Search

Search Results (391055 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-78302 1 Joomshaper.com 1 Sp Property Extension For Joomla 2026-09-13 N/A
Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rendered attributes and text values directly into HTML without contextual escaping.
CVE-2026-78085 1 Joomshaper.com 1 Sp Property Extension For Joomla 2026-09-13 N/A
Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks.
CVE-2026-84828 1 Redhat 5 Enterprise Linux, Openshift, Openshift Container Platform and 2 more 2026-09-13 6.5 Medium
A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the files are shorter than 256 bytes. The file contents are read with root privileges by the pcsd daemon and can be exfiltrated by the attacker through subsequent cluster node communication. This allows disclosure of sensitive data such as API keys, tokens, or configuration secrets that would otherwise be inaccessible to the attacker.
CVE-2026-9161 1 Dernekplus 1 Website Template 2026-09-13 5.3 Medium
Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting. This issue affects Website Template: through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-88038 1 Pillarjs 1 Cookies 2026-09-13 4.8 Medium
cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator, but the domain and path options are checked only against a permissive RFC 7230 field-content matcher that allows semicolons, and both are written into the Set-Cookie header unescaped. An application that passes untrusted or request-derived data into the domain or path option can therefore inject additional cookie attributes, overriding SameSite, Secure, HttpOnly, or Domain on the cookies the application issues. This is a Set-Cookie attribute injection issue (CWE-74). The issue is fixed in cookies 0.9.2, which validates domain and path against RFC 6265 character sets. As a workaround, keep domain and path application-set rather than derived from untrusted input.
CVE-2026-85544 1 Hikvision 13 Ds-kd8003, Ds-kd8005, Ds-kv6103 and 10 more 2026-09-13 5.2 Medium
There is an Improper Encryption Configuration Vulnerability in some Hikvision Intercom Products. This could allow attackers to forge M1 cards.
CVE-2026-85545 1 Hikvision 1 Hikcentral Access Control 2026-09-13 7.1 High
There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that their role is not authorized to access.
CVE-2026-85543 1 Hikvision 1 Wi-fi Series Camera 2026-09-13 4.3 Medium
Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces.
CVE-2026-12683 1 Ankaref Innovation And Technology Inc. 1 Librid/libref 2026-09-13 5.4 Medium
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-6285 1 Ankaref Innovation And Technology Inc. 1 Librid/libref 2026-09-13 7.5 High
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-12682 1 Ankaref Innovation And Technology Inc. 1 Librid/libref 2026-09-13 5.4 Medium
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-81783 2 Mailmunch, Wordpress 2 Mailmunch – Grow Your Email List, Wordpress 2026-09-13 7.1 High
Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.
CVE-2026-81791 2 Ashan Perera, Wordpress 2 Eventon, Wordpress 2026-09-13 6.5 Medium
Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions.
CVE-2026-81794 2 Mlfactory, Wordpress 2 Shirt Product Designer For Woocommerce, Wordpress 2026-09-13 7.5 High
Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.
CVE-2026-81795 2 Denis Botić, Wordpress 2 Page Visits Counter – Lite, Wordpress 2026-09-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter &#8211; Lite <= 1.2.3 versions.
CVE-2026-81800 2 Par Avisverifies, Wordpress 2 Verified Reviews (avis Vérifiés), Wordpress 2026-09-13 9.3 Critical
Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.
CVE-2026-81801 2 Udx Usability Dynamics, Wordpress 2 Wp-stateless, Wordpress 2026-09-13 8.1 High
Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.
CVE-2026-81804 2 Wordpress, Zain Hassan 2 Wordpress, Zhbackup – Backup, Restore & Migration 2026-09-13 7.5 High
Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration <= 2.4.2 versions.
CVE-2026-81805 2 Siteskite, Wordpress 2 Siteskite, Wordpress 2026-09-13 8.1 High
Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.
CVE-2026-88924 2 Gnome, Redhat 2 Gvfs, Enterprise Linux 2026-09-13 7 High
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root.