Export limit exceeded: 401149 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (401149 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-81740 | 2 Paytm, Wordpress-extensions | 2 Payment Gateway, Paytm Payment Gateway | 2026-10-02 | 5.3 Medium |
| The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders, including marking unpaid orders as paid and reducing stock. | ||||
| CVE-2026-85004 | 1 Wordpress-extensions | 1 Popup Maker | 2026-10-02 | 4.3 Medium |
| The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker WordPress plugin through 1.4.5 option (the linked service account and API configuration) that should only be modifiable by administrators. | ||||
| CVE-2026-90988 | 1 Wordpress-extensions | 1 Request A Quote | 2026-10-02 | 5.3 Medium |
| The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published. | ||||
| CVE-2026-13718 | 1 Wordpress-extensions | 1 Tabs Responsive | 2026-10-02 | 6.8 Medium |
| The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page. | ||||
| CVE-2026-91828 | 1 Wordpress-extensions | 1 Omgf | 2026-10-02 | 7.5 High |
| The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site's PHP worker pool and make the entire site unavailable. | ||||
| CVE-2026-85016 | 1 Wordpress-extensions | 1 Unlimited Elements For Elementor | 2026-10-02 | 6.8 Medium |
| The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered. | ||||
| CVE-2026-91022 | 1 Wordpress-extensions | 1 Motors | 2026-10-02 | 6.8 Medium |
| The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator. | ||||
| CVE-2026-91023 | 1 Wordpress-extensions | 1 Motors | 2026-10-02 | 3.1 Low |
| The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration. | ||||
| CVE-2026-94298 | 1 Wordpress-extensions | 1 Buildkit | 2026-10-02 | 6.2 Medium |
| The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor. | ||||
| CVE-2026-97317 | 2 Rafflepress, Wordpress-extensions | 2 Giveaways And Contests By Rafflepress, Giveaways And Contests By Rafflepress | 2026-10-02 | 5.3 Medium |
| The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured. | ||||
| CVE-2026-97318 | 2 Rafflepress, Wordpress-extensions | 2 Giveaways And Contests By Rafflepress, Giveaways And Contests By Rafflepress | 2026-10-02 | 6.1 Medium |
| The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary external site. | ||||
| CVE-2026-80464 | 1 Havelsan | 1 Sef - Ai Chatbot Platform | 2026-10-02 | 4.9 Medium |
| Server-Side request forgery (SSRF) vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Server Side Request Forgery. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported. | ||||
| CVE-2026-80337 | 1 Havelsan | 1 Sef - Ai Chatbot Platform | 2026-10-02 | 5.3 Medium |
| Missing Authorization vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported. | ||||
| CVE-2026-80443 | 1 Havelsan | 1 Sef - Ai Chatbot Platform | 2026-10-02 | 7.4 High |
| Improper certificate validation vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Adversary in the Middle (AiTM). This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported. | ||||
| CVE-2026-59659 | 1 Repasat | 1 Repasat Application | 2026-10-02 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomZonaGeo” parameter is affected – endpoint “/es/geozones/update/149979”. | ||||
| CVE-2026-59660 | 1 Repasat | 1 Repasat Application | 2026-10-02 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTransportista” parameter is affected – endpoint “/es/carriers/update”. | ||||
| CVE-2026-59661 | 1 Repasat | 1 Repasat Application | 2026-10-02 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomRuta” parameter is affected – endpoint “/es/routes/update/693”. | ||||
| CVE-2026-59666 | 1 Repasat | 1 Repasat Application | 2026-10-02 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomOrigen” parameter is affected – endpoint “/es/origins/store”. | ||||
| CVE-2026-59667 | 1 Repasat | 1 Repasat Application | 2026-10-02 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTamano” parameter is affected – endpoint “/es/companysizemployees/update”. | ||||
| CVE-2026-93925 | 1 Apache | 1 Thrift | 2026-10-02 | 7.5 High |
| Stack-based buffer overflow, Incorrect bitwise shift of integer vulnerability in Apache Thrift C++ THeaderProtocol. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||