Export limit exceeded: 399985 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399985 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-96346 | 2026-09-30 | 7.6 High | ||
| Author SQL Injection in WP ERP <= 1.17.9 versions. | ||||
| CVE-2026-96345 | 2026-09-30 | 7.6 High | ||
| Administrator SQL Injection in Estatik <= 4.3.5 versions. | ||||
| CVE-2026-96344 | 2026-09-30 | 7.2 High | ||
| Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions. | ||||
| CVE-2026-96343 | 2026-09-30 | 7.2 High | ||
| Custom role PHP Object Injection in WP ERP <= 1.17.9 versions. | ||||
| CVE-2026-96338 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions. | ||||
| CVE-2026-95616 | 2026-09-30 | 7.5 High | ||
| An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. | ||||
| CVE-2026-95587 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions. | ||||
| CVE-2026-95531 | 2026-09-30 | 8.8 High | ||
| Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions. | ||||
| CVE-2026-94683 | 2026-09-30 | 8.8 High | ||
| Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions. | ||||
| CVE-2026-94681 | 2026-09-30 | 5.9 Medium | ||
| Unauthenticated Denial of Service Attack in WP Store Locator < 3.0.0 versions. | ||||
| CVE-2026-94678 | 2026-09-30 | 8.8 High | ||
| Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions. | ||||
| CVE-2026-94677 | 2026-09-30 | 7.2 High | ||
| Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions. | ||||
| CVE-2026-94674 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Pixel Manager for WooCommerce <= 1.69.0 versions. | ||||
| CVE-2026-94673 | 2026-09-30 | 5.3 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions. | ||||
| CVE-2026-94672 | 2026-09-30 | 4.3 Medium | ||
| Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions. | ||||
| CVE-2026-94499 | 2026-09-30 | 7.1 High | ||
| Subscriber Broken Access Control in FormGent <= 1.12.2 versions. | ||||
| CVE-2026-94389 | 2026-09-30 | 9 Critical | ||
| Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions. | ||||
| CVE-2026-94297 | 2026-09-30 | 2.7 Low | ||
| The Media Library Organizer WordPress plugin before 2.1.4 does not verify that the requesting user holds the target taxonomy's management capability before creating a new term, allowing users with contributor-level access and above to create publicly visible terms in any taxonomy registered on the site. | ||||
| CVE-2026-94274 | 2026-09-30 | 5.3 Medium | ||
| The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content. | ||||
| CVE-2026-94194 | 1 Elixir-mint | 1 Mint | 2026-09-30 | N/A |
| Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint client on a pooled connection, poisoning the responses to subsequent requests that share the connection. message_body/1 in lib/mint/http1.ex selects chunked framing when chunked is the first coding listed in a response's Transfer-Encoding fields. RFC 9112 section 6.3 applies chunked framing only when chunked is the final coding, and otherwise reads the body until the server closes the connection. For a response such as Transfer-Encoding: chunked, gzip, an intermediary that follows the RFC treats every byte up to the close as the body, while Mint ends the body at the zero-length chunk and parses the remaining bytes as the response to the next request on the connection. Mint also keeps the connection open after an HTTP/1.0 response, final or 1xx, that carries Transfer-Encoding and Connection: keep-alive. RFC 9112 section 6.1 requires treating the framing of such a message as faulty and closing the connection after it, so bytes after its chunked body are parsed as the response to the next request in the same way. This issue affects mint: from 0.1.0 before 1.10.2. | ||||