Export limit exceeded: 401009 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (401009 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-55252 | 1 Openrundev | 1 Openrun | 2026-10-02 | N/A |
| OpenRun is an open-source, self-hosted GitOps platform for deploying web apps and internal tools to Docker or Kubernetes. Prior to version 0.17.7, the restrictions on redirect URLs in openrun can be bypassed by attackers, leading to open redirect attacks. This issue has been patched in version 0.17.7. | ||||
| CVE-2026-96780 | 1 Patorjk | 1 Figlet.js | 2026-10-02 | N/A |
| figlet.js is a FIG driver written in JavaScript that aims to implement the FIGfont specification. Prior to 1.11.3, text() and textSync() can enter an unbounded loop when whitespaceBreak is enabled and width is smaller than the rendered width of a single FIGlet character. Under these conditions, breakWord() cannot find a valid break point and returns without consuming a character, so generateFigTextLines() repeatedly processes the same input while consuming CPU and growing memory. The non-default option and attacker-controlled width must both reach an affected call. This issue is fixed in version 1.11.3. | ||||
| CVE-2026-104020 | 1 Amazon | 1 Ion-python | 2026-10-02 | 7.5 High |
| Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value. To remediate this issue, users should upgrade to version 0.15.0 or later. | ||||
| CVE-2026-102370 | 1 Tp-link | 2 Kasa Ec70 V4, Kasa Ec71 V4 | 2026-10-02 | N/A |
| Kasa EC70 v4 and EC71 v4 do not logically disable the production debug interface at the firmware or chip level and do not lock the bootloader. Although the debug traces are physically severed during manufacturing, an attacker with physical access can restore the connection, interrupt the boot process, and manipulate boot parameters to enter a non-standard initialization path that exposes an unauthenticated root shell during startup. Successful exploitation may allow an attacker with physical access to obtain root-level command access during device startup, resulting in loss of confidentiality, integrity, and availability for the affected device. Exploitation requires device disassembly, restoration of the severed debug connection, and manipulation of the boot process. | ||||
| CVE-2026-104002 | 1 Aws | 1 Powertools-lambda-python | 2026-10-02 | 5.3 Medium |
| A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask. To remediate this issue, users should upgrade to version 3.35.0. | ||||
| CVE-2026-34175 | 1 Intel | 2 Hardware-aware-automated-machine-learning, Hardware-aware-automated-machinelearning | 2026-10-02 | 6.7 Medium |
| Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. | ||||
| CVE-2026-103098 | 2 Geovision, Geovision Inc. | 2 Gv-eye, Gv-eye | 2026-10-02 | 7.5 High |
| Transmission of a sensitive key in the URL over an unencrypted HTTP connection. The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor network traffic could intercept the request and obtain the key | ||||
| CVE-2026-104480 | 1 Discord | 1 Libdave | 2026-10-02 | N/A |
| Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio and video. | ||||
| CVE-2026-14378 | 2 Dplugins, Wordpress-extensions | 2 Devkit Pro, Devkit Pro | 2026-10-02 | 9.8 Critical |
| The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by the cookie rather than on the actual requester via `current_user_can()`, while the switch-back form and a valid session-bound nonce are emitted publicly via `wp_footer` to any visitor — including unauthenticated users — whenever that cookie is present. This makes it possible for unauthenticated attackers to set the `original_user_id` cookie to any administrator's user ID, collect the rendered nonce, and POST it back to the `revert_switch` handler, causing `wp_set_auth_cookie()` to be called with the administrator's ID and granting the attacker a full administrator-level authenticated session and complete site takeover. | ||||
| CVE-2026-81740 | 2 Paytm, Wordpress-extensions | 2 Payment Gateway, Paytm Payment Gateway | 2026-10-02 | 5.3 Medium |
| The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders, including marking unpaid orders as paid and reducing stock. | ||||
| CVE-2026-85004 | 1 Wordpress-extensions | 1 Popup Maker | 2026-10-02 | 4.3 Medium |
| The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker WordPress plugin through 1.4.5 option (the linked service account and API configuration) that should only be modifiable by administrators. | ||||
| CVE-2026-90988 | 1 Wordpress-extensions | 1 Request A Quote | 2026-10-02 | 5.3 Medium |
| The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published. | ||||
| CVE-2026-13718 | 1 Wordpress-extensions | 1 Tabs Responsive | 2026-10-02 | 6.8 Medium |
| The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page. | ||||
| CVE-2026-91828 | 1 Wordpress-extensions | 1 Omgf | 2026-10-02 | 7.5 High |
| The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site's PHP worker pool and make the entire site unavailable. | ||||
| CVE-2026-85016 | 1 Wordpress-extensions | 1 Unlimited Elements For Elementor | 2026-10-02 | 6.8 Medium |
| The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered. | ||||
| CVE-2026-91022 | 1 Wordpress-extensions | 1 Motors | 2026-10-02 | 6.8 Medium |
| The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator. | ||||
| CVE-2026-91023 | 1 Wordpress-extensions | 1 Motors | 2026-10-02 | 3.1 Low |
| The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration. | ||||
| CVE-2026-94298 | 1 Wordpress-extensions | 1 Buildkit | 2026-10-02 | 6.2 Medium |
| The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor. | ||||
| CVE-2026-97317 | 2 Rafflepress, Wordpress-extensions | 2 Giveaways And Contests By Rafflepress, Giveaways And Contests By Rafflepress | 2026-10-02 | 5.3 Medium |
| The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured. | ||||
| CVE-2026-97318 | 2 Rafflepress, Wordpress-extensions | 2 Giveaways And Contests By Rafflepress, Giveaways And Contests By Rafflepress | 2026-10-02 | 6.1 Medium |
| The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary external site. | ||||