Export limit exceeded: 20855 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (390764 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-78084 | 1 Joomshaper.com | 1 Sp Property Extension For Joomla | 2026-09-13 | N/A |
| Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked authorization checks and CSRF token validation.. Users could invoke file removal actions with arbitrary path strings or upload unverified file types. | ||||
| CVE-2026-78083 | 1 Joomshaper.com | 1 Sp Property Extension For Joomla | 2026-09-13 | N/A |
| Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 - The visitor booking (properties.booking) and agent contact form submission (agents.sendmail) endpoints processed POST requests without verifying Joomla session anti-CSRF tokens. | ||||
| CVE-2026-78374 | 1 Joomlart.com | 1 T4 Page Builder Extension For Joomla | 2026-09-13 | N/A |
| Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The front-end JSON editor endpoint exposes an action called contact that requires no authentication, no CSRF token, no captcha (when no captcha plugin is enabled) and has no rate limiting. The attacker fully controls the recipient, subject and HTML body, and the mail is sent from the site's configured sender identity (mailfrom/fromname). | ||||
| CVE-2026-78302 | 1 Joomshaper.com | 1 Sp Property Extension For Joomla | 2026-09-13 | N/A |
| Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rendered attributes and text values directly into HTML without contextual escaping. | ||||
| CVE-2026-78085 | 1 Joomshaper.com | 1 Sp Property Extension For Joomla | 2026-09-13 | N/A |
| Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks. | ||||
| CVE-2026-84828 | 1 Redhat | 5 Enterprise Linux, Openshift, Openshift Container Platform and 2 more | 2026-09-13 | 6.5 Medium |
| A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the files are shorter than 256 bytes. The file contents are read with root privileges by the pcsd daemon and can be exfiltrated by the attacker through subsequent cluster node communication. This allows disclosure of sensitive data such as API keys, tokens, or configuration secrets that would otherwise be inaccessible to the attacker. | ||||
| CVE-2026-9161 | 1 Dernekplus | 1 Website Template | 2026-09-13 | 5.3 Medium |
| Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting. This issue affects Website Template: through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-88038 | 1 Pillarjs | 1 Cookies | 2026-09-13 | 4.8 Medium |
| cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator, but the domain and path options are checked only against a permissive RFC 7230 field-content matcher that allows semicolons, and both are written into the Set-Cookie header unescaped. An application that passes untrusted or request-derived data into the domain or path option can therefore inject additional cookie attributes, overriding SameSite, Secure, HttpOnly, or Domain on the cookies the application issues. This is a Set-Cookie attribute injection issue (CWE-74). The issue is fixed in cookies 0.9.2, which validates domain and path against RFC 6265 character sets. As a workaround, keep domain and path application-set rather than derived from untrusted input. | ||||
| CVE-2026-85544 | 1 Hikvision | 13 Ds-kd8003, Ds-kd8005, Ds-kv6103 and 10 more | 2026-09-13 | 5.2 Medium |
| There is an Improper Encryption Configuration Vulnerability in some Hikvision Intercom Products. This could allow attackers to forge M1 cards. | ||||
| CVE-2026-85545 | 1 Hikvision | 1 Hikcentral Access Control | 2026-09-13 | 7.1 High |
| There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that their role is not authorized to access. | ||||
| CVE-2026-85543 | 1 Hikvision | 1 Wi-fi Series Camera | 2026-09-13 | 4.3 Medium |
| Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces. | ||||
| CVE-2026-12683 | 1 Ankaref Innovation And Technology Inc. | 1 Librid/libref | 2026-09-13 | 5.4 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-6285 | 1 Ankaref Innovation And Technology Inc. | 1 Librid/libref | 2026-09-13 | 7.5 High |
| Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-12682 | 1 Ankaref Innovation And Technology Inc. | 1 Librid/libref | 2026-09-13 | 5.4 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-81783 | 2 Mailmunch, Wordpress | 2 Mailmunch – Grow Your Email List, Wordpress | 2026-09-13 | 7.1 High |
| Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions. | ||||
| CVE-2026-81791 | 2 Ashan Perera, Wordpress | 2 Eventon, Wordpress | 2026-09-13 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions. | ||||
| CVE-2026-81794 | 2 Mlfactory, Wordpress | 2 Shirt Product Designer For Woocommerce, Wordpress | 2026-09-13 | 7.5 High |
| Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions. | ||||
| CVE-2026-81795 | 2 Denis Botić, Wordpress | 2 Page Visits Counter – Lite, Wordpress | 2026-09-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter – Lite <= 1.2.3 versions. | ||||
| CVE-2026-81800 | 2 Par Avisverifies, Wordpress | 2 Verified Reviews (avis Vérifiés), Wordpress | 2026-09-13 | 9.3 Critical |
| Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions. | ||||
| CVE-2026-81801 | 2 Udx Usability Dynamics, Wordpress | 2 Wp-stateless, Wordpress | 2026-09-13 | 8.1 High |
| Subscriber Settings Change in WP-Stateless <= 4.4.1 versions. | ||||