Export limit exceeded: 402502 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402502 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402502 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-106269 | 2026-10-06 | 8.8 High | ||
| Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106506 | 2026-10-06 | 5.3 Medium | ||
| Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list ordering. An authenticated Backstage user with permission to create and read relevant scaffolder tasks may be able to infer confidential task data under specific conditions. Successful exploitation requires retained task secrets, visibility of a target task, knowledge of the secret structure, and repeated requests. This issue is fixed in version 4.1.0. | ||||
| CVE-2026-106505 | 2026-10-06 | 7.7 High | ||
| Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by bypass of mkdocs configuration sanitizer in techdocs backend. Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer introduced in response to CVE-2026-25153 and execute arbitrary code on the TechDocs backend host during documentation generation. This issue is fixed in versions 1.14.6 and 1.15.4. | ||||
| CVE-2026-106504 | 2026-10-06 | 6.5 Medium | ||
| Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder task logs. An authenticated user who can create and read scaffolder tasks may be able to observe sensitive values in task logs in deployments with restrictive action permissions and affected templates. Exploitation requires a denied action whose input contains such a value. This issue is fixed in version 4.1.0. | ||||
| CVE-2026-39758 | 2 Midtrans, Wordpress-extensions | 2 Midtrans-woocommerce, Midtrans-woocommerce | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Midtrans-WooCommerce <= 2.32.3 versions. | ||||
| CVE-2026-39759 | 2 Amentotech, Wordpress-extensions | 2 Workreap, Workreap | 2026-10-06 | 9.9 Critical |
| Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions. | ||||
| CVE-2026-39761 | 2 Elightup, Wordpress-extensions | 2 Meta Box Aio, Meta Box Aio | 2026-10-06 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Meta Box AIO <= 3.7.1 versions. | ||||
| CVE-2026-39762 | 2 Patterns In The Cloud, Wordpress-extensions | 2 Autoship Cloud For Woocommerce Subscription Products, Autoship Cloud For Woocommerce Subscription Products | 2026-10-06 | 6.5 Medium |
| Missing Authorization vulnerability in Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products autoship-cloud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.17.1. | ||||
| CVE-2026-39764 | 2 Radiustheme, Wordpress-extensions | 2 Radius Booking — Booking Calendar For Appointments & Services, Radius Booking | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments & Services <= 1.0.19 versions. | ||||
| CVE-2026-39765 | 2 Webappick, Wordpress-extensions | 2 Challan, Challan | 2026-10-06 | 7.2 High |
| Shop Manager Privilege Escalation in Challan <= 3.7.88 versions. | ||||
| CVE-2026-39766 | 2 Reputeinfosystems, Wordpress-extensions | 2 Arforms, Arforms | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions. | ||||
| CVE-2026-39767 | 2 Baseapp, Wordpress-extensions | 2 Wpbase Cache, Wpbase Cache | 2026-10-06 | 6.5 Medium |
| Subscriber Denial of Service Attack in WPBase Cache <= 5.5.6 versions. | ||||
| CVE-2026-39768 | 2 Cleantalk, Wordpress-extensions | 2 Security & Malware Scan, Security & Malware Scan By Cleantalk | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Security & Malware scan by CleanTalk <= 2.189 versions. | ||||
| CVE-2026-39769 | 2 Iqonicdesign, Wordpress-extensions | 2 Graphina, Graphina | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions. | ||||
| CVE-2026-39770 | 2 Amentotech, Wordpress-extensions | 2 Doctreat Core, Doctreat | 2026-10-06 | 10 Critical |
| Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions. | ||||
| CVE-2026-39771 | 2 Mightynetworks Vs Buddyboss, Wordpress-extensions | 2 Buddyboss Platform, Buddyboss Platform | 2026-10-06 | 8.5 High |
| Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions. | ||||
| CVE-2026-39772 | 2 Bestwebsoft, Wordpress-extensions | 2 Captcha By Bestwebsoft, Captcha By Bestwebsoft | 2026-10-06 | 5.3 Medium |
| Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions. | ||||
| CVE-2026-39773 | 2 Amentotech, Wordpress-extensions | 2 Doctreat Core, Doctreat Core | 2026-10-06 | 10 Critical |
| Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions. | ||||
| CVE-2026-39774 | 2 Tourfic Ai Studio, Wordpress-extensions | 2 Tourfic Pro, Tourfic Pro | 2026-10-06 | 8.8 High |
| Unauthenticated Privilege Escalation in Tourfic Pro <= 1.17.3 versions. | ||||
| CVE-2026-39775 | 2 Dexignzone, Wordpress-extensions | 2 Jobzilla - Job Board Wordpress Theme, Jobzilla | 2026-10-06 | 8.8 High |
| Subscriber Privilege Escalation in JobZilla - Job Board WordPress Theme <= 2.2 versions. | ||||