Export limit exceeded: 400994 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400994 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400994 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103336 | 2 Smackcoders, Wordpress-extensions | 2 Wp Ultimate Csv Importer, Wp Ultimate Csv Importer | 2026-10-01 | 5.3 Medium |
| Insertion of Sensitive Information Into Sent Data vulnerability in Smackcoders Inc. WP Ultimate CSV Importer wp-ultimate-csv-importer allows Retrieve Embedded Sensitive Data.This issue affects WP Ultimate CSV Importer: from n/a through 9.1. | ||||
| CVE-2026-103339 | 2 Wordpress-extensions, Wpmet | 2 Metform, Metform | 2026-10-01 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet Metform metform allows Stored XSS.This issue affects Metform: from n/a through 4.3.0. | ||||
| CVE-2026-62063 | 2 Magepeople, Wordpress-extensions | 2 Wptravelly, Wptravelly | 2026-10-01 | 5.4 Medium |
| Missing Authorization vulnerability in Magepeople inc. WpTravelly tour-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpTravelly: from n/a through 2.3.1. | ||||
| CVE-2026-66246 | 1 Hcltech | 1 Icontrol | 2026-10-01 | 8.8 High |
| iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege escalation and the unauthorized modification or deletion of sensitive application data. | ||||
| CVE-2026-66248 | 1 Hcltech | 1 Icontrol | 2026-10-01 | 3.1 Low |
| iControl is affected by an Improper Error Handling vulnerability, which could allow an unauthenticated attacker to trigger verbose database and system errors, enabling the disclosure of sensitive internal infrastructure details used to plan advanced targeted attacks. | ||||
| CVE-2026-66249 | 1 Hcltech | 1 Icontrol | 2026-10-01 | 3.1 Low |
| iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers. | ||||
| CVE-2026-66253 | 1 Hcltech | 1 Icontrol | 2026-10-01 | 3.1 Low |
| iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an unattended or abandoned active session, enabling unauthorized access to the application and the ability to perform actions on behalf of the victim. | ||||
| CVE-2026-18734 | 2026-10-01 | N/A | ||
| ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage. | ||||
| CVE-2026-97443 | 1 Linux | 1 Linux Kernel | 2026-10-01 | 5.5 Medium |
| In the Linux kernel, the following vulnerability has been resolved: perf/ftrace: Fix WARNING in __unregister_ftrace_function perf_ftrace_function_unregister() unconditionally calls unregister_ftrace_function() without checking whether the ftrace_ops was ever successfully registered. This triggers a WARN_ON in __unregister_ftrace_function() when the ops doesn't have FTRACE_OPS_FL_ENABLED set. This can happen during perf_event_alloc() error cleanup when perf_trace_destroy() is called via __free_event() on an event whose ftrace_ops registration failed or was already torn down by perf_try_init_event()'s err_destroy path. The call path is: perf_event_alloc() error cleanup -> __free_event() -> event->destroy() [tp_perf_event_destroy] -> perf_trace_destroy() -> perf_trace_event_close() -> TRACE_REG_PERF_CLOSE -> perf_ftrace_function_unregister() -> unregister_ftrace_function() -> __unregister_ftrace_function() -> WARN_ON(!(ops->flags & FTRACE_OPS_FL_ENABLED)) Fix this by checking FTRACE_OPS_FL_ENABLED before attempting to unregister. If the ops is not enabled, just free the filter and return success. | ||||
| CVE-2026-102378 | 2026-10-01 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions. | ||||
| CVE-2026-102717 | 1 Eclipse | 1 Threadx Netx Duo | 2026-10-01 | 7.5 High |
| MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash | ||||
| CVE-2026-102089 | 1 Kiteworks | 1 Kiteworks Email Protection Gateway | 2026-10-01 | 7.2 High |
| Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system. | ||||
| CVE-2026-102094 | 1 Kiteworks | 1 Kiteworks Email Protection Gateway | 2026-10-01 | 7.2 High |
| Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not sufficiently restrict the code that the mail-processing pipeline could load from an imported rule configuration. An authenticated administrator with mail-rule configuration privileges could cause the gateway to load and execute code beyond the approved set of mail-processing components, potentially in the context of the mail-gateway service account. | ||||
| CVE-2026-102095 | 1 Kiteworks | 1 Kiteworks Email Protection Gateway | 2026-10-01 | 9.1 Critical |
| Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the message content it processed, without adequately restricting the fetch destination. A remote, unauthenticated sender could craft a message that caused the gateway to issue requests to internal services and cloud instance metadata endpoints and return the responses, potentially disclosing sensitive internal data and, depending on the internal service reached, affecting its state. | ||||
| CVE-2026-102097 | 1 Kiteworks | 1 Kiteworks Email Protection Gateway | 2026-10-01 | 7.2 High |
| Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose contents were not sufficiently validated before being processed. A crafted submission could potentially allow arbitrary commands to be executed on the affected gateway. | ||||
| CVE-2026-102146 | 1 Kiteworks | 1 Kiteworks Email Protection Gateway | 2026-10-01 | 6.5 Medium |
| An authenticated Email Protection Gateway administrator holding only limited, delegated permissions could write files with attacker-controlled content to arbitrary locations accessible to the Email Protection Gateway service account. This exceeds the administrator's intended privileges and could be used to alter application files and configuration or to disrupt the availability of the service. | ||||
| CVE-2026-102149 | 1 Kiteworks | 1 Kiteworks Email Protection Gateway | 2026-10-01 | 9.4 Critical |
| Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is enabled, potentially permitting unauthorized access to the account. | ||||
| CVE-2026-102139 | 1 Kiteworks | 1 Kiteworks Email Protection Gateway | 2026-10-01 | 6.5 Medium |
| An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read the subject, message body, and attachments of packages they neither sent nor received. | ||||
| CVE-2026-102135 | 1 Kiteworks | 1 Kiteworks Email Protection Gateway | 2026-10-01 | 6.6 Medium |
| On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially allowing code execution as the gateway service account. Replication is disabled by default, and exploitation requires control of a trusted cluster peer or administrative access to the appliance. | ||||
| CVE-2026-102102 | 1 Kiteworks | 1 Kiteworks Email Protection Gateway | 2026-10-01 | 9.1 Critical |
| Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves an issuer certificate in an inbound message. Depending on the services reachable from the gateway, this could disclose sensitive internal information or disrupt gateway operation. | ||||