Export limit exceeded: 403584 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403584 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-107446 | 1 Containerd | 1 Overlaybd | 2026-10-09 | 6.8 Medium |
| containerd overlaybd through 1.0.18 has a do_load_index (LSMT index loading) integer overflow (and resultant out-of-bounds heap access) for index_bytes, if an untrusted overlaybd blob from a registry is used in a scenario with multiple overlaybd-backed containers. | ||||
| CVE-2026-107444 | 2 Katello, Redhat | 4 Katello, Hardened Images, Hummingbird and 1 more | 2026-10-09 | 4.3 Medium |
| A flaw was found in Katello where the Docker Tags repositories API does not properly enforce organization scoping when listing repositories for a Docker meta tag. An authenticated user with permission to view products in one organization may be able to retrieve repository metadata associated with Docker tags belonging to another organization by supplying the tag identifier. This can result in unauthorized disclosure of repository configuration information across organization boundaries. | ||||
| CVE-2026-107445 | 2 Katello, Redhat | 4 Katello, Hardened Images, Hummingbird and 1 more | 2026-10-09 | 5.4 Medium |
| A flaw was found in Katello where the Flatpak Remote Repositories API does not properly enforce authorization when accessing a flatpak remote repository by identifier. An authenticated user with permission to view flatpak remotes in one organization may be able to access flatpak remote repository information belonging to another organization. The same unscoped lookup is used by the mirror action, which may allow creating a repository in a product the user can edit that is configured with another organization's flatpak remote URL and stored remote credentials. | ||||
| CVE-2026-107448 | 1 Wizards Of The Coast | 1 Magic The Gathering Arena | 2026-10-09 | 3.4 Low |
| Magic: The Gathering Arena (Windows/Steam client; 2026.59.30.12801.127931.6 and certain later 2026.60.x builds) passes a server-supplied URL from a home-screen carousel GoToExternalUrl action directly to the Windows shell via Application.OpenURL/ShellExecuteW without validating the URI scheme or domain. A hypothetical attacker able to control the carousel content delivered to clients can cause arbitrary registered URI-scheme handlers to be invoked on client hosts with no user interaction. For example, one might expect that the carousel content only has https: URIs, not ms-calculator: URIs. | ||||
| CVE-2026-17196 | 2 Webrehab, Wordpress-extensions | 2 Super Forms – Drag & Drop Form Builder, Super Forms | 2026-10-09 | 8.8 High |
| The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 6.3.316 via the upload_files function. This is due to missing file type validation in the upload_files function, which reads and applies an attacker-controlled extensions string from _super_elements post meta verbatim as the allowed MIME type map. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. The attack requires a preceding step: poisoning the _super_elements post meta via the super_save_form AJAX handler, which lacks a capability and nonce check but requires the attacker to be authenticated as at minimum a Subscriber-level user; the subsequent file upload via super_upload_files requires no authentication at all. | ||||
| CVE-2026-17609 | 2 Webrehab, Wordpress-extensions | 2 Super Forms – Drag & Drop Form Builder, Super Forms | 2026-10-09 | 9.1 Critical |
| The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the trailing slash. This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server, including the WordPress root directory. Exploitation requires that an administrator has enabled the 'Delete files from server after form submissions' setting, though this is a documented and commonly-enabled feature. | ||||
| CVE-2026-107450 | 1 Stumpapp | 1 Stump | 2026-10-09 | 5.4 Medium |
| In Stump through 0.1.10, the updateSmartList and deleteSmartList GraphQL mutations (crates/graphql/src/mutation/smart_lists.rs) depend only on the shared AccessSmartList permission and resolve the target list at Reader access (lacking a creator check). Any authenticated user with that permission can overwrite, delete, or take over another user's smart list. (updateSmartList sets creatorId to the caller identity, and can set visibility to PRIVATE, locking out the original owner.) NOTE: this is unrelated to the graphql crate on crates.io. | ||||
| CVE-2026-107459 | 1 Openfind | 1 Secushare Pro | 2026-10-09 | 9.8 Critical |
| The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server. | ||||
| CVE-2026-103309 | 1 Wordpress-extensions | 1 Gptranslate | 2026-10-09 | 7.5 High |
| The GPTranslate WordPress plugin before 2.34.14 does not properly restrict who can store translations, and does not escape them when outputting them in translated pages, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks when server-side translations are enabled. | ||||
| CVE-2026-103646 | 1 Wordpress-extensions | 1 Ultimate Multisite | 2026-10-09 | 9.8 Critical |
