Search

Search Results (400347 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-79899 2026-10-01 7.9 High
Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation.
CVE-2026-102580 1 Moodle 1 Moodle 2026-10-01 2.2 Low
A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may result in unexpected application behavior.
CVE-2026-103347 2026-10-01 5.3 Medium
Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions.
CVE-2026-103068 2026-10-01 8.8 High
Subscriber Privilege Escalation in ByteCoreStack &#8211; MCP Connector for AI Tools <= 1.2.2 versions.
CVE-2026-102378 2026-10-01 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions.
CVE-2026-100517 2026-10-01 7.5 High
Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions.
CVE-2026-100514 2026-10-01 7.5 High
Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions.
CVE-2026-97297 2026-10-01 7.6 High
Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions.
CVE-2026-97284 2026-10-01 8.8 High
Contributor PHP Object Injection in Icegram <= 3.1.31 versions.
CVE-2026-97281 2026-10-01 6.3 Medium
Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions.
CVE-2026-97277 2026-10-01 7.6 High
Subscriber Broken Access Control in Social Boost <= 3.6.2 versions.
CVE-2026-97273 2026-10-01 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.
CVE-2026-97269 2026-10-01 6.5 Medium
Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions.
CVE-2026-97268 2026-10-01 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.
CVE-2026-97260 2026-10-01 7.1 High
Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions.
CVE-2026-97258 2026-10-01 6.5 Medium
Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions.
CVE-2026-97251 2026-10-01 6.5 Medium
Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions.
CVE-2026-95588 2026-10-01 8.6 High
Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions.
CVE-2026-94390 2026-10-01 7.2 High
Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions.
CVE-2026-62073 2026-10-01 7.5 High
Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions.