Export limit exceeded: 403962 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 103047 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (103047 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104394 | 2 Syed Balkhi, Wordpress-extensions | 2 Charitable, Charitable | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Charitable <= 1.8.12.3 versions. | ||||
| CVE-2026-104395 | 2 Picu, Wordpress-extensions | 2 Picu, Picu | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in picu <= 3.10.1 versions. | ||||
| CVE-2026-104405 | 2 Nexcess, Wordpress-extensions | 2 Givewp, Givewp | 2026-10-06 | 8.1 High |
| Unauthenticated Privilege Escalation in GiveWP <= 4.17.0 versions. | ||||
| CVE-2026-104406 | 2 Picu, Wordpress-extensions | 2 Picu, Picu | 2026-10-06 | 7.3 High |
| Unauthenticated Broken Access Control in picu <= 3.10.1 versions. | ||||
| CVE-2026-104670 | 2 Thimpress, Wordpress-extensions | 2 Learnpress, Learnpress | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in LearnPress <= 4.4.9 versions. | ||||
| CVE-2026-104672 | 2 Nexcess, Wordpress-extensions | 2 Givewp, Givewp | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.17.0 versions. | ||||
| CVE-2026-104747 | 2 Edge-themes, Wordpress-extensions | 2 Haaken, Haaken | 2026-10-06 | 8.1 High |
| Unauthenticated PHP Object Injection in Haaken <= 1.5 versions. | ||||
| CVE-2026-104757 | 2 Carazo, Wordpress-extensions | 2 Import And Export Users And Customers, Import And Export Users And Customers | 2026-10-06 | 7.2 High |
| Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions. | ||||
| CVE-2026-104814 | 2 Epiph, Wordpress-extensions | 2 Form Block, Form Block | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Form Block <= 1.8.1 versions. | ||||
| CVE-2026-105058 | 2 John James Jacoby, Wordpress-extensions | 2 Wp User Profiles, Wp User Profiles | 2026-10-06 | 8.8 High |
| Subscriber Privilege Escalation in WP User Profiles <= 2.7.3 versions. | ||||
| CVE-2026-105061 | 2 Brandtoss, Wordpress-extensions | 2 Wpmailster, Wp Mailster | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP Mailster <= 1.9.0.0 versions. | ||||
| CVE-2026-105070 | 2 Dimitri Grassi, Wordpress-extensions | 2 Salon Booking System, Salon Booking System | 2026-10-06 | 8.8 High |
| Unauthenticated Privilege Escalation in Salon booking system <= 10.31.7 versions. | ||||
| CVE-2026-105071 | 2 Royal Plugins, Wordpress-extensions | 2 Sitevault, Sitevault | 2026-10-06 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in SiteVault – Backup, Restore, Migration & Cloning <= 1.5.17 versions. | ||||
| CVE-2026-105317 | 2 Cozmoslabs, Wordpress-extensions | 2 Paid Member Subscriptions, Paid Member Subscriptions | 2026-10-06 | 8.5 High |
| Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions. | ||||
| CVE-2026-98363 | 1 Linux | 1 Linux Kernel | 2026-10-06 | 7.0 High |
| In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS scpi_dvfs_get_info() already rejected a zero opp_count, but still trusted any larger value from the SCP firmware. The shared-memory reply only holds MAX_DVFS_OPPS entries in buf.opps[]; a bigger count over-reads that array and then sizes the allocated OPP table incorrectly (garbage OPPs / OOB). The missing upper bound dates back to the original SCPI DVFS support. Reject zero and out-of-range counts in one check and return -EINVAL. | ||||
| CVE-2026-86104 | 1 Watchguard | 2 Fireware, Fireware Os | 2026-10-06 | 7.5 High |
| An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request. | ||||
| CVE-2026-86105 | 1 Watchguard | 2 Fireware, Fireware Os | 2026-10-06 | 7.1 High |
| An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access. | ||||
| CVE-2026-63277 | 1 The Document Foundation | 1 Libreoffice | 2026-10-06 | 7.8 High |
| LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL. | ||||
| CVE-2026-105649 | 1 Ghost | 1 Ghost | 2026-10-06 | 7.3 High |
| Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG images uploaded with a non-SVG file extension were stored without sanitization. This allowed any staff user, including Contributors, to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.65.0. | ||||
| CVE-2026-105650 | 1 Ghost | 1 Ghost | 2026-10-06 | 8.1 High |
| Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These scripts could run in the Ghost editor, on the published site, and in newsletter emails, possibly resulting in compromise of a staff user's admin session. This issue is fixed in version 6.64.0. | ||||