Export limit exceeded: 403624 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403624 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-78340 | 2026-10-09 | 6.3 Medium | ||
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Filesystem access for attacker. | ||||
| CVE-2026-78341 | 2026-10-09 | 6.5 Medium | ||
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges and Unauthorized access. | ||||
| CVE-2026-98382 | 1 Linux | 1 Linux Kernel | 2026-10-09 | N/A |
| In the Linux kernel, the following vulnerability has been resolved: bpf: Reject dev-bound-only programs on other devices __bpf_offload_dev_match() falls back to comparing offdev pointers after an exact netdev mismatch. Bound-only programs normally have NULL offdevs, so unrelated netdevs compare equal. A bound-only program on an offload-registered netdev can instead inherit a real offdev and match a sibling port. With CAP_BPF and CAP_NET_ADMIN, a caller can use bpf(BPF_LINK_CREATE) with a different target ifindex to run metadata kfuncs specialized for the bound driver on the target driver's xdp_buff. Running a veth-bound program on tun reads beyond tun's bare stack xdp_buff as a veth_xdp_buff. Oops: general protection fault, probably for non-canonical address KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017] RIP: 0010:veth_xdp_rx_timestamp (drivers/net/veth.c:1673) Call Trace: ... tun_build_skb (drivers/net/tun.c:1739) tun_get_user (drivers/net/tun.c:1856) tun_chr_write_iter (drivers/net/tun.c:2091) vfs_write (fs/read_write.c:595 fs/read_write.c:687) ksys_write (fs/read_write.c:739) do_syscall_64 (arch/x86/entry/syscall_64.c:84) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Kernel panic - not syncing: Fatal exception in interrupt Restrict non-offloaded programs to exact netdev matches and retain the shared-offdev fallback only for genuinely offloaded multi-port programs. | ||||
| CVE-2025-60201 | 2 Aguilatechnologies, Wordpress | 2 Wp Customer Area, Wordpress | 2026-10-09 | 7.5 High |
| Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in aguilatechnologies WP Customer Area customer-area allows PHP Local File Inclusion. This issue affects WP Customer Area: before 8.3.4. | ||||
| CVE-2025-1647 | 2026-10-09 | 5.6 Medium | ||
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap allows Cross-Site Scripting (XSS).This issue affects Bootstrap: from 3.4.1 before 4.0.0. | ||||
| CVE-2026-93947 | 2026-10-09 | 9.3 Critical | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through 3.2.9. | ||||
| CVE-2026-94158 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bkninja Gloria Admin Panel gloria-admin-panel allows Reflected XSS.This issue affects Gloria Admin Panel: from n/a through 1.3. | ||||
| CVE-2026-94503 | 2026-10-09 | 10 Critical | ||
| Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows Upload a Web Shell to a Web Server.This issue affects Zombify: from n/a through 1.7.7. | ||||
| CVE-2026-94161 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Reflected XSS.This issue affects Grand Restaurant: from n/a before 7.0.11. | ||||
| CVE-2026-94159 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KlbTheme Total Donations totaldonations allows Stored XSS.This issue affects Total Donations: from n/a through 2.0.5. | ||||
| CVE-2026-94167 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubio AI Page Builder kubio allows Reflected XSS.This issue affects Kubio AI Page Builder: from n/a through 2.9.3. | ||||
| CVE-2026-96334 | 2026-10-09 | 5.6 Medium | ||
| Missing Authorization vulnerability in ThemeGrill User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through 5.2.7. | ||||
| CVE-2026-94170 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Heateor Support Sassy Social Share sassy-social-share allows Reflected XSS.This issue affects Sassy Social Share: from n/a through 3.3.79. | ||||
| CVE-2026-94664 | 2026-10-09 | 7.5 High | ||
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org PDF for Contact Form 7 pdf-for-contact-form-7 allows Path Traversal.This issue affects PDF for Contact Form 7: from n/a through 7.1.0. | ||||
| CVE-2026-96607 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Reflected XSS.This issue affects NEX-Forms: from n/a through 9.3.1. | ||||
| CVE-2026-94666 | 2026-10-09 | 7.5 High | ||
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7 allows Path Traversal.This issue affects Generate PDF using Contact Form 7: from n/a through 4.2.1. | ||||
| CVE-2026-96332 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yalla ya! Simple Payment simple-payment allows Reflected XSS.This issue affects Simple Payment: from n/a through 2.5.4. | ||||
| CVE-2026-95589 | 2026-10-09 | 6.5 Medium | ||
| Missing Authorization vulnerability in Magepeople inc. Deposits and Partial Payments for WooCommerce advanced-partial-payment-or-deposit-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Deposits and Partial Payments for WooCommerce: from n/a through 4.0.1. | ||||
| CVE-2026-94668 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Reflected XSS.This issue affects Salon booking system: from n/a through 10.31.5. | ||||
| CVE-2026-94667 | 2026-10-09 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetReviews jet-reviews allows Stored XSS.This issue affects JetReviews: from n/a through 3.1.2. | ||||