Export limit exceeded: 403962 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 103047 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (103047 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-104394 2 Syed Balkhi, Wordpress-extensions 2 Charitable, Charitable 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Charitable <= 1.8.12.3 versions.
CVE-2026-104395 2 Picu, Wordpress-extensions 2 Picu, Picu 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in picu <= 3.10.1 versions.
CVE-2026-104405 2 Nexcess, Wordpress-extensions 2 Givewp, Givewp 2026-10-06 8.1 High
Unauthenticated Privilege Escalation in GiveWP <= 4.17.0 versions.
CVE-2026-104406 2 Picu, Wordpress-extensions 2 Picu, Picu 2026-10-06 7.3 High
Unauthenticated Broken Access Control in picu <= 3.10.1 versions.
CVE-2026-104670 2 Thimpress, Wordpress-extensions 2 Learnpress, Learnpress 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in LearnPress <= 4.4.9 versions.
CVE-2026-104672 2 Nexcess, Wordpress-extensions 2 Givewp, Givewp 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.17.0 versions.
CVE-2026-104747 2 Edge-themes, Wordpress-extensions 2 Haaken, Haaken 2026-10-06 8.1 High
Unauthenticated PHP Object Injection in Haaken <= 1.5 versions.
CVE-2026-104757 2 Carazo, Wordpress-extensions 2 Import And Export Users And Customers, Import And Export Users And Customers 2026-10-06 7.2 High
Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions.
CVE-2026-104814 2 Epiph, Wordpress-extensions 2 Form Block, Form Block 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Form Block <= 1.8.1 versions.
CVE-2026-105058 2 John James Jacoby, Wordpress-extensions 2 Wp User Profiles, Wp User Profiles 2026-10-06 8.8 High
Subscriber Privilege Escalation in WP User Profiles <= 2.7.3 versions.
CVE-2026-105061 2 Brandtoss, Wordpress-extensions 2 Wpmailster, Wp Mailster 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP Mailster <= 1.9.0.0 versions.
CVE-2026-105070 2 Dimitri Grassi, Wordpress-extensions 2 Salon Booking System, Salon Booking System 2026-10-06 8.8 High
Unauthenticated Privilege Escalation in Salon booking system <= 10.31.7 versions.
CVE-2026-105071 2 Royal Plugins, Wordpress-extensions 2 Sitevault, Sitevault 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1.5.17 versions.
CVE-2026-105317 2 Cozmoslabs, Wordpress-extensions 2 Paid Member Subscriptions, Paid Member Subscriptions 2026-10-06 8.5 High
Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions.
CVE-2026-98363 1 Linux 1 Linux Kernel 2026-10-06 7.0 High
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS scpi_dvfs_get_info() already rejected a zero opp_count, but still trusted any larger value from the SCP firmware. The shared-memory reply only holds MAX_DVFS_OPPS entries in buf.opps[]; a bigger count over-reads that array and then sizes the allocated OPP table incorrectly (garbage OPPs / OOB). The missing upper bound dates back to the original SCPI DVFS support. Reject zero and out-of-range counts in one check and return -EINVAL.
CVE-2026-86104 1 Watchguard 2 Fireware, Fireware Os 2026-10-06 7.5 High
An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request.
CVE-2026-86105 1 Watchguard 2 Fireware, Fireware Os 2026-10-06 7.1 High
An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.
CVE-2026-63277 1 The Document Foundation 1 Libreoffice 2026-10-06 7.8 High
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.
CVE-2026-105649 1 Ghost 1 Ghost 2026-10-06 7.3 High
Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG images uploaded with a non-SVG file extension were stored without sanitization. This allowed any staff user, including Contributors, to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.65.0.
CVE-2026-105650 1 Ghost 1 Ghost 2026-10-06 8.1 High
Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These scripts could run in the Ghost editor, on the published site, and in newsletter emails, possibly resulting in compromise of a staff user's admin session. This issue is fixed in version 6.64.0.