Export limit exceeded: 396815 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (396815 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-96514 | 1 Neethuharii | 1 Cafemanagement | 2026-09-23 | 7.3 High |
| A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogin.php of the component Login Handler. This manipulation of the argument uname causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-96445 | 1 Redhat | 2 Build Keycloak, Red Hat Single Sign On | 2026-09-23 | 6.8 Medium |
| A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates specific HTTP headers to determine if a one-time password (OTP) should be skipped, but fails to verify if those headers came from a trusted source. This could allow an attacker who already has a user's password to bypass the second-factor authentication by providing a specially crafted header in their request. | ||||
| CVE-2026-95845 | 1 Moquette-io | 1 Moquette | 2026-09-23 | N/A |
| Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message queues. When a fast publisher sends messages to a slow subscriber whose in-flight window is full, queued messages can accumulate without bound in memory or persistent storage. Remote clients can use this condition to exhaust broker resources and cause a denial of service. This issue is fixed in version 0.18.1. | ||||
| CVE-2026-95603 | 2026-09-23 | 7.2 High | ||
| Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions. | ||||
| CVE-2026-95600 | 2026-09-23 | 5.3 Medium | ||
| Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions. | ||||
| CVE-2026-95592 | 2026-09-23 | 5.3 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions. | ||||
| CVE-2026-95530 | 2026-09-23 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions. | ||||
| CVE-2026-95528 | 2026-09-23 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions. | ||||
| CVE-2026-95524 | 2026-09-23 | 5.3 Medium | ||
| Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. | ||||
| CVE-2026-95522 | 2026-09-23 | 7.6 High | ||
| Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions. | ||||
| CVE-2026-95513 | 2026-09-23 | 7.5 High | ||
| Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions. | ||||
| CVE-2026-94682 | 2026-09-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions. | ||||
| CVE-2026-94671 | 2026-09-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. | ||||
| CVE-2026-94498 | 2026-09-23 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions. | ||||
| CVE-2026-94457 | 2026-09-23 | 4.8 Medium | ||
| Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions. | ||||
| CVE-2026-94183 | 2026-09-23 | 7.4 High | ||
| Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about the origin of displayed content and increasing the risk of phishing. | ||||
| CVE-2026-94181 | 2026-09-23 | 7.4 High | ||
| An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification. | ||||
| CVE-2026-94179 | 2026-09-23 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions. | ||||
| CVE-2026-94168 | 2 Leap13, Wordpress | 2 Premium Addons For Elementor, Wordpress | 2026-09-23 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. | ||||
| CVE-2026-94118 | 2026-09-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions. | ||||