Export limit exceeded: 403696 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403696 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-39798 | 2 Themetechmount, Wordpress-extensions | 2 Truebooker, Truebooker | 2026-10-06 | 6.5 Medium |
| Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions. | ||||
| CVE-2026-40806 | 2 Plugin-devs, Wordpress-extensions | 2 Blog, Posts And Category Filter For Elementor, Blog Posts And Category Filter For Elementor | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions. | ||||
| CVE-2026-40807 | 2 Aman, Wordpress-extensions | 2 Cf7 Views – Complete Entry Management For Contact Form 7, Cf7 Views | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.6 versions. | ||||
| CVE-2026-41555 | 2 Weblizar, Wordpress-extensions | 2 Newsletter Subscription Form – User Subscriptions Form, Capture Email, Newsletter Subscription Form – User Subscriptions Form, Capture Email | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions. | ||||
| CVE-2026-41559 | 2 Pluginjoy, Wordpress-extensions | 2 Safesnap – Verified Wordpress Backup & Restore, Safesnap | 2026-10-06 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in SafeSnap – Verified WordPress Backup & Restore <= 2.1.2 versions. | ||||
| CVE-2026-41560 | 2 Wordpress-extensions, Wxdlabs | 2 Wxd Backup Lite, Wxd Backup Lite | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions. | ||||
| CVE-2026-41561 | 2 Adrian Lin, Wordpress-extensions | 2 Museder Restoreone, Museder Restoreone | 2026-10-06 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Museder RestoreOne <= 2.7.276 versions. | ||||
| CVE-2026-41562 | 2 Norvisgabriel, Wordpress-extensions | 2 Norvis Backup, Norvis Backup | 2026-10-06 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions. | ||||
| CVE-2026-42413 | 2 Daftplug, Wordpress-extensions | 2 Snapshotify, Snapshotify | 2026-10-06 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Snapshotify – All-in-One Backup & Restore & Migrate <= 1.3.2 versions. | ||||
| CVE-2026-98356 | 1 Linux | 1 Linux Kernel | 2026-10-06 | 7.0 High |
| In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup bnxt_re_init_dcb_wq() ignores a failed allocation. The async DCB handler later calls queue_work() on the NULL pointer. | ||||
| CVE-2014-125130 | 2 Damjan, Wordpress-extensions | 2 Codeart Google Mp3 Audio Player, Codeart Google Mp3 Audio Player | 2026-10-06 | 7.5 High |
| CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-traversal payload in the file parameter of direct_download.php. Attackers can request paths ../../wp-config.php without authentication to download configuration files containing database credentials and secret keys, leading to full site compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-19. | ||||
| CVE-2026-104872 | 2 Open-telemetry, Opentelemetry | 9 Opentelemetry-js-contrib, Instrumentation-cassandra-driver, Instrumentation-knex and 6 more | 2026-10-06 | 5.8 Medium |
| OpenTelemetry JavaScript Contrib provides instrumentation libraries for collecting telemetry from JavaScript applications. Prior to versions 0.66.0 of @opentelemetry/instrumentation-cassandra-driver, 0.65.0 of @opentelemetry/instrumentation-knex, 0.67.0 of @opentelemetry/instrumentation-mongoose, @opentelemetry/instrumentation-mysql, and @opentelemetry/instrumentation-mysql2, 0.46.0 of @opentelemetry/instrumentation-oracledb, 0.73.0 of @opentelemetry/instrumentation-pg, and 0.40.0 of @opentelemetry/instrumentation-tedious, the packages add the database connection username to every instrumented database operation as the db.user span attribute. The attribute is emitted by default and is not controlled by enhancedDatabaseReporting or another opt-in setting. Configured observability backends therefore receive database account names that may expose service topology, role or environment information, and account naming patterns. This issue is fixed in versions 0.66.0, 0.65.0, 0.67.0, 0.46.0, 0.73.0, and 0.40.0 of the respective packages. | ||||
| CVE-2026-75937 | 1 Digi International | 12 Anywhereusb Plus Family, Connect Ez Family, Connect It Family and 9 more | 2026-10-06 | N/A |
| A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device. | ||||
| CVE-2026-95865 | 2 Beaverbuilder, Wordpress-extensions | 2 Beaver Builder Page Builder – Drag And Drop Website Builder, Beaver Builder Page Builder | 2026-10-06 | 6.5 Medium |
| The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all versions up to, and including, 2.11.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable get_autosuggest_values AJAX endpoint is reachable by any Contributor who owns a draft post, as the required fl_ajax_update nonce is emitted into the block editor for any user who can edit a Beaver Builder post type. | ||||
| CVE-2026-105220 | 1 Klembot | 1 Twinejs | 2026-10-06 | 7.8 High |
| Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScratchFile IPC bridge to write and open a .bat file, executing code as the user. | ||||
| CVE-2026-105221 | 1 Defunkt | 1 Gist | 2026-10-06 | 7.4 High |
| The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists. | ||||
| CVE-2026-105222 | 2 Alexpechkarev, Bestwebsoft | 2 Google-maps, Google Maps | 2026-10-06 | 7.4 High |
| The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses. | ||||
| CVE-2026-105223 | 1 Maclof | 1 Kubernetes-client | 2026-10-06 | 7.4 High |
| maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers can impersonate the Kubernetes API server to capture Bearer tokens or Basic credentials and tamper with WebSocket or REST API traffic. | ||||
| CVE-2026-105293 | 1 Legcord | 1 Legcord | 2026-10-06 | 8.1 High |
| Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as through XSS, can abuse themes.folder, themes.uninstall, and themes.install to launch local executables, recursively delete directories, and write files outside the themes directory. | ||||
| CVE-2026-105294 | 1 Legcord | 1 Legcord | 2026-10-06 | 7.4 High |
| Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set additionalArguments to persistently add --proxy-server and --ignore-certificate-errors switches, routing all client traffic through an interception proxy. | ||||