Export limit exceeded: 390800 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (390800 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-9161 | 1 Dernekplus | 1 Website Template | 2026-09-13 | 5.3 Medium |
| Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting. This issue affects Website Template: through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-88038 | 1 Pillarjs | 1 Cookies | 2026-09-13 | 4.8 Medium |
| cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator, but the domain and path options are checked only against a permissive RFC 7230 field-content matcher that allows semicolons, and both are written into the Set-Cookie header unescaped. An application that passes untrusted or request-derived data into the domain or path option can therefore inject additional cookie attributes, overriding SameSite, Secure, HttpOnly, or Domain on the cookies the application issues. This is a Set-Cookie attribute injection issue (CWE-74). The issue is fixed in cookies 0.9.2, which validates domain and path against RFC 6265 character sets. As a workaround, keep domain and path application-set rather than derived from untrusted input. | ||||
| CVE-2026-85544 | 1 Hikvision | 13 Ds-kd8003, Ds-kd8005, Ds-kv6103 and 10 more | 2026-09-13 | 5.2 Medium |
| There is an Improper Encryption Configuration Vulnerability in some Hikvision Intercom Products. This could allow attackers to forge M1 cards. | ||||
| CVE-2026-85545 | 1 Hikvision | 1 Hikcentral Access Control | 2026-09-13 | 7.1 High |
| There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that their role is not authorized to access. | ||||
| CVE-2026-85543 | 1 Hikvision | 1 Wi-fi Series Camera | 2026-09-13 | 4.3 Medium |
| Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces. | ||||
| CVE-2026-12683 | 1 Ankaref Innovation And Technology Inc. | 1 Librid/libref | 2026-09-13 | 5.4 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-6285 | 1 Ankaref Innovation And Technology Inc. | 1 Librid/libref | 2026-09-13 | 7.5 High |
| Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-12682 | 1 Ankaref Innovation And Technology Inc. | 1 Librid/libref | 2026-09-13 | 5.4 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-81783 | 2 Mailmunch, Wordpress | 2 Mailmunch – Grow Your Email List, Wordpress | 2026-09-13 | 7.1 High |
| Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions. | ||||
| CVE-2026-81791 | 2 Ashan Perera, Wordpress | 2 Eventon, Wordpress | 2026-09-13 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions. | ||||
| CVE-2026-81794 | 2 Mlfactory, Wordpress | 2 Shirt Product Designer For Woocommerce, Wordpress | 2026-09-13 | 7.5 High |
| Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions. | ||||
| CVE-2026-81795 | 2 Denis Botić, Wordpress | 2 Page Visits Counter – Lite, Wordpress | 2026-09-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter – Lite <= 1.2.3 versions. | ||||
| CVE-2026-81800 | 2 Par Avisverifies, Wordpress | 2 Verified Reviews (avis Vérifiés), Wordpress | 2026-09-13 | 9.3 Critical |
| Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions. | ||||
| CVE-2026-81801 | 2 Udx Usability Dynamics, Wordpress | 2 Wp-stateless, Wordpress | 2026-09-13 | 8.1 High |
| Subscriber Settings Change in WP-Stateless <= 4.4.1 versions. | ||||
| CVE-2026-81804 | 2 Wordpress, Zain Hassan | 2 Wordpress, Zhbackup – Backup, Restore & Migration | 2026-09-13 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions. | ||||
| CVE-2026-81805 | 2 Siteskite, Wordpress | 2 Siteskite, Wordpress | 2026-09-13 | 8.1 High |
| Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions. | ||||
| CVE-2026-88924 | 2 Gnome, Redhat | 2 Gvfs, Enterprise Linux | 2026-09-13 | 7 High |
| A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root. | ||||
| CVE-2026-15417 | 1 Silicon Labs | 1 Silabser.sys Driver | 2026-09-13 | N/A |
| In the silabser.sys Windows 8 driver for CP210x devices, a local unprivileged user can use incorrect driver settings to cause a kernel crash. | ||||
| CVE-2026-15418 | 1 Silicon Labs | 1 Silabser.sys Driver | 2026-09-13 | N/A |
| In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. This vulnerability affects Windows 10 and earlier. | ||||
| CVE-2026-90583 | 1 Kagisearch | 1 Smallweb | 2026-09-13 | 4.3 Medium |
| A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulation of the argument qs results in cross site scripting. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The patch is named 00b68144e583f20a6b67e29cf01bc07f57979ffb. It is recommended to apply a patch to fix this issue. Exploitability requires a raw HTTP request carrying unencoded double-quote characters in the query string - Werkzeug's request.query_string returns the raw request-target, and ordinary browsers percent-encode " as %22, so the payload only lands via netcat/curl-style raw sockets. | ||||