Export limit exceeded: 28752 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (28752 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-106392 | 1 Google | 1 Chrome | 2026-10-07 | 4.3 Medium |
| Information leak in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106321 | 1 Google | 1 Chrome | 2026-10-07 | 4.3 Medium |
| Information leak in Editing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106254 | 1 Google | 2 Android, Chrome | 2026-10-07 | 5.1 Medium |
| Information leak in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: Medium) | ||||
| CVE-2026-106415 | 1 Google | 1 Chrome | 2026-10-07 | 4.3 Medium |
| Information leak in Enterprise in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106414 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-10-07 | 9.6 Critical |
| Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106256 | 1 Google | 2 Android, Chrome | 2026-10-07 | 8.8 High |
| Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-28640 | 1 Google | 1 Android | 2026-10-07 | 7.8 High |
| In checkCallerIsCertInstallerOrSelfInProfile of CredentialStorageActivity.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-106180 | 1 Google | 1 Chrome | 2026-10-07 | 3.1 Low |
| Observable discrepancy in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106226 | 1 Google | 1 Chrome | 2026-10-07 | 4.2 Medium |
| Improper input validation in Compositing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-97331 | 2026-10-07 | 4.3 Medium | ||
| The User Private Files WordPress plugin before 2.1.9 does not validate that a supplied user belongs to the document being operated on before returning that user's email address, allowing any authenticated user, such as a Subscriber, to obtain the email address of any registered account, including administrators. | ||||
| CVE-2026-96530 | 2026-10-07 | 6.5 Medium | ||
| The Optimole WordPress plugin before 4.2.15 does not perform a capability check before exposing its stored image-optimization account data in a dashboard widget, allowing any authenticated user, including Subscribers, to read the site's third-party service credentials. | ||||
| CVE-2026-106210 | 1 Google | 1 Chrome | 2026-10-07 | 3.1 Low |
| Observable discrepancy in Scroll in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium) | ||||
| CVE-2021-1432 | 1 Cisco | 2 Ios Xe, Ios Xe Sd-wan | 2026-10-07 | 7.3 High |
| A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected device as a low-privileged user to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by injecting arbitrary commands to a file as a lower-privileged user. The commands are then executed on the device by the root user. A successful exploit could allow the attacker to execute arbitrary commands as the root user. | ||||
| CVE-2026-86833 | 2026-10-07 | 5.4 Medium | ||
| The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, allowing unauthenticated attackers to inject arbitrary markup into the administrator and submitter notification emails the site sends. | ||||
| CVE-2026-86816 | 2026-10-07 | 5.3 Medium | ||
| The WPCafe WordPress plugin before 3.0.21 does not restrict access to some of its REST API endpoints, allowing unauthenticated attackers to read WooCommerce product data, including per-product sales counts, exact stock levels, and private product meta, that WooCommerce itself keeps behind authentication. | ||||
| CVE-2026-82211 | 2026-10-07 | 8.2 High | ||
| The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing attackers to mark arbitrary orders as paid or failed, to cancel them, and to obtain order keys which expose guest buyers' details. | ||||
| CVE-2026-103323 | 2026-10-07 | 5.9 Medium | ||
| The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2 does not perform an authorization check on one of its REST endpoints, allowing unauthenticated users to retrieve the site's scheduled background tasks and their arguments, which include order identifiers and, when WooCommerce's deferred emails feature is enabled, the plaintext passwords of newly registered customers. | ||||
| CVE-2026-103378 | 2026-10-07 | 6.5 Medium | ||
| The Geliver Akıllı Kargo Pazaryeri WordPress plugin before 3.1.1 does not prevent unauthenticated access to a log file it stores within its own web-accessible directory, into which it writes the site's carrier integration key while processing requests from unauthenticated users, allowing attackers to retrieve the key and use it to modify WooCommerce order statuses. The same log file also exposes customer information from orders the shop has processed. | ||||
| CVE-2026-52001 | 1 Geelen | 1 Mcp-remote | 2026-10-07 | 7.5 High |
| An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE transport eventSourceInit fetch wrapper " src/lib/utils.ts | ||||
| CVE-2026-103627 | 1 Google | 1 Chrome | 2026-10-07 | 6.5 Medium |
| Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||