Export limit exceeded: 403770 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403770 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403770 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403770 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-76463 | 1 Cisco | 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more | 2026-10-09 | 8.8 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76463 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284. | ||||
| CVE-2026-76464 | 1 Cisco | 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more | 2026-10-09 | 9.6 Critical |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by this CVE-2026-76464 are related to buffer management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-119. | ||||
| CVE-2026-76468 | 1 Cisco | 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more | 2026-10-09 | 8.2 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76468 are related to improper input validation that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20. | ||||
| CVE-2026-76469 | 1 Cisco | 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more | 2026-10-09 | 7.4 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76469 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-691. | ||||
| CVE-2026-76470 | 1 Cisco | 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more | 2026-10-09 | 8.8 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76470 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-682. | ||||
| CVE-2026-76467 | 1 Cisco | 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more | 2026-10-09 | 7.5 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76467 are related to issues concerning improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664. | ||||
| CVE-2026-76472 | 1 Cisco | 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more | 2026-10-09 | 8.8 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-76472 are related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74. | ||||
| CVE-2026-106557 | 1 Backstage | 2 Backstage, Plugin-techdocs-node | 2026-10-09 | 7.7 High |
| Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package did not sufficiently validate TechDocs Markdown extension configuration. An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary, potentially exposing backend-host data or internal network resources. This issue is fixed in versions 1.14.6 and 1.15.4 when pymdown-extensions 10.21.3 or later is also used, normally through mkdocs-techdocs-core 1.7.0 or later. | ||||
| CVE-2026-92542 | 2 Docker, Moby | 3 Docker Engine, Docker Engine Overlay Network Driver, Moby Overlay Network Driver | 2026-10-09 | 7.1 High |
| The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged datagrams sent by user processes. Any packet sent from the host network namespace of a Linux Swarm node is encrypted with the overlay-network IPsec parameters which meets the following criteria: - UDP datagram - Destination port is the Swarm data-path port - Datagram starts with a VXLAN header for the VNI of an encrypted overlay network which any running container on the node is connected to | ||||
| CVE-2026-94662 | 2 Unlimited-elements, Wordpress-extensions | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor | 2026-10-09 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Stored XSS. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.19. | ||||
| CVE-2026-106065 | 2 Gimp, Redhat | 2 Gimp, Enterprise Linux | 2026-10-09 | 6.3 Medium |
| A heap-based buffer overflow was found in GIMP’s PCX export plug-in. For images with extremely large width and height, buffer allocation uses overflowing 32-bit width * height arithmetic while subsequent GEGL operations use the full extent, after integer overflow in size calculation | ||||
| CVE-2026-94670 | 2 Wordpress-extensions, Wpeverest | 2 Everest Forms, Everest Forms | 2026-10-09 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Everest Forms allows Reflected XSS. This issue affects Everest Forms: from n/a through 3.6.1. | ||||
| CVE-2026-95534 | 2 Unlimited-elements, Wordpress-extensions | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor | 2026-10-09 | 8.8 High |
| Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Object Injection. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.19. | ||||
| CVE-2026-95595 | 2 Fontsplugin, Wordpress-extensions | 2 Disable And Remove Google Fonts Gdpr Dsgvo Friendly, Disable And Remove Google Fonts Gdpr Dsgvo Friendly | 2026-10-09 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fontsplugin Disable and Remove Google Fonts | GDPR & DSGVO friendly disable-remove-google-fonts allows Reflected XSS. This issue affects Disable and Remove Google Fonts | GDPR & DSGVO friendly: from n/a through 2.0.2. | ||||
| CVE-2026-95605 | 2 Passionate Programmer Peter, Wordpress-extensions | 2 Wp Data Access, Wp Data Access | 2026-10-09 | 9.3 Critical |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Passionate Programmer Peter WP Data Access allows Blind SQL Injection. This issue affects WP Data Access: from n/a through 5.5.82. | ||||
| CVE-2026-95606 | 2 Stellarwp, Wordpress-extensions | 2 The Events Calendar, The Events Calendar | 2026-10-09 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection. This issue affects The Events Calendar: from n/a through 6.17.4. | ||||
| CVE-2026-96335 | 2 Wordpress-extensions, Wpmudev | 2 Forminator, Forminator Forms | 2026-10-09 | 7.5 High |
| Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Forminator: from n/a through 1.57.2. | ||||
| CVE-2026-106066 | 2 Gimp, Redhat | 2 Gimp, Enterprise Linux | 2026-10-09 | 6.3 Medium |
| A heap-based buffer overflow was found in GIMP’s raw data export plug-in. When exporting very large images, g_malloc() sizing based on overflowing width * height * bytes-per-pixel can allocate far less memory than GEGL reads or writes during export, following integer overflow | ||||
| CVE-2026-106067 | 2 Gimp, Redhat | 2 Gimp, Enterprise Linux | 2026-10-09 | 6.3 Medium |
| A heap-based buffer overflow was found in GIMP’s Hot color filter plug-in. For very large images, a pixel buffer is allocated using overflowing 32-bit width * height (and related) arithmetic while the filter’s pixel access path uses the true image size, after integer overflow in the allocation size | ||||
| CVE-2026-56851 | 1 Golang | 1 Text | 2026-10-09 | 7.5 High |
| The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer. | ||||