Export limit exceeded: 396891 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (396891 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-58268 | 1 Emiago | 1 Sipgo | 2026-09-23 | 7.5 High |
| SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.1, ParserStream.parseSingle in sip/parser_stream.go allocates a SIP body buffer from the client-controlled Content-Length header before ParseMaxMessageLength is enforced. An unauthenticated peer can send a stream-transport message over TCP, TLS, WS, or WSS with an oversized declared length, causing excessive memory allocation and denial of service before the body is read. This issue is fixed in version 1.4.1. | ||||
| CVE-2026-14913 | 1 Zohocorp | 2 Manageengine Firewall Analyzer, Manageengine Opmanager | 2026-09-23 | 8.8 High |
| ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports. | ||||
| CVE-2026-12370 | 1 Zohocorp | 3 Manageengine Netflow Analyzer, Manageengine Network Configuration Manager, Manageengine Opmanager | 2026-09-23 | 7.6 High |
| ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution. | ||||
| CVE-2026-86681 | 1 Zohocorp | 1 Manageengine Applications Manager | 2026-09-23 | 7.6 High |
| ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope. | ||||
| CVE-2026-73014 | 1 Microsoft | 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more | 2026-09-23 | 7.8 High |
| Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-73018 | 1 Microsoft | 27 Graphics Component, Windows 10 1607, Windows 10 1809 and 24 more | 2026-09-23 | 8.8 High |
| Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-95676 | 1 Watchguard | 1 Authpoint Authentication Gateway | 2026-09-23 | N/A |
| A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply. | ||||
| CVE-2026-96446 | 1 Redhat | 2 Build Keycloak, Red Hat Single Sign On | 2026-09-23 | 4.2 Medium |
| A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent authentication path prompt=none is used, which allows the authorization process to skip certain steps if a user is already logged in. Due to this bypass, the security rule that ensures a pushed request URI is used only once is not enforced. An attacker could potentially reuse a request URI to obtain multiple authorization codes for a user who is already signed in, violating security standards like FAPI-2. | ||||
| CVE-2026-22554 | 1 Mediaarea | 2 Mediainfo, Mediainfolib | 2026-09-23 | 7.8 High |
| A heap-based buffer overflow vulnerability exists in the Channel Splitting functionality of MediaInfoLib (version(s): 26.01). A specially crafted .riff file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | ||||
| CVE-2026-77006 | 2026-09-23 | 9.6 Critical | ||
| The WebTotem Backups WordPress plugin before 1.1.0 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover. | ||||
| CVE-2026-25713 | 1 Mediaarea | 2 Mediainfo, Mediainfolib | 2026-09-23 | 7.8 High |
| A heap-based buffer overflow vulnerability exists in the ID3v2 parsing functionality of MediaInfoLib (version(s): 26.01). A specially crafted media file that contains ID3v2 tags can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | ||||
| CVE-2026-77762 | 2026-09-23 | N/A | ||
| Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat allows an attacker to inject trailer fields into another HTTP/2 request. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.39 through 9.0.121. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60, 9.0.122, which fix the issue. | ||||
| CVE-2026-93528 | 2026-09-23 | 3.7 Low | ||
| The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key. | ||||
| CVE-2026-93511 | 2026-09-23 | 5.3 Medium | ||
| The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment and subscription notifications, allowing unauthenticated attackers to forge payment confirmations and subscription-cancellation events against any order whose transaction id they know. | ||||
| CVE-2026-93510 | 2026-09-23 | 4.3 Medium | ||
| The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or restrict who can call its Win Wheel claim handler, allowing authenticated users, Subscriber and above, to credit their own account with an arbitrary and unlimited amount of loyalty points and, where a companion wallet Points and Rewards for WooCommerce WordPress plugin before 2.10.4 is active, wallet balance. | ||||
| CVE-2026-93508 | 2026-09-23 | 8.1 High | ||
| The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to manipulate stored pricing rules on a product to reduce its checkout price. | ||||
| CVE-2026-93507 | 2026-09-23 | 3.3 Low | ||
| The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy. | ||||
| CVE-2026-91077 | 2026-09-23 | 2.7 Low | ||
| The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to read, so users with contributor-level access and above can retrieve other authors' private, draft and trashed events, together with event detail the standard listing does not show them. This discloses private events and their content that WordPress withholds from users lacking the read_private_posts capability. | ||||
| CVE-2026-91073 | 2026-09-23 | 6.8 Medium | ||
| The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who views a page embedding the form, including logged-out visitors and administrators. | ||||
| CVE-2026-91025 | 2026-09-23 | 4.3 Medium | ||
| The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated user with subscriber-level access and above to create or overwrite the Booking Manager WordPress plugin before 2.1.21's per-user settings on arbitrary users, including administrators. | ||||