Export limit exceeded: 404217 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404217 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-94158 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bkninja Gloria Admin Panel gloria-admin-panel allows Reflected XSS.This issue affects Gloria Admin Panel: from n/a through 1.3. | ||||
| CVE-2026-94159 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KlbTheme Total Donations totaldonations allows Stored XSS.This issue affects Total Donations: from n/a through 2.0.5. | ||||
| CVE-2026-96334 | 2026-10-09 | 5.6 Medium | ||
| Missing Authorization vulnerability in ThemeGrill User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through 5.2.7. | ||||
| CVE-2026-94170 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Heateor Support Sassy Social Share sassy-social-share allows Reflected XSS.This issue affects Sassy Social Share: from n/a through 3.3.79. | ||||
| CVE-2026-94666 | 2026-10-09 | 7.5 High | ||
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7 allows Path Traversal.This issue affects Generate PDF using Contact Form 7: from n/a through 4.2.1. | ||||
| CVE-2026-94667 | 2026-10-09 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetReviews jet-reviews allows Stored XSS.This issue affects JetReviews: from n/a through 3.1.2. | ||||
| CVE-2026-94661 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog jet-blog allows Reflected XSS.This issue affects JetBlog: from n/a through 2.4.10. | ||||
| CVE-2026-94641 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stiofan UsersWP userswp allows Reflected XSS.This issue affects UsersWP: from n/a through 1.2.73. | ||||
| CVE-2026-96809 | 2026-10-09 | 9.3 Critical | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MultiNet Interactive AB EduAdmin Booking eduadmin-booking allows Blind SQL Injection.This issue affects EduAdmin Booking: from n/a before 6.0.0. | ||||
| CVE-2026-94415 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Muffingroup Betheme betheme allows Reflected XSS.This issue affects Betheme: from n/a through 28.5.8. | ||||
| CVE-2026-96330 | 2026-10-09 | 9.3 Critical | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows Blind SQL Injection.This issue affects tagDiv Opt-In Builder: from n/a through 1.7.6. | ||||
| CVE-2026-96329 | 2026-10-09 | 8.5 High | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows Blind SQL Injection.This issue affects tagDiv Opt-In Builder: from n/a through 1.7.6. | ||||
| CVE-2026-95609 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.41. | ||||
| CVE-2026-95597 | 2026-10-09 | 6.5 Medium | ||
| Missing Authorization vulnerability in codemstory 워드프레스 결제 심플페이 pgall-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 워드프레스 결제 심플페이: from n/a through 5.5.17. | ||||
| CVE-2026-95596 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mamunur Rashid ShopBuilder – Elementor WooCommerce Builder Addons shopbuilder allows Reflected XSS.This issue affects ShopBuilder – Elementor WooCommerce Builder Addons: from n/a through 3.4.1. | ||||
| CVE-2026-95608 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginUs.Net HUSKY woocommerce-products-filter allows Reflected XSS.This issue affects HUSKY: from n/a through 1.4.3.2. | ||||
| CVE-2026-96553 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Damian Góra FiboSearch ajax-search-for-woocommerce allows Reflected XSS.This issue affects FiboSearch: from n/a through 1.34.1. | ||||
| CVE-2026-96539 | 2026-10-09 | 5.6 Medium | ||
| Incorrect Privilege Assignment vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1. | ||||
| CVE-2026-96336 | 2026-10-09 | 7.5 High | ||
| Authentication Bypass by Spoofing vulnerability in WPMU DEV Forminator forminator allows Identity Spoofing.This issue affects Forminator: from n/a through 1.57.2. | ||||
| CVE-2026-98378 | 1 Linux | 1 Linux Kernel | 2026-10-09 | N/A |
| In the Linux kernel, the following vulnerability has been resolved: bpf: Skip unsettled links in link iterator bpf_link_prime() inserts a link into link_idr before anon_inode_getfile() succeeds and before bpf_link_settle() publishes the ID in link->id. bpf_link_by_id() treats such an ID-zero link as unsettled, but the link iterator takes a reference without this check. If anon_inode_getfile() then fails, the creator removes the ID and frees its still-private link directly. The iterator is left with a dangling reference and its next bpf_link_put() accesses freed memory. Treat ID-zero entries as transient in bpf_link_get_curr_or_next(), just as bpf_link_by_id() does. BUG: KASAN: slab-use-after-free in bpf_link_put Write of size 8 by task exp/384 Call Trace: bpf_link_put kernel/bpf/syscall.c:3372 bpf_link_seq_next kernel/bpf/link_iter.c:33 bpf_seq_read kernel/bpf/bpf_iter.c:158 vfs_read fs/read_write.c:572 ksys_read fs/read_write.c:716 do_syscall_64 arch/x86/entry/syscall_64.c:84 entry_SYSCALL_64_after_hwframe arch/x86/entry/entry_64.S:121 Kernel panic - not syncing: KASAN: panic_on_warn set ... | ||||