Export limit exceeded: 403768 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403768 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403768 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-39794 | 2 Wclovers, Wordpress-extensions | 2 Woocommerce Multivendor Marketplace, Woocommerce Multivendor Marketplace Rest Api | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions. | ||||
| CVE-2026-39795 | 2 Brewlabs, Wordpress-extensions | 2 Sendpress Newsletters, Sendpress Newsletters | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions. | ||||
| CVE-2026-39796 | 2 Flipper Code, Wordpress-extensions | 2 Advanced Posts Listing – Show Post List Easily, Advanced Posts Listing–show Post List Easily | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions. | ||||
| CVE-2026-39797 | 2 Data443, Wordpress-extensions | 2 Gdpr Framework By Data443, Gdpr Framework By Data443 | 2026-10-06 | 9.8 Critical |
| Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions. | ||||
| CVE-2026-39798 | 2 Themetechmount, Wordpress-extensions | 2 Truebooker, Truebooker | 2026-10-06 | 6.5 Medium |
| Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions. | ||||
| CVE-2026-40806 | 2 Plugin-devs, Wordpress-extensions | 2 Blog, Posts And Category Filter For Elementor, Blog Posts And Category Filter For Elementor | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions. | ||||
| CVE-2026-40807 | 2 Aman, Wordpress-extensions | 2 Cf7 Views – Complete Entry Management For Contact Form 7, Cf7 Views | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.6 versions. | ||||
| CVE-2026-41555 | 2 Weblizar, Wordpress-extensions | 2 Newsletter Subscription Form – User Subscriptions Form, Capture Email, Newsletter Subscription Form – User Subscriptions Form, Capture Email | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions. | ||||
| CVE-2026-41559 | 2 Pluginjoy, Wordpress-extensions | 2 Safesnap – Verified Wordpress Backup & Restore, Safesnap | 2026-10-06 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in SafeSnap – Verified WordPress Backup & Restore <= 2.1.2 versions. | ||||
| CVE-2026-41560 | 2 Wordpress-extensions, Wxdlabs | 2 Wxd Backup Lite, Wxd Backup Lite | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions. | ||||
| CVE-2026-41561 | 2 Adrian Lin, Wordpress-extensions | 2 Museder Restoreone, Museder Restoreone | 2026-10-06 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Museder RestoreOne <= 2.7.276 versions. | ||||
| CVE-2026-41562 | 2 Norvisgabriel, Wordpress-extensions | 2 Norvis Backup, Norvis Backup | 2026-10-06 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions. | ||||
| CVE-2026-42413 | 2 Daftplug, Wordpress-extensions | 2 Snapshotify, Snapshotify | 2026-10-06 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Snapshotify – All-in-One Backup & Restore & Migrate <= 1.3.2 versions. | ||||
| CVE-2026-98356 | 1 Linux | 1 Linux Kernel | 2026-10-06 | 7.0 High |
| In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup bnxt_re_init_dcb_wq() ignores a failed allocation. The async DCB handler later calls queue_work() on the NULL pointer. | ||||
| CVE-2014-125130 | 2 Damjan, Wordpress-extensions | 2 Codeart Google Mp3 Audio Player, Codeart Google Mp3 Audio Player | 2026-10-06 | 7.5 High |
| CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-traversal payload in the file parameter of direct_download.php. Attackers can request paths ../../wp-config.php without authentication to download configuration files containing database credentials and secret keys, leading to full site compromise. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-19. | ||||
| CVE-2026-104872 | 2 Open-telemetry, Opentelemetry | 9 Opentelemetry-js-contrib, Instrumentation-cassandra-driver, Instrumentation-knex and 6 more | 2026-10-06 | 5.8 Medium |
| OpenTelemetry JavaScript Contrib provides instrumentation libraries for collecting telemetry from JavaScript applications. Prior to versions 0.66.0 of @opentelemetry/instrumentation-cassandra-driver, 0.65.0 of @opentelemetry/instrumentation-knex, 0.67.0 of @opentelemetry/instrumentation-mongoose, @opentelemetry/instrumentation-mysql, and @opentelemetry/instrumentation-mysql2, 0.46.0 of @opentelemetry/instrumentation-oracledb, 0.73.0 of @opentelemetry/instrumentation-pg, and 0.40.0 of @opentelemetry/instrumentation-tedious, the packages add the database connection username to every instrumented database operation as the db.user span attribute. The attribute is emitted by default and is not controlled by enhancedDatabaseReporting or another opt-in setting. Configured observability backends therefore receive database account names that may expose service topology, role or environment information, and account naming patterns. This issue is fixed in versions 0.66.0, 0.65.0, 0.67.0, 0.46.0, 0.73.0, and 0.40.0 of the respective packages. | ||||
| CVE-2026-75937 | 1 Digi International | 12 Anywhereusb Plus Family, Connect Ez Family, Connect It Family and 9 more | 2026-10-06 | N/A |
| A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device. | ||||
| CVE-2026-95865 | 2 Beaverbuilder, Wordpress-extensions | 2 Beaver Builder Page Builder – Drag And Drop Website Builder, Beaver Builder Page Builder | 2026-10-06 | 6.5 Medium |
| The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all versions up to, and including, 2.11.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable get_autosuggest_values AJAX endpoint is reachable by any Contributor who owns a draft post, as the required fl_ajax_update nonce is emitted into the block editor for any user who can edit a Beaver Builder post type. | ||||
| CVE-2026-105220 | 1 Klembot | 1 Twinejs | 2026-10-06 | 7.8 High |
| Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScratchFile IPC bridge to write and open a .bat file, executing code as the user. | ||||
| CVE-2026-105221 | 1 Defunkt | 1 Gist | 2026-10-06 | 7.4 High |
| The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists. | ||||