Export limit exceeded: 402719 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402719 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-25273 | 1 Qualcomm | 1 Snapdragon | 2026-10-07 | 6.7 Medium |
| Memory Corruption when processing camera operations due to out-of-bounds write during driver updates. | ||||
| CVE-2026-15894 | 1 Zephyrproject | 1 Zephyr | 2026-10-07 | 8.8 High |
| The Bluetooth Mesh On-Demand Private Proxy solicitation handler in subsys/bluetooth/mesh/solicitation.c copies a received Solicitation PDU into a fixed 17-byte stack buffer without bounding the source length. In sol_pdu_decrypt(), out is allocated as NET_BUF_SIMPLE(17) and then filled with net_buf_simple_add_mem(out, in->data, in->len); net_buf_simple_add() guards its tailroom only with __ASSERT_NO_MSG, which is compiled out in production builds, so when in->len > 17 the underlying memcpy writes attacker-controlled bytes past the 17-byte stack buffer. The copy occurs before any decryption or authentication, so no key material is required to trigger it. The oversized length arises because the mesh scan callback in subsys/bluetooth/mesh/adv.c calls net_buf_simple_restore() before dispatching to bt_mesh_sol_recv(), leaving buf->len covering the entire remaining advertising payload rather than just the Solicitation Service Data. After the parser locates the Service Data AD and consumes the Identification Type byte, the remaining buf->len is the 17-octet Network PDU plus any trailing advertising bytes, and prior to this fix there was no maximum-length check (only a minimum). An attacker can therefore append extra AD structures or padding after the Solicitation Service Data to make buf->len exceed 17. bt_mesh_scan_cb() is registered directly as the BLE scan callback, so buf is raw, unauthenticated advertising data received over the air. Any device in radio range can send a non-connectable advertisement carrying a crafted mesh Proxy Solicitation to a node that has CONFIG_BT_MESH_OD_PRIV_PROXY_SRV enabled and is currently eligible to be solicited (GATT proxy disabled, On-Demand Private Proxy enabled), with no pairing, bonding, or provisioning. The result is an attacker-controlled stack overwrite — plausibly leading to remote code execution and at minimum a reliable remote denial of service. The fix trims buf->len to the spec-fixed 17 octets (dropping the PDU if fewer remain) before decryption. | ||||
| CVE-2026-97354 | 2026-10-07 | 4.1 Medium | ||
| The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-supplied media URL, allowing users with the contributor role and above to perform Server-Side Request Forgery attacks against internal services. | ||||
| CVE-2026-97294 | 2026-10-07 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.41. | ||||
| CVE-2026-97188 | 2026-10-07 | 8.8 High | ||
| The String locator WordPress plugin before 2.6.8 does not restrict the classes allowed when deserializing the content of a database row saved through its database editor, allowing unauthenticated attackers to store a serialized PHP object that is instantiated when an administrator later opens and saves that row. If a suitable POP chain is present via another installed String locator WordPress plugin before 2.6.8 or , this can lead to arbitrary file deletion, sensitive data disclosure or remote code execution. | ||||
| CVE-2026-87971 | 2026-10-07 | 7.1 High | ||
| The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link. | ||||
| CVE-2026-87782 | 2026-10-07 | 8.8 High | ||
| The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role. | ||||
| CVE-2026-86833 | 2026-10-07 | 5.4 Medium | ||
| The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, allowing unauthenticated attackers to inject arbitrary markup into the administrator and submitter notification emails the site sends. | ||||
| CVE-2026-86816 | 2026-10-07 | 5.3 Medium | ||
| The WPCafe WordPress plugin before 3.0.21 does not restrict access to some of its REST API endpoints, allowing unauthenticated attackers to read WooCommerce product data, including per-product sales counts, exact stock levels, and private product meta, that WooCommerce itself keeps behind authentication. | ||||
| CVE-2026-82211 | 2026-10-07 | 8.2 High | ||
| The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing attackers to mark arbitrary orders as paid or failed, to cancel them, and to obtain order keys which expose guest buyers' details. | ||||
| CVE-2026-27434 | 2026-10-07 | 5.3 Medium | ||
| Missing Authorization vulnerability in sc Internet Vivoo WP Rentals wprentals allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Rentals: from n/a through 3.14.2. | ||||
| CVE-2026-105884 | 2026-10-07 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media Rocket Lazy Load rocket-lazy-load allows Stored XSS.This issue affects Rocket Lazy Load: from n/a through 2.4.0. | ||||
| CVE-2026-105876 | 2026-10-07 | 5.3 Medium | ||
| Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Retrieve Embedded Sensitive Data.This issue affects Modula Image Gallery: from n/a through 3.0.11. | ||||
| CVE-2026-105875 | 2026-10-07 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Prime Slider – Addons For Elementor bdthemes-prime-slider-lite allows Stored XSS.This issue affects Prime Slider – Addons For Elementor: from n/a through 4.6.2. | ||||
| CVE-2026-105873 | 2026-10-07 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 8.8.6. | ||||
| CVE-2026-105871 | 2026-10-07 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 8.8.6. | ||||
| CVE-2026-105316 | 2026-10-07 | 7.1 High | ||
| The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting. | ||||
| CVE-2026-104953 | 2026-10-07 | 6.8 Medium | ||
| The MPG WordPress plugin before 4.2.3 does not properly validate the structure of imported project data before using it in a database query, allowing users with the Editor role or higher to perform SQL injection attacks and read sensitive data such as password hashes. | ||||
| CVE-2026-104678 | 2026-10-07 | 2.7 Low | ||
| The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that should require administrator access. | ||||
| CVE-2026-104667 | 2026-10-07 | 6.8 Medium | ||
| The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the counter, leading to second-order SQL injection that can read arbitrary data including password hashes. | ||||