Export limit exceeded: 401009 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 401009 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (401009 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-91784 | 1 Cjbassi | 1 Gotop | 2026-10-02 | N/A |
| cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process with a crafted name beginning with -- (e.g. containing a target user's UID). When the user running gotop invokes the kill feature on that process, pkill interprets the crafted name as a command-line option, terminating all processes owned by the targeted user. Product is no longer actively supported and the vulnerabilities have not been fixed. Vulnerability was confirmed at version 3.0.0; other versions were not tested but may also be affected. | ||||
| CVE-2026-59669 | 1 Repasat | 1 Repasat Application | 2026-10-02 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “name” parameter is affected – endpoint “/es/attachmenttypes/update/203336” | ||||
| CVE-2026-80464 | 1 Havelsan | 1 Sef - Ai Chatbot Platform | 2026-10-02 | 4.9 Medium |
| Server-Side request forgery (SSRF) vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Server Side Request Forgery. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported. | ||||
| CVE-2026-80337 | 1 Havelsan | 1 Sef - Ai Chatbot Platform | 2026-10-02 | 5.3 Medium |
| Missing Authorization vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported. | ||||
| CVE-2026-59670 | 1 Repasat | 1 Repasat Application | 2026-10-02 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomListaValidacion” parameter is affected – endpoint “/es/validationslists/assignList/Employee/45659”. | ||||
| CVE-2026-80443 | 1 Havelsan | 1 Sef - Ai Chatbot Platform | 2026-10-02 | 7.4 High |
| Improper certificate validation vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Adversary in the Middle (AiTM). This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported. | ||||
| CVE-2026-59671 | 1 Repasat | 1 Repasat Application | 2026-10-02 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The endpoint “/es/datatables/getemployeetypesdatatable” is affected. | ||||
| CVE-2026-80298 | 1 Havelsan Inc. | 1 Sef - Ai Chatbot Platform | 2026-10-02 | 8.8 High |
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows SQL Injection. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported. | ||||
| CVE-2026-94635 | 1 Apache | 1 Thrift | 2026-10-02 | 7.5 High |
| Allocation of resources without limits or throttling, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||
| CVE-2026-59672 | 1 Repasat | 1 Repasat Application | 2026-10-02 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomGrupoEmpresarial” parameter is affected – endpoint "/es/corporategroups/update/246”. | ||||
| CVE-2026-94541 | 2 Amauri, Wordpress-extensions | 2 Wpmobile.app, Wpmobile.app | 2026-10-02 | 9.8 Critical |
| The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate password-reset URLs for arbitrary users, including administrators, mirrored into the push queue by the mail-to-push feature, and use those URLs to take over the targeted accounts. This exploit chain requires the plugin's mail-to-push feature (wpmobile_auto_mail=1) to be enabled, as that setting is what causes outbound WordPress password-reset emails — including the reset URL and key — to be mirrored into the push row queue where they become accessible to the attacker. | ||||
| CVE-2026-87920 | 2 Boldgrid, Wordpress-extensions | 2 W3 Total Cache, W3 Total Cache | 2026-10-02 | 7.2 High |
| The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Output-Buffer Regex Rewrite in all versions up to, and including, 2.10.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the 'Remove query strings from static resources' option is enabled in W3 Total Cache, as mutate_url() must strip the '?' delimiter and everything following it — including the closing quote of the outer attribute — to break the attribute boundary. | ||||
| CVE-2026-59659 | 1 Repasat | 1 Repasat Application | 2026-10-02 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomZonaGeo” parameter is affected – endpoint “/es/geozones/update/149979”. | ||||
| CVE-2026-59660 | 1 Repasat | 1 Repasat Application | 2026-10-02 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTransportista” parameter is affected – endpoint “/es/carriers/update”. | ||||
| CVE-2026-59661 | 1 Repasat | 1 Repasat Application | 2026-10-02 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomRuta” parameter is affected – endpoint “/es/routes/update/693”. | ||||
| CVE-2026-95662 | 1 Repasat | 1 Repasat Application | 2026-10-02 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomCompetidor” parameter is affected – endpoint “/es/competitors/store”. | ||||
| CVE-2026-59663 | 1 Repasat | 1 Repasat Application | 2026-10-02 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomDelegacion” parameter is affected – endpoint “/es/delegations/store”. | ||||
| CVE-2026-59664 | 1 Repasat | 1 Repasat Application | 2026-10-02 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomServicioPrestado” parameter is affected – endpoint “/es/providedservices/store”. | ||||
| CVE-2026-59662 | 1 Repasat | 1 Repasat Application | 2026-10-02 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomCompetidor” parameter is affected – endpoint “/es/competitors/store”. | ||||
| CVE-2026-59666 | 1 Repasat | 1 Repasat Application | 2026-10-02 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomOrigen” parameter is affected – endpoint “/es/origins/store”. | ||||