Export limit exceeded: 403985 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403985 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403985 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103636 | 2026-10-10 | N/A | ||
| Out-of-bounds read in the VarOpt union deserialization of Apache DataSketches C++ (repo: datasketches-cpp). var_opt_union::deserialize() read the 32-byte preamble of a non-empty union after checking that only 8 bytes were available, so a truncated serialized union could cause a read of up to 24 bytes past the end of the input. For such inputs, the size remaining for the embedded sketch was also computed by an unsigned subtraction that could wrap around, so the embedded sketch's own size checks no longer limited reads to the input. The bytes read can become part of the deserialized union's state. This can cause a crash (denial of service) and could expose adjacent memory contents. This issue affects Apache DataSketches C++: from 2.0.0-incubating before 5.3.0. Only applications that deserialize VarOpt unions from untrusted sources are affected. Users are recommended to upgrade to version 5.3.0, which fixes this issue. | ||||
| CVE-2026-103635 | 2026-10-10 | N/A | ||
| Out-of-bounds read in the compact Theta sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). compact_theta_sketch::deserialize() and wrapped_compact_theta_sketch::wrap() read header fields before checking that the input was long enough. For the compressed format, the size check could be defeated by a 32-bit overflow, and two header fields that control decoding were not validated; this also affected deserialization from a stream. A crafted or truncated sketch could cause a read past the end of the input. In the compressed case the over-read can be large, and the bytes read can become part of the deserialized sketch. This can cause a crash (denial of service) and could expose adjacent memory contents. This issue affects Apache DataSketches C++: from 3.1.0 before 5.3.0. Only applications that deserialize Theta sketches from untrusted sources are affected. Users are recommended to upgrade to version 5.3.0, which fixes this issue. | ||||
| CVE-2026-103513 | 2026-10-10 | N/A | ||
| Out-of-bounds read and write in the CPC sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). A crafted serialized CPC sketch passed to cpc_sketch::deserialize(), from either a byte buffer or a stream, can cause the decompressor to read past the end of the compressed data, because the read position was only checked after decoding finished. In the hybrid flavor, it can also cause a write outside an internal heap buffer, because decoded row indices were not validated. Several other header fields and decoded values, including lg_k, were also not validated. This can corrupt heap memory, causing a crash and potentially enabling further exploitation. This issue affects Apache DataSketches C++: from 2.0.0-incubating before 5.3.0. Only applications that deserialize CPC sketches from untrusted sources are affected. Users are recommended to upgrade to version 5.3.0, which fixes this issue. | ||||
| CVE-2026-103501 | 2026-10-10 | N/A | ||
| Heap buffer overflow in the HLL sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). When deserializing a sketch in LIST mode, from either a byte buffer or a stream, the coupon count was read from the input and used as the number of entries to copy into a fixed buffer of 8 entries, without checking it against the buffer's capacity. A crafted sketch could cause a write of up to 988 bytes past the end of this internal heap buffer. This can corrupt heap memory, causing a crash and potentially enabling further exploitation. This issue affects Apache DataSketches C++: from 1.0.0-incubating before 5.3.0. Only applications that deserialize HLL sketches from untrusted sources are affected. Users are recommended to upgrade to version 5.3.0, which fixes this issue. | ||||
| CVE-2026-107794 | 2026-10-10 | N/A | ||
| ExtUtils::Typemaps::STL::List versions before 1.07 for Perl allocate a 32 GiB array on an empty list. The OUTPUT typemaps call av_extend( av, len-1 ). On an empty list, this undeflows, and av_extend will allocate an array with 2^32 slots, leading to memory exhaustion. Note that a similar issue was fixed in ExtUtils::Typemaps::STL::Vector version 1.05. | ||||
| CVE-2013-10076 | 2026-10-10 | N/A | ||
| ExtUtils::Typemaps::STL::Vector versions before 1.05 for Perl allocate a 32 GiB array on an empty list. The OUTPUT typemaps call av_extend( av, len-1 ). On an empty list, this undeflows, and av_extend will allocate an array with 2^32 slots, leading to memory exhaustion. | ||||
| CVE-2026-107373 | 2026-10-10 | N/A | ||
| ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument. The typemap uses $var = std::string( SvPV_nolen($arg), SvCUR($arg) ) However, evaluation order for C++ arguments is not specified, and some compilers may produce code that evalutes SvCUR($arg) first. When $arg is not a string (for example, an interger, number or a reference) then SvCUR will return an invalid value, and the program may abort or segfault. | ||||
| CVE-2026-94256 | 2026-10-10 | 8.1 High | ||
| The SMS Alert WordPress plugin before 4.0.1 does not verify that the account being logged in is the one the verified one-time code belongs to, allowing unauthenticated attackers to sign in as any user with a stored phone number, including an administrator, by completing a code challenge on a phone they control. | ||||
| CVE-2026-87781 | 2026-10-10 | 8.6 High | ||
| The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users. | ||||
| CVE-2026-87780 | 2026-10-10 | 8.8 High | ||
| The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape values submitted through an unauthenticated endpoint before storing them and outputting them back in an administrative page, leading to Stored XSS which will execute in the session of any administrator viewing it. | ||||
| CVE-2026-85571 | 2026-10-10 | 6.5 Medium | ||
| The Tutor LMS WordPress plugin before 4.1.1 does not verify that the posts named in its course content ordering requests belong to a course the requester manages, allowing users with instructor level access to reassign the parent of any post on the site, taking other instructors' course content into their own courses and making arbitrary published content unreachable. | ||||
| CVE-2026-107323 | 2026-10-10 | 6.8 Medium | ||
| The Gallery PhotoBlocks WordPress plugin before 1.3.6 does not sanitize and escape one of its gallery settings before outputting it into an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of anyone who views a page containing the gallery, including administrators. | ||||
| CVE-2026-105995 | 2026-10-10 | 5.3 Medium | ||
| The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens. | ||||
| CVE-2026-105977 | 2026-10-10 | 2.2 Low | ||
| The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform a per-object authorization check before deleting an attachment, allowing users with the Contributor role and above to permanently delete certain media attachments belonging to other users, including administrators. | ||||
| CVE-2026-105976 | 2026-10-10 | 4.7 Medium | ||
| The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform proper authorization checks in a set of AJAX actions, allowing users with at least the Contributor role to read, modify and delete other users' galleries as well as site-wide gallery filters. | ||||
| CVE-2026-104754 | 2026-10-10 | 3.5 Low | ||
| The Rank Math SEO WordPress plugin before 1.0.280 does not escape a stored redirection source value before outputting it in an administrative list view, allowing users who can manage redirections (Administrators by default) to store JavaScript that executes in the session of any user who later opens that view, including a Super Administrator on multisite. | ||||
| CVE-2026-104752 | 2026-10-10 | 7.2 High | ||
| The Rank Math SEO WordPress plugin before 1.0.280 does not correctly validate the type of a file uploaded through its settings import feature, allowing users with administrator-level access to upload a PHP file and achieve remote code execution. | ||||
| CVE-2026-106139 | 2026-10-10 | 5.4 Medium | ||
| In Progress® Kendo UI for Vue (@progress/kendo-vue-charts) starting with version 2.5.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application. | ||||
| CVE-2026-106138 | 2026-10-10 | 5.4 Medium | ||
| In Progress® KendoReact (@progress/kendo-react-charts) starting with version 1.1.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application. | ||||
| CVE-2026-108506 | 2026-10-10 | 5.5 Medium | ||
| ZTE Z80 Ultra's system interfaces do not have robust invocation authentication, with inadequate access control. Third-party apps may call the interfaces through reflection and retrieve relevant information. | ||||