Export limit exceeded: 403798 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403798 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-90461 | 1 Openstack | 1 Ironic | 2026-10-09 | 6.3 Medium |
| OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication. | ||||
| CVE-2026-102782 | 1 Ordasoft.com | 1 Ordasoft Simple Membership Extension For Joomla | 2026-10-09 | N/A |
| Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 - site/simplemembership.php dispatches task=checkLoginPass with no authentication or access control check of any kind. The handler reads a login request parameter through Joomla’s generic, non-sanitizing input filter, which strips HTML/script tags but never touches quotes or SQL syntax, and concatenates it directly into a query string with no escaping or parameterization: | ||||
| CVE-2026-89417 | 2 Daanvandenbergh, Wordpress-extensions | 2 Omgf, Omgf | 2026-10-09 | 7.2 High |
| The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 's' Search Parameter via comments-atom Feed in all versions up to, and including, 6.3.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that the front-end server serves the retained .tmp file without a Content-Type or X-Content-Type-Options header, enabling MIME-sniffing browsers such as Chromium to execute the injected script — a condition present by default on many Apache and nginx/php-fpm deployments. | ||||
| CVE-2026-5703 | 2 Satel-iberia, Satel Iberia | 2 Sennet Datalogger Serie 200, Sennet Datalogger Serie 200 | 2026-10-09 | N/A |
| Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an authenticated user to read any file or list any directory accessible to the system user running the web server. This is possible by modifying the URL to include a path traversal payload. Successful exploitation of this vulnerability could allow an attacker to access critical system files containing confidential information. | ||||
| CVE-2026-92393 | 1 Apache | 1 Yunikorn | 2026-10-09 | N/A |
| Apache YuniKorn 1.9.0 and earlier does not implement label and user annotation checks for workload UPDATE action bypassing all checks. Workloads in YuniKorn are defined as the following Kubernetes objects: "deployments", "replicasets", "statefulsets", "daemonsets", "jobs", "cronjobs". The CREATE action correctly enforces the checks for all object types. The bypass allows any user to specify an arbitrary user info annotation. The same bypass also allows changing the application ID for the workload. The combination of the two applied in one UPDATE could allow access to a queue that the user normally would not have access to. Quota usage for the queue might be impacted if the application runs in the incorrect queue. User based quota enforcement is also based on the user annotation. User quota tracking could be side stepped even if the application runs in the correct queue. Users are recommended to upgrade to version 1.10.0, which fixes this issue. | ||||
| CVE-2026-78243 | 1 Apache | 1 Yunikorn | 2026-10-09 | N/A |
| Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries.If the LDAP server returns a group membership entry, memberOf attribute, for a user specified in the pod the server crashes if a membership record does not start with "CN=". This only affects install that have the non default LDAP group provider configured. Users are recommended to upgrade to version 1.10.0, which fixes this issue. | ||||
| CVE-2026-97146 | 1 Apache | 1 Yunikorn | 2026-10-09 | N/A |
| Apache YuniKorn 1.9.0 and earlier allows bypassing the check for the user annotation by setting a secondary label on the pod. If the pod has the label 'app=yunikorn' the checks limiting the user annotation content are not run. The label is used to identify the YuniKorn application itself in the deployments. The bypass allows any user to specify an arbitrary user info annotation. The arbitrary user information could allow access to a queue that the user normally would not have access to. Quota usage for the queue might be impacted if the application runs in the incorrect queue. User based quota enforcement is also based on the user annotation. User quota tracking could be side stepped even if the application runs in the correct queue. Users are recommended to upgrade to version 1.10.0, which fixes this issue. | ||||
| CVE-2026-42721 | 2 Servit Software Solutions, Wordpress-extensions | 2 Affiliate-toolkit, Affiliate-toolkit | 2026-10-09 | 7.6 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SERVIT Software Solutions affiliate-toolkit affiliate-toolkit-starter allows Blind SQL Injection.This issue affects affiliate-toolkit: from n/a through 3.9.1. | ||||
