Export limit exceeded: 400333 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400333 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-102578 | 1 Moodle | 1 Moodle | 2026-10-01 | 5.5 Medium |
| A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database. | ||||
| CVE-2026-102580 | 1 Moodle | 1 Moodle | 2026-10-01 | 2.2 Low |
| A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may result in unexpected application behavior. | ||||
| CVE-2026-103347 | 2026-10-01 | 5.3 Medium | ||
| Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions. | ||||
| CVE-2026-103068 | 2026-10-01 | 8.8 High | ||
| Subscriber Privilege Escalation in ByteCoreStack – MCP Connector for AI Tools <= 1.2.2 versions. | ||||
| CVE-2026-102378 | 2026-10-01 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions. | ||||
| CVE-2026-100517 | 2026-10-01 | 7.5 High | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions. | ||||
| CVE-2026-100514 | 2026-10-01 | 7.5 High | ||
| Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions. | ||||
| CVE-2026-97297 | 2026-10-01 | 7.6 High | ||
| Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions. | ||||
| CVE-2026-97284 | 2026-10-01 | 8.8 High | ||
| Contributor PHP Object Injection in Icegram <= 3.1.31 versions. | ||||
| CVE-2026-97281 | 2026-10-01 | 6.3 Medium | ||
| Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions. | ||||
| CVE-2026-97277 | 2026-10-01 | 7.6 High | ||
| Subscriber Broken Access Control in Social Boost <= 3.6.2 versions. | ||||
| CVE-2026-97273 | 2026-10-01 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions. | ||||
| CVE-2026-97269 | 2026-10-01 | 6.5 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions. | ||||
| CVE-2026-97268 | 2026-10-01 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions. | ||||
| CVE-2026-97260 | 2026-10-01 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions. | ||||
| CVE-2026-97258 | 2026-10-01 | 6.5 Medium | ||
| Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions. | ||||
| CVE-2026-97251 | 2026-10-01 | 6.5 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions. | ||||
| CVE-2026-95588 | 2026-10-01 | 8.6 High | ||
| Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions. | ||||
| CVE-2026-94390 | 2026-10-01 | 7.2 High | ||
| Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions. | ||||
| CVE-2026-62073 | 2026-10-01 | 7.5 High | ||
| Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions. | ||||