1.17.3 versions.
CVE-2026-39775 2 Dexignzone, Wordpress-extensions 2 Jobzilla - Job Board Wordpress Theme, Jobzilla 2026-10-06 8.8 High
Subscriber Privilege Escalation in JobZilla - Job Board WordPress Theme <= 2.2 versions.
CVE-2026-39776 2 Wordpress-extensions, Wpshopmart 2 Tabs, Tabs 2026-10-06 8 High
Editor Remote Code Execution (RCE) in Tabs <= 2.5 versions.
CVE-2026-39778 2 Themeansar, Wordpress-extensions 2 Ansar Import – One Click Starter Sites – For Elementor & Themes, Ansar Import – One Click Starter Sites – For Elementor & Themes 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Ansar Import – One Click Starter Sites – for Elementor &amp; Themes <= 2.1.2 versions.
CVE-2026-39780 2 Wordpress-extensions, Youzify 2 Youzify, Youzify 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Youzify <= 1.3.7 versions.
CVE-2026-39781 2 Dan Rossiter, Wordpress-extensions 2 Document Gallery, Document Gallery 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Document Gallery <= 5.1.1 versions.
CVE-2026-39784 2 Nicdark, Wordpress-extensions 2 Hotel Booking, Hotel Booking 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Hotel Booking <= 3.8 versions.
CVE-2026-39792 2 Mitchell Bennis, Wordpress-extensions 2 Simple File List, Simple File List 2026-10-06 8.6 High
Unauthenticated Arbitrary File Deletion in Simple File List <= 6.3.11 versions.
CVE-2026-39793 2 Nicu Micle, Wordpress-extensions 2 Simple Jwt Login, Simple Jwt Login 2026-10-06 8.8 High
Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions.
CVE-2026-39794 2 Wclovers, Wordpress-extensions 2 Woocommerce Multivendor Marketplace, Woocommerce Multivendor Marketplace Rest Api 2026-10-06 7.5 High
Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions.