Export limit exceeded: 402868 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402868 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402868 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104380 | 1 Perl | 1 Punk | 2026-10-06 | 5.3 Medium |
| Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it. A cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx. | ||||
| CVE-2026-94293 | 1 Murrelektronik | 2 Aas Edge Client, Software Aas Edge Client All Versions | 2026-10-06 | 9.8 Critical |
| An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints. | ||||
| CVE-2026-42414 | 2 Cridio, Wordpress-extensions | 2 Listingpro, Listingpro | 2026-10-06 | 8.5 High |
| Subscriber SQL Injection in ListingPro <= 2.9.12 versions. | ||||
| CVE-2026-42415 | 2 Portotheme, Wordpress-extensions | 2 Functionality, Porto Theme | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions. | ||||
| CVE-2026-42416 | 2 Andondesign, Wordpress-extensions | 2 Udesign, Udesign Core | 2026-10-06 | 8.5 High |
| Subscriber SQL Injection in UDesign Core <= 4.15.0 versions. | ||||
| CVE-2026-42417 | 2 Reputeinfosystems, Wordpress-extensions | 2 Armember, Armember Premium | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions. | ||||
| CVE-2026-42634 | 2 Bplugins, Wordpress-extensions | 2 Video Background Block – Use Video As Background In The Section., Video Background Block Use Video As Background In The Section | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Video Background Block – Use video as background in the section. <= 2.0.3 versions. | ||||
| CVE-2026-42635 | 2 Wordpress-extensions, Wpgenie | 2 Woocommerce Simple Auctions, Woocommerce Simple Auctions | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WooCommerce Simple Auctions <= 3.0.10 versions. | ||||
| CVE-2026-42636 | 2 Wordpress-extensions, Wp Legal Pages | 2 Wp Cookie Notice For Gdpr, Ccpa & Eprivacy Consent, Wp Cookie Notice For Gdpr, Ccpa & Eprivacy Consent | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.4.6 versions. | ||||
| CVE-2026-42637 | 2 Payplug, Wordpress-extensions | 2 Payplug For Woocommerce (official), Payplug For Woocommerce (official) | 2026-10-06 | 6.5 Medium |
| Unauthenticated Settings Change in PayPlug for WooCommerce (Official) <= 3.1.0 versions. | ||||
| CVE-2026-48197 | 2 Publishpress, Wordpress-extensions | 2 Capabilities, Publishpress Capabilities | 2026-10-06 | 7.2 High |
| Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0. | ||||
| CVE-2026-48199 | 2 Beplusthemes, Wordpress-extensions | 2 Sermon'e, Sermon'e | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in Sermon'e <= 1.0.2 versions. | ||||
| CVE-2026-62072 | 2 Progress Planner, Wordpress-extensions | 2 Progress Planner, Progress Planner | 2026-10-06 | 8.8 High |
| Subscriber Broken Access Control in Progress Planner <= 1.10.0 versions. | ||||
| CVE-2026-66588 | 2 Dream-theme, Wordpress-extensions | 2 The7, The7 | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in The7 <= 14.2.2 versions. | ||||
| CVE-2026-94675 | 2 Fluent Forms Free Vs Pro, Wordpress-extensions | 2 Fluent Forms Pro Add On Pack, Fluent Forms Pro Add On Pack | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack <= 6.2.13 versions. | ||||
| CVE-2026-95526 | 2 Realmag777, Wordpress-extensions | 2 Bear, Bear | 2026-10-06 | 7.3 High |
| Unauthenticated Broken Access Control in BEAR <= 1.2.2 versions. | ||||
| CVE-2026-95594 | 2 Cozy Vision Technologies Pvt. Ltd., Wordpress-extensions | 2 Sms Alert Order Notifications, Sms Alert Order Notifications | 2026-10-06 | 8.1 High |
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions. | ||||
| CVE-2026-97308 | 2 Webfactoryltd, Wordpress-extensions | 2 Wp Login Lockdown, Login Lockdown | 2026-10-06 | 4.8 Medium |
| Unauthenticated Bypass Vulnerability in Login Lockdown <= 2.17 versions. | ||||
| CVE-2026-100518 | 2 Webfactoryltd, Wordpress-extensions | 2 Advanced Google Recaptcha, Advanced Google Recaptcha | 2026-10-06 | 5.3 Medium |
| Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions. | ||||
| CVE-2026-102387 | 2 Wordpress-extensions, Xserver | 2 Xserver Migrator, Xserver Migrator | 2026-10-06 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Xserver Migrator <= 1.6.6 versions. | ||||