Search

Search Results (400097 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-96345 2026-09-30 7.6 High
Administrator SQL Injection in Estatik <= 4.3.5 versions.
CVE-2026-96344 2026-09-30 7.2 High
Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions.
CVE-2026-96343 2026-09-30 7.2 High
Custom role PHP Object Injection in WP ERP <= 1.17.9 versions.
CVE-2026-96338 2026-09-30 6.5 Medium
Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions.
CVE-2026-95587 2026-09-30 7.5 High
Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions.
CVE-2026-95531 2026-09-30 8.8 High
Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions.
CVE-2026-94683 2026-09-30 8.8 High
Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions.
CVE-2026-94681 2026-09-30 5.9 Medium
Unauthenticated Denial of Service Attack in WP Store Locator < 3.0.0 versions.
CVE-2026-94678 2026-09-30 8.8 High
Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions.
CVE-2026-94677 2026-09-30 7.2 High
Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions.
CVE-2026-94674 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in Pixel Manager for WooCommerce <= 1.69.0 versions.
CVE-2026-94673 2026-09-30 5.3 Medium
Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions.
CVE-2026-94672 2026-09-30 4.3 Medium
Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions.
CVE-2026-94499 2026-09-30 7.1 High
Subscriber Broken Access Control in FormGent <= 1.12.2 versions.
CVE-2026-94389 2026-09-30 9 Critical
Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions.
CVE-2026-94194 1 Elixir-mint 1 Mint 2026-09-30 N/A
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint client on a pooled connection, poisoning the responses to subsequent requests that share the connection. message_body/1 in lib/mint/http1.ex selects chunked framing when chunked is the first coding listed in a response's Transfer-Encoding fields. RFC 9112 section 6.3 applies chunked framing only when chunked is the final coding, and otherwise reads the body until the server closes the connection. For a response such as Transfer-Encoding: chunked, gzip, an intermediary that follows the RFC treats every byte up to the close as the body, while Mint ends the body at the zero-length chunk and parses the remaining bytes as the response to the next request on the connection. Mint also keeps the connection open after an HTTP/1.0 response, final or 1xx, that carries Transfer-Encoding and Connection: keep-alive. RFC 9112 section 6.1 requires treating the framing of such a message as faulty and closing the connection after it, so bytes after its chunked body are parsed as the response to the next request in the same way. This issue affects mint: from 0.1.0 before 1.10.2.
CVE-2026-94178 2026-09-30 7.5 High
Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions.
CVE-2026-94177 2026-09-30 8.5 High
Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions.
CVE-2026-94173 2026-09-30 5.4 Medium
Contributor Insecure Direct Object References (IDOR) in Business Directory <= 6.4.27 versions.
CVE-2026-94123 2026-09-30 7.5 High
Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions.