Export limit exceeded: 403775 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403775 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-106497 | 1 Backstage | 2 Backstage, Plugin-catalog-backend | 2026-10-09 | 4.3 Medium |
| Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent catalog property permission evaluation. In deployments that use affected value-based catalog permission conditions as a confidentiality boundary, an authenticated user could receive catalog entity data that policy authors intended to restrict. This issue is fixed in version 3.9.1. | ||||
| CVE-2026-106498 | 1 Backstage | 2 Backstage, Plugin-catalog-backend | 2026-10-09 | 7.7 High |
| Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/plugin-catalog-backend package is affected by improper url validation in catalog entity placeholder resolution. An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under certain configurations, this could allow access to data not intended to be available to the user. This issue is fixed in versions 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1. | ||||
| CVE-2026-80048 | 2 Redhat, Sssd | 4 Enterprise Linux, Openshift, Openshift Container Platform and 1 more | 2026-10-09 | 5.5 Medium |
| A flaw was found in `sssd-kcm`. A local user or process able to connect to the `sssd-kcm` UNIX socket can exploit this vulnerability. By sending a large request length header and then stalling the connection, an attacker can cause the system to preallocate significant memory. This leads to memory exhaustion within the `sssd-kcm` responder, resulting in a Denial of Service (DoS) for affected deployments. | ||||
| CVE-2025-70515 | 1 Fanvil | 1 X7a | 2026-10-09 | N/A |
| The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows for the injection of HTML which can be used to execute malicious JavaScript code on any target browser which renders the device log component. | ||||
| CVE-2025-70516 | 1 Fanvil | 1 X7a | 2026-10-09 | 9.1 Critical |
| The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests. | ||||
| CVE-2025-70517 | 1 Fanvil | 1 X7a | 2026-10-09 | 8.8 High |
| The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint. | ||||
| CVE-2025-70518 | 1 Fanvil | 1 X7a | 2026-10-09 | 10 Critical |
| The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system. | ||||
| CVE-2025-70519 | 1 Fanvil | 1 X7a | 2026-10-09 | 6.1 Medium |
| The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows for the injection of HTML which can be used to execute malicious JavaScript code on any target browser which renders the device log component. | ||||
| CVE-2025-70520 | 1 Fanvil | 1 X7a | 2026-10-09 | N/A |
| The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests. | ||||
| CVE-2025-70521 | 1 Fanvil | 1 X7a | 2026-10-09 | 9.8 Critical |
| The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system. | ||||
| CVE-2025-70522 | 1 Fanvil | 1 X7a | 2026-10-09 | 8.8 High |
| The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint. | ||||
| CVE-2026-59346 | 1 Vmware | 2 Vmware Fusion, Vmware Workstation | 2026-10-09 | 9.3 Critical |
| VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1) | ||||
| CVE-2026-59347 | 1 Vmware | 2 Vmware Fusion, Vmware Workstation | 2026-10-09 | 8.1 High |
| VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1) | ||||
| CVE-2026-103323 | 1 Wordpress-extensions | 1 Integration For Epos Now And Woocommerce | 2026-10-09 | 5.9 Medium |
| The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2 does not perform an authorization check on one of its REST endpoints, allowing unauthenticated users to retrieve the site's scheduled background tasks and their arguments, which include order identifiers and, when WooCommerce's deferred emails feature is enabled, the plaintext passwords of newly registered customers. | ||||
| CVE-2026-103378 | 1 Wordpress-extensions | 1 Geliver Aklly Kargo Pazaryeri | 2026-10-09 | 6.5 Medium |
| The Geliver Akıllı Kargo Pazaryeri WordPress plugin before 3.1.1 does not prevent unauthenticated access to a log file it stores within its own web-accessible directory, into which it writes the site's carrier integration key while processing requests from unauthenticated users, allowing attackers to retrieve the key and use it to modify WooCommerce order statuses. The same log file also exposes customer information from orders the shop has processed. | ||||
| CVE-2026-103681 | 1 Wordpress-extensions | 1 Frontend Dashboard | 2026-10-09 | 4.3 Medium |
| The Frontend Dashboard WordPress plugin before 3.0.0 does not perform a capability check in one of its AJAX actions, allowing authenticated users with low privileges, such as subscribers, to delete the Frontend Dashboard WordPress plugin before 3.0.0's configured profile and post form fields. | ||||
| CVE-2026-104049 | 1 Wordpress-extensions | 1 Academy Lms | 2026-10-09 | 4.3 Medium |
| The Academy LMS WordPress plugin before 4.0.0 does not verify course enrollment or object ownership when returning a lesson's content through one of its REST API routes, allowing users with a self-registerable student account to read the full content of arbitrary lessons, including lessons of paid or private courses they are not enrolled in. | ||||
| CVE-2026-104050 | 1 Wordpress-extensions | 1 Academy Lms | 2026-10-09 | 4.3 Medium |
| The Academy LMS WordPress plugin before 4.0.0 does not verify that a quiz question belongs to the course the requesting user is authorized to access before returning that question's answer options, allowing any authenticated user with access to a single course, such as an enrolled student, to read the quiz answer options of questions belonging to other courses they are not enrolled in. | ||||
| CVE-2026-104651 | 1 Wordpress-extensions | 1 Yaad Sarig Payment Gateway For Wc | 2026-10-09 | 4.3 Medium |
| The Yaad Sarig Payment Gateway For WC WordPress plugin before 2.2.13 does not verify authorization or that the requesting user owns the target order in several of its order payment-processing actions, allowing any authenticated user, including subscribers, to act on and alter orders belonging to other customers. | ||||
| CVE-2026-104652 | 1 Wordpress-extensions | 1 Envira Gallery | 2026-10-09 | 6.8 Medium |
| The Envira Gallery WordPress plugin before 1.16.1 does not sanitise and escape a gallery item identifier before outputting it in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page embedding the gallery. | ||||