Search
Search Results (400454 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-79899 | 2026-10-01 | 7.9 High | ||
| Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation. | ||||
| CVE-2026-102580 | 1 Moodle | 1 Moodle | 2026-10-01 | 2.2 Low |
| A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may result in unexpected application behavior. | ||||
| CVE-2026-103347 | 2026-10-01 | 5.3 Medium | ||
| Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions. | ||||
| CVE-2026-103068 | 2026-10-01 | 8.8 High | ||
| Subscriber Privilege Escalation in ByteCoreStack – MCP Connector for AI Tools <= 1.2.2 versions. | ||||
| CVE-2026-102378 | 2026-10-01 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions. | ||||
| CVE-2026-100517 | 2026-10-01 | 7.5 High | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions. | ||||
| CVE-2026-100514 | 2026-10-01 | 7.5 High | ||
| Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions. | ||||
| CVE-2026-97297 | 2026-10-01 | 7.6 High | ||
| Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions. | ||||
| CVE-2026-97284 | 2026-10-01 | 8.8 High | ||
| Contributor PHP Object Injection in Icegram <= 3.1.31 versions. | ||||
| CVE-2026-97281 | 2026-10-01 | 6.3 Medium | ||
| Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions. | ||||
| CVE-2026-97277 | 2026-10-01 | 7.6 High | ||
| Subscriber Broken Access Control in Social Boost <= 3.6.2 versions. | ||||
| CVE-2026-97273 | 2026-10-01 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions. | ||||
| CVE-2026-97269 | 2026-10-01 | 6.5 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions. | ||||
| CVE-2026-97268 | 2026-10-01 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions. | ||||
| CVE-2026-97260 | 2026-10-01 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions. | ||||
| CVE-2026-97258 | 2026-10-01 | 6.5 Medium | ||
| Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions. | ||||
| CVE-2026-97251 | 2026-10-01 | 6.5 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions. | ||||
| CVE-2026-95588 | 2026-10-01 | 8.6 High | ||
| Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions. | ||||
| CVE-2026-94390 | 2026-10-01 | 7.2 High | ||
| Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions. | ||||
| CVE-2026-62073 | 2026-10-01 | 7.5 High | ||
| Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions. | ||||