Export limit exceeded: 404439 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 404439 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 404439 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404439 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104681 | 2026-10-11 | 2.7 Low | ||
| The Envira Gallery WordPress plugin before 1.16.2 does not verify that an image identifier added to a gallery refers to a media attachment the caller is permitted to view, allowing any user able to create and edit a gallery (Author and above by default) to disclose the title and excerpt of other users' private, draft, pending and trashed posts that WordPress would otherwise withhold from them. | ||||
| CVE-2026-103695 | 2026-10-11 | 8.6 High | ||
| The Mobile builder WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-103305 | 2026-10-11 | 8.8 High | ||
| The Prenotazioni WordPress plugin through 1.7.5 does not have authorisation and CSRF checks when saving its settings, and does not escape some of them when outputting them, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators and site visitors. | ||||
| CVE-2026-102388 | 2026-10-11 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV Forminator forminator allows Stored XSS.This issue affects Forminator: from n/a through 1.57.3. | ||||
| CVE-2026-20321 | 1 Cisco | 1 Application Policy Infrastructure Controller (apic) | 2026-10-11 | 6.5 Medium |
| A vulnerability in the web-based management API for Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to execute arbitrary commands as the root user. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient input validation of user-controlled command arguments. An attacker could exploit this vulnerability by authenticating using the API and sending crafted input. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system of an affected device with root-level privileges. | ||||
| CVE-2026-20032 | 1 Cisco | 1 Nx-os Software | 2026-10-11 | 4.4 Medium |
| A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, local attacker with low privileges to escape the Python sandbox and gain unauthorized access to the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by manipulating specific functions within the Python interpreter. A successful exploit could allow an attacker to escape the Python sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user. | ||||
| CVE-2026-76453 | 1 Cisco | 3 Cisco Nx-os System Software In Aci Mode, Nx-os Software, Unified Computing System Manager | 2026-10-11 | 8.8 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76453 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) CWE-707. | ||||
| CVE-2026-76465 | 1 Cisco | 1 Nx-os Software | 2026-10-11 | 9.8 Critical |
| A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validation when an affected device is processing an MPLS echo-request packet. An attacker could exploit this vulnerability by sending a crafted MPLS echo-request to an IP address on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a device reload and a DoS condition. | ||||
| CVE-2026-76456 | 1 Cisco | 3 Cisco Nx-os System Software In Aci Mode, Nx-os Software, Unified Computing System Manager | 2026-10-11 | 8.6 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76456 are related to improper input validation of special elements used in a command issue that are grouped under the Common Weakness Enumeration (CWE) CWE-20. | ||||
| CVE-2026-76457 | 1 Cisco | 3 Cisco Nx-os System Software In Aci Mode, Nx-os Software, Unified Computing System Manager | 2026-10-11 | 8.6 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76457 are related to out-of-bounds read issues that are grouped under the Common Weakness Enumeration (CWE) CWE-125. | ||||
| CVE-2026-76455 | 1 Cisco | 3 Cisco Nx-os System Software In Aci Mode, Nx-os Software, Unified Computing System Manager | 2026-10-11 | 9.8 Critical |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76455 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284. | ||||
| CVE-2026-76471 | 1 Cisco | 2 Nx-os Software, Unified Computing System Manager | 2026-10-11 | 9.8 Critical |
| A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a reload of the device and a DoS condition. | ||||
| CVE-2026-107727 | 1 Strawberry | 1 Strawberry | 2026-10-11 | 3.7 Low |
| Strawberry GraphQL is a library for creating GraphQL APIs. From 0.312.3 until 0.327.2, the legacy graphql-ws subscription handler in strawberry/subscriptions/protocols/graphql_ws/handlers.py does not remove naturally completed operations from self.tasks and self.subscriptions. When max_subscriptions_per_connection is configured, a client on a persistent WebSocket connection can use distinct operation IDs for one-shot subscriptions to fill the connection's configured slots even after those subscriptions send complete, causing later legitimate operations on that connection to be rejected with Subscription limit reached. The modern graphql-transport-ws protocol and deployments without the configured per-connection cap are not affected. This issue is fixed in version 0.327.2. | ||||
| CVE-2026-107728 | 1 Strawberry | 1 Strawberry | 2026-10-11 | 7.5 High |
| Strawberry GraphQL is a library for creating GraphQL APIs. From 0.217.0 until 0.326.1, PermissionExtension.resolve() on a synchronous field resolver evaluates the result of has_permission() for truthiness. When a custom permission declares has_permission() as a normal function but returns an awaitable, supports_sync does not classify it as asynchronous, the awaitable is not awaited, and its inherently truthy object value permits the protected resolver to run even when the result would resolve to false. This affects synchronous field resolvers under both execute_sync() and execute(); permissions declared with async def has_permission() and synchronous permissions returning a boolean are not affected. This issue is fixed in version 0.326.1. | ||||
| CVE-2026-76769 | 1 Dell | 1 Secure Connect Gateway Policy Manager | 2026-10-11 | 4.3 Medium |
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | ||||
| CVE-2026-76779 | 1 Dell | 1 Secure Connect Gateway Policy Manager | 2026-10-11 | 7.4 High |
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Excessive Authentication Attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Protection mechanism bypass, and Unauthorized access. | ||||
| CVE-2026-78013 | 1 Dell | 1 Secure Connect Gateway Policy Manager | 2026-10-11 | 5.2 Medium |
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service, Information disclosure, and Protection mechanism bypass. | ||||
| CVE-2026-78015 | 1 Dell | 1 Secure Connect Gateway Policy Manager | 2026-10-11 | 3.7 Low |
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Less Trusted Source vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information tampering. | ||||
| CVE-2026-78016 | 1 Dell | 1 Secure Connect Gateway Policy Manager | 2026-10-11 | 3.1 Low |
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Validation of Specified Type of Input vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure and Information tampering. | ||||
| CVE-2026-78017 | 1 Dell | 1 Secure Connect Gateway Policy Manager | 2026-10-11 | 3.8 Low |
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Check for Unusual or Exceptional Conditions vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Protection mechanism bypass. | ||||