| The Ultimate Multisite WordPress plugin before 2.17.0 does not require authentication before a logged-out checkout is linked to, and logged in as, an existing WordPress account matching the submitted email address, and its duplicate-account check normalizes that address differently from the lookup used to create the customer, so an unauthenticated attacker can log in as any existing user, including a Network Super Admin, whose email address they know. This bypass is not addressed by the 2.15.1 fix for CVE-2026-75957 and remains exploitable in all versions up to and including 2.16.1, the releases that fix was expected to cover. Exploitation requires a checkout form configured without a password field (auto-generated password) and a target account that has no existing customer record in the Ultimate Multisite WordPress plugin before 2.17.0. | ||||
| CVE-2026-103692 | 1 Wordpress-extensions | 1 Frontend Dashboard | 2026-10-09 | 9.8 Critical |
| The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class method with the request data, allowing unauthenticated users to take over any account, including administrators. | ||||
| CVE-2026-104645 | 1 Wordpress-extensions | 1 Image Photo Gallery Final Tiles Grid | 2026-10-09 | 2.7 Low |
| The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not properly verify authorization on several of its gallery and image management actions, checking ownership against a different object than the one being acted on, or omitting the check entirely, allowing any authenticated user with contributor-level access or above to clone, modify and reorder galleries and images belonging to other users and to write Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 metadata onto arbitrary posts they do not own. | ||||
| CVE-2026-104646 | 1 Wordpress-extensions | 1 Image Photo Gallery Final Tiles Grid | 2026-10-09 | 6.8 Medium |
| The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not sanitise several gallery configuration values that can be overridden through its gallery shortcode before printing them into an inline script block, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of anyone viewing the post, including an administrator previewing a pending submission. No gallery ownership is required: any gallery that already exists on the site can be referenced. | ||||
| CVE-2026-105193 | 1 Wordpress-extensions | 1 Booking Calendar | 2026-10-09 | 4.8 Medium |
| The Booking Calendar WordPress plugin before 11.8 does not generate its per-booking access hashes with sufficient entropy, deriving each from a low-entropy time-seeded value, which can allow unauthenticated attackers who are able to determine a booking's creation time to predict the hash and then read that booking's personal data or modify the booking in place. | ||||
| CVE-2026-105194 | 1 Wordpress-extensions | 1 Easy Digital Downloads | 2026-10-09 | 4.3 Medium |
| The Easy Digital Downloads WordPress plugin before 3.7.1 does not restrict a block's order data to the current user, allowing users with subscriber-level access to view other customers' recent order products and obtain signed download links that grant access to paid digital files without purchase. | ||||
| CVE-2026-105195 | 1 Wordpress-extensions | 1 Booking Calendar | 2026-10-09 | 2.7 Low |
| The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration. | ||||
| CVE-2026-105196 | 1 Wordpress-extensions | 1 Latepoint | 2026-10-09 | 3.3 Low |
| The Appointment Booking Plugin WordPress plugin before 5.6.9 does not enforce per-record authorization on several of its AI Abilities API actions, allowing an authenticated user holding the LatePoint Agent role, normally restricted to their own records, to read and modify other agents' profile data and read other agents' bookings and associated customer details when the Abilities API feature is enabled. | ||||
| CVE-2026-105197 | 1 Wordpress-extensions | 1 Latepoint | 2026-10-09 | 2.7 Low |
| The Appointment Booking Plugin WordPress plugin before 5.6.5 does not verify that a backend staff user is authorized to act on the specific record targeted for deletion, allowing an authenticated user with a record-scoped staff role to irreversibly delete any order, customer, or transaction on the site, including records belonging to other staff and outside their assigned scope. | ||||
| CVE-2026-105198 | 1 Wordpress-extensions | 1 Latepoint | 2026-10-09 | 5.3 Medium |
| The Appointment Booking Plugin WordPress plugin before 5.7.3 does not verify that the caller owns the order referenced by an order-item identifier before rendering that order's confirmation summary, letting an unauthenticated visitor retrieve any customer's name, contact details and order confirmation code by supplying a sequential order-item id. | ||||
| CVE-2026-105260 | 1 Wordpress-extensions | 1 Database Addon For Wpforms | 2026-10-09 | 4.3 Medium |
| The Database Addon For WPForms ( wpforms entries ) WordPress plugin before 1.1.1 does not verify the CSRF nonce when the field is omitted and performs no capability check of its own, allowing attackers to delete arbitrary stored form entries by tricking a logged-in administrator into loading a crafted page. | ||||