| CVE-2026-42720 | 2 Sarah Giles, Wordpress-extensions | 2 Dynamic User Directory, Dynamic User Directory | 2026-10-09 | 7.6 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sarah Giles Dynamic User Directory dynamic-user-directory allows Blind SQL Injection.This issue affects Dynamic User Directory: from n/a through 2.4. | ||||
| CVE-2026-96408 | 1 Six Apart | 4 Movable Type, Movable Type Cloud Edition, Movable Type Premium and 1 more | 2026-10-09 | N/A |
| A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product. | ||||
| CVE-2026-103668 | 1 Six Apart | 4 Movable Type, Movable Type Cloud Edition, Movable Type Premium and 1 more | 2026-10-09 | N/A |
| An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product. | ||||
| CVE-2026-42714 | 2 Piggly Dev, Wordpress-extensions | 2 Pix Por Piggly (para Woocommerce), Pix Por Piggly (para Woocommerce) | 2026-10-09 | 7.6 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Piggly Dev Pix por Piggly (para Woocommerce) pix-por-piggly allows Blind SQL Injection.This issue affects Pix por Piggly (para Woocommerce): from n/a through 2.1.2. | ||||
| CVE-2026-42713 | 2 Gopiplus, Wordpress-extensions | 2 Post Title Marquee Scroll, Post Title Marquee Scroll | 2026-10-09 | 7.6 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gopiplus Post title marquee scroll post-title-marquee-scroll allows Blind SQL Injection.This issue affects Post title marquee scroll: from n/a through 9.9. | ||||
| CVE-2026-42710 | 2 10web, Wordpress-extensions | 2 Sliderby10web, Slider By 10web | 2026-10-09 | 7.6 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Slider by 10Web slider-wd allows Blind SQL Injection.This issue affects Slider by 10Web: from n/a through 1.2.63. | ||||
| CVE-2026-42708 | 2 Afthemes, Wordpress-extensions | 2 Wp Post Author, Wp Post Author | 2026-10-09 | 7.6 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author wp-post-author allows Blind SQL Injection.This issue affects WP Post Author: from n/a through 4.0.0. | ||||
| CVE-2026-107168 | 2 M17n-lib, Redhat | 2 M17n-lib, Enterprise Linux | 2026-10-09 | 6.2 Medium |
| A flaw was found in m17n-lib. By providing crafted input containing an invalid UTF-8 character sequence, an attacker can cause the text parsing function to enter an infinite loop. This issue leads to sustained high CPU utilization, resulting in a Denial of Service (DoS) for the affected application. | ||||
| CVE-2026-107170 | 2 M17n-lib, Redhat | 2 M17n-lib, Enterprise Linux | 2026-10-09 | 2.9 Low |
| A flaw was found in m17n-lib. A partial failure during library initialization can leave an internal driver pointer uninitialized. Under specific error conditions, such as system resource exhaustion or database corruption, an application attempting to open an input method dereferences this null pointer without proper validation. This issue causes the application to crash, resulting in a Denial of Service (DoS). | ||||
| CVE-2026-103435 | 1 Anthropic | 1 Claude Code | 2026-10-09 | 7.0 High |
| Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at write time without repeating that validation. This time-of-check to time-of-use (TOCTOU) gap allowed an attacker who could write to the workspace to atomically replace a project file with a symlink, causing Claude Code to follow the symlink and write its output to an arbitrary file outside the project sandbox. Exploitation required the ability to win a race condition against the write operation and write access to the shared workspace, enabling a lower-privileged attacker to redirect benign edits to sensitive files (e.g., shell configuration) in a higher-privileged session. Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version. Thank you to hackerone.com/c_h4ck_0 for reporting this issue. | ||||
| CVE-2026-42532 | 1 Visidata | 1 Visidata | 2026-10-09 | 5.5 Medium |
| A path traversal vulnerability exists in the EmailSheet extract_parts functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .eml file can lead to arbitrary file write. An attacker can provide a malicious file to trigger this vulnerability. | ||||
| CVE-2026-41958 | 1 Visidata | 1 Visidata | 2026-10-09 | 6.5 Medium |
| A path traversal vulnerability exists in the unzip_http RemoteZipFile extract functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .zip file can lead to arbitrary file write. An attacker can provide a crafted URL to trigger this vulnerability. | ||||