Export limit exceeded: 402502 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (402502 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-106269 2026-10-06 8.8 High
Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106506 2026-10-06 5.3 Medium
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list ordering. An authenticated Backstage user with permission to create and read relevant scaffolder tasks may be able to infer confidential task data under specific conditions. Successful exploitation requires retained task secrets, visibility of a target task, knowledge of the secret structure, and repeated requests. This issue is fixed in version 4.1.0.
CVE-2026-106505 2026-10-06 7.7 High
Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by bypass of mkdocs configuration sanitizer in techdocs backend. Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer introduced in response to CVE-2026-25153 and execute arbitrary code on the TechDocs backend host during documentation generation. This issue is fixed in versions 1.14.6 and 1.15.4.
CVE-2026-106504 2026-10-06 6.5 Medium
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder task logs. An authenticated user who can create and read scaffolder tasks may be able to observe sensitive values in task logs in deployments with restrictive action permissions and affected templates. Exploitation requires a denied action whose input contains such a value. This issue is fixed in version 4.1.0.
CVE-2026-39758 2 Midtrans, Wordpress-extensions 2 Midtrans-woocommerce, Midtrans-woocommerce 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Midtrans-WooCommerce <= 2.32.3 versions.
CVE-2026-39759 2 Amentotech, Wordpress-extensions 2 Workreap, Workreap 2026-10-06 9.9 Critical
Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions.
CVE-2026-39761 2 Elightup, Wordpress-extensions 2 Meta Box Aio, Meta Box Aio 2026-10-06 9.8 Critical
Unauthenticated Privilege Escalation in Meta Box AIO <= 3.7.1 versions.
CVE-2026-39762 2 Patterns In The Cloud, Wordpress-extensions 2 Autoship Cloud For Woocommerce Subscription Products, Autoship Cloud For Woocommerce Subscription Products 2026-10-06 6.5 Medium
Missing Authorization vulnerability in Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products autoship-cloud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.17.1.
CVE-2026-39764 2 Radiustheme, Wordpress-extensions 2 Radius Booking — Booking Calendar For Appointments & Services, Radius Booking 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments &amp; Services <= 1.0.19 versions.
CVE-2026-39765 2 Webappick, Wordpress-extensions 2 Challan, Challan 2026-10-06 7.2 High
Shop Manager Privilege Escalation in Challan <= 3.7.88 versions.
CVE-2026-39766 2 Reputeinfosystems, Wordpress-extensions 2 Arforms, Arforms 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.
CVE-2026-39767 2 Baseapp, Wordpress-extensions 2 Wpbase Cache, Wpbase Cache 2026-10-06 6.5 Medium
Subscriber Denial of Service Attack in WPBase Cache <= 5.5.6 versions.
CVE-2026-39768 2 Cleantalk, Wordpress-extensions 2 Security & Malware Scan, Security & Malware Scan By Cleantalk 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Security & Malware scan by CleanTalk <= 2.189 versions.
CVE-2026-39769 2 Iqonicdesign, Wordpress-extensions 2 Graphina, Graphina 2026-10-06 7.5 High
Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions.
CVE-2026-39770 2 Amentotech, Wordpress-extensions 2 Doctreat Core, Doctreat 2026-10-06 10 Critical
Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions.
CVE-2026-39771 2 Mightynetworks Vs Buddyboss, Wordpress-extensions 2 Buddyboss Platform, Buddyboss Platform 2026-10-06 8.5 High
Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions.
CVE-2026-39772 2 Bestwebsoft, Wordpress-extensions 2 Captcha By Bestwebsoft, Captcha By Bestwebsoft 2026-10-06 5.3 Medium
Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions.
CVE-2026-39773 2 Amentotech, Wordpress-extensions 2 Doctreat Core, Doctreat Core 2026-10-06 10 Critical
Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions.
CVE-2026-39774 2 Tourfic Ai Studio, Wordpress-extensions 2 Tourfic Pro, Tourfic Pro 2026-10-06 8.8 High
Unauthenticated Privilege Escalation in Tourfic Pro <= 1.17.3 versions.
CVE-2026-39775 2 Dexignzone, Wordpress-extensions 2 Jobzilla - Job Board Wordpress Theme, Jobzilla 2026-10-06 8.8 High
Subscriber Privilege Escalation in JobZilla - Job Board WordPress Theme <= 2.2 versions.