Export limit exceeded: 404102 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404102 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-108602 | 2026-10-10 | 4.3 Medium | ||
| Helicone through v2025.08.21-1 contains a server-side request forgery vulnerability in the Jawn webhook sender that allows authenticated organization users to reach internal services by using hostnames resolving to private addresses. Attackers can create webhooks with public hostnames that resolve or DNS-rebind to loopback or internal addresses, causing blind POST requests to internal HTTPS services. | ||||
| CVE-2026-27350 | 1 Builderius.io | 1 Builderius | 2026-10-10 | 7.2 High |
| Server-Side Request Forgery (SSRF) vulnerability in Builderius.io Builderius allows Server Side Request Forgery. This issue affects Builderius: from 1.4 through 1.4-beta. | ||||
| CVE-2026-66480 | 2026-10-10 | 5.3 Medium | ||
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in YITH YITH WooCommerce Product Add-Ons allows Retrieve Embedded Sensitive Data. This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.34.0. | ||||
| CVE-2026-57742 | 1 Themerex Group | 1 Kids Planet | 2026-10-10 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group Kids Planet allows Reflected XSS. This issue affects Kids Planet: from n/a through 2.2.14.2. | ||||
| CVE-2026-81797 | 2026-10-10 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme <= 1.0.2 versions. | ||||
| CVE-2026-78535 | 2026-10-10 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions. | ||||
| CVE-2026-78534 | 2026-10-10 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Educavo <= 3.4.2 versions. | ||||
| CVE-2026-78533 | 2026-10-10 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Qwery <= 3.6.1 versions. | ||||
| CVE-2026-78532 | 2026-10-10 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in LMS <= 8.3 versions. | ||||
| CVE-2026-78531 | 2026-10-10 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Jacqueline <= 2.22 versions. | ||||
| CVE-2026-78530 | 2026-10-10 | 7.7 High | ||
| Subscriber Arbitrary File Deletion in FoodBakery <= 4.6 versions. | ||||
| CVE-2026-78529 | 2026-10-10 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Alliance <= 3.11 versions. | ||||
| CVE-2026-66569 | 2026-10-10 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Kicker <= 2.2.1 versions. | ||||
| CVE-2026-66568 | 2026-10-10 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Original <= 1.9.0 versions. | ||||
| CVE-2026-66567 | 2026-10-10 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Anesta <= 1.5.3 versions. | ||||
| CVE-2026-66566 | 2026-10-10 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Ambient <= 1.7 versions. | ||||
| CVE-2026-66565 | 2026-10-10 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in FC United <= 1.1.1 versions. | ||||
| CVE-2026-66564 | 2026-10-10 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in ShiftCV <= 3.0.14 versions. | ||||
| CVE-2026-66563 | 2026-10-10 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Windsor <= 2.10 versions. | ||||
| CVE-2026-66483 | 2026-10-10 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Education Center <= 3.6.12 versions. | ||||