Export limit exceeded: 103047 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (103047 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-12171 | 1 Cookpete | 1 Auto-changelog | 2026-10-06 | 7.8 High |
| auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over attacker-controlled repository content (for example, in a CI workflow that checks out an untrusted pull request head, or locally on a forked or third-party repository) executes attacker-chosen code with the privileges of the invoking user or CI job, including access to workflow secrets, without the repository dependencies ever being installed. The plugins option similarly loads attacker-controlled modules from the repository. Under the same conditions, appendGitLog/appendGitTag allow git argument injection (e.g. --output= to write arbitrary files), output allows writing attacker-influenced content to arbitrary paths, and template causes an outbound request to an attacker-chosen URL. Version 2.6.1 treats in-repository configuration as untrusted and refuses to run when it sets these options, unless the new --unsafe-config flag is passed. | ||||
| CVE-2026-102262 | 1 Newell Brands | 1 Dymo Id | 2026-10-06 | 7.3 High |
| Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the victim's privilege level. Fixed in 1.6.0. | ||||
| CVE-2026-105773 | 1 Canimaan Software | 1 Clamxav | 2026-10-06 | 7 High |
| Canimaan Software ClamXAV versions 3.3 - 3.11 contains a local privilege escalation vulnerability in the Privileged Helper Tool caused by a race condition and insufficient file validation, allowing a local attacker to execute arbitrary code with system privileges. Fixed in 3.11.1. | ||||
| CVE-2026-82988 | 1 Viewsonic | 1 Vcast | 2026-10-06 | 7.5 High |
| There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to trigger unprivileged APK installation via serving a malicious APK URL through an unauthenticated download endpoint | ||||
| CVE-2026-42414 | 2 Cridio, Wordpress-extensions | 2 Listingpro, Listingpro | 2026-10-06 | 8.5 High |
| Subscriber SQL Injection in ListingPro <= 2.9.12 versions. | ||||
| CVE-2026-42416 | 2 Andondesign, Wordpress-extensions | 2 Udesign, Udesign Core | 2026-10-06 | 8.5 High |
| Subscriber SQL Injection in UDesign Core <= 4.15.0 versions. | ||||
| CVE-2026-42634 | 2 Bplugins, Wordpress-extensions | 2 Video Background Block – Use Video As Background In The Section., Video Background Block Use Video As Background In The Section | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Video Background Block – Use video as background in the section. <= 2.0.3 versions. | ||||
| CVE-2026-42635 | 2 Wordpress-extensions, Wpgenie | 2 Woocommerce Simple Auctions, Woocommerce Simple Auctions | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WooCommerce Simple Auctions <= 3.0.10 versions. | ||||
| CVE-2026-42636 | 2 Wordpress-extensions, Wp Legal Pages | 2 Wp Cookie Notice For Gdpr, Ccpa & Eprivacy Consent, Wp Cookie Notice For Gdpr, Ccpa & Eprivacy Consent | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.4.6 versions. | ||||
| CVE-2026-48197 | 2 Publishpress, Wordpress-extensions | 2 Capabilities, Publishpress Capabilities | 2026-10-06 | 7.2 High |
| Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0. | ||||
| CVE-2026-48199 | 2 Beplusthemes, Wordpress-extensions | 2 Sermon'e, Sermon'e | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in Sermon'e <= 1.0.2 versions. | ||||
| CVE-2026-62072 | 2 Progress Planner, Wordpress-extensions | 2 Progress Planner, Progress Planner | 2026-10-06 | 8.8 High |
| Subscriber Broken Access Control in Progress Planner <= 1.10.0 versions. | ||||
| CVE-2026-66588 | 2 Dream-theme, Wordpress-extensions | 2 The7, The7 | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in The7 <= 14.2.2 versions. | ||||
| CVE-2026-94675 | 2 Fluent Forms Free Vs Pro, Wordpress-extensions | 2 Fluent Forms Pro Add On Pack, Fluent Forms Pro Add On Pack | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack <= 6.2.13 versions. | ||||
| CVE-2026-95526 | 2 Realmag777, Wordpress-extensions | 2 Bear, Bear | 2026-10-06 | 7.3 High |
| Unauthenticated Broken Access Control in BEAR <= 1.2.2 versions. | ||||
| CVE-2026-95594 | 2 Cozy Vision Technologies Pvt. Ltd., Wordpress-extensions | 2 Sms Alert Order Notifications, Sms Alert Order Notifications | 2026-10-06 | 8.1 High |
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions. | ||||
| CVE-2026-102387 | 2 Wordpress-extensions, Xserver | 2 Xserver Migrator, Xserver Migrator | 2026-10-06 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Xserver Migrator <= 1.6.6 versions. | ||||
| CVE-2026-102915 | 2 Marco Van Wieren, Wordpress-extensions | 2 Wpo365, Wpo365 | 2026-10-06 | 8.5 High |
| Subscriber Broken Access Control in WPO365 <= 44.1 versions. | ||||
| CVE-2026-104385 | 2 Adrian Tobey, Wordpress-extensions | 2 Groundhogg, Groundhogg | 2026-10-06 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Groundhogg <= 4.8.3 versions. | ||||
| CVE-2026-104387 | 2 Blubrry, Wordpress-extensions | 2 Powerpress Podcasting, Powerpress Podcasting | 2026-10-06 | 7.2 High |
| Unauthenticated Broken Access Control in PowerPress Podcasting <= 11.17.9 versions. | ||||