Export limit exceeded: 400564 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400564 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400564 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-62061 | 2 Metagauss, Wordpress-extensions | 2 Profilegrid, Profilegrid | 2026-10-01 | 5.3 Medium |
| Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 6.0.0.2. | ||||
| CVE-2026-62060 | 2 Captivateaudio, Wordpress-extensions | 2 Captivate Sync, Captivate Sync | 2026-10-01 | 7.6 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Blind SQL Injection.This issue affects Captivate Sync: from n/a through 3.3.2. | ||||
| CVE-2026-62059 | 2 Ultimatemember, Wordpress-extensions | 2 Ultimate Member, Ultimate Member | 2026-10-01 | 7.6 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ultimate Member: from n/a through 2.13.1. | ||||
| CVE-2026-79901 | 1 Fortra | 1 Boks Manager Boks-server | 2026-10-01 | 9.9 Critical |
| In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline. | ||||
| CVE-2026-79900 | 1 Fortra | 1 Boks Manager Boks-server | 2026-10-01 | 6.5 Medium |
| boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name but do not verify that the value fits in a fixed 16-byte checksum context field before copying it. An authenticated KSL client can supply an oversized, OpenSSL-recognized digest name and write beyond the end of the heap allocation. | ||||
| CVE-2024-58388 | 2 Sharp Corporation, Toshiba Tec Corporation | 2 Multiple Multifunction Printers, Multiple Multifunction Printers | 2026-10-01 | 7.5 High |
| Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, including /etc/passwd, coredump files containing credentials, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30. | ||||
| CVE-2026-103752 | 2 Paul Ryan, Wordpress-extensions | 2 Authorizer, Authorizer | 2026-10-01 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions. | ||||
| CVE-2026-62071 | 2 Nickboss, Wordpress-extensions | 2 Wordpress File Upload, Wordpress File Upload | 2026-10-01 | 9.3 Critical |
| Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions. | ||||
| CVE-2026-62073 | 2 Themeisle, Wordpress-extensions | 2 Wp Full Stripe Free, Wp Full Stripe Free | 2026-10-01 | 7.5 High |
| Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions. | ||||
| CVE-2026-94390 | 2 Dotstore, Wordpress-extensions | 2 Hide Shipping Method For Woocommerce, Hide Shipping Method For Woocommerce | 2026-10-01 | 7.2 High |
| Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions. | ||||
| CVE-2026-97260 | 2 Maxfoundry, Wordpress-extensions | 2 Maxgalleria, Maxgalleria | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions. | ||||
| CVE-2026-97269 | 2 Getwpfunnels, Wordpress-extensions | 2 Wpfunnels, Wpfunnels | 2026-10-01 | 6.5 Medium |
| Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions. | ||||
| CVE-2026-97273 | 2 Premmerce, Wordpress-extensions | 2 Wishlist For Woocommerce, Premmerce Wishlist For Woocommerce | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions. | ||||
| CVE-2026-79899 | 1 Fortra | 1 Boks Manager | 2026-10-01 | 7.9 High |
| Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation. | ||||
| CVE-2026-97280 | 2 Mamunur Rashid, Wordpress-extensions | 2 Review Schema, Review Schema | 2026-10-01 | 6.5 Medium |
| Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Review Schema: 3.1.0. | ||||
| CVE-2026-79898 | 1 Fortra | 1 Boks Manager | 2026-10-01 | 9.1 Critical |
| Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide network-accessible administration paths and do not require a local sudo or suexec rule; non-root use of cacrl requires such a rule. | ||||
| CVE-2026-79896 | 1 Fortra | 1 Boks Manager | 2026-10-01 | 7.5 High |
| Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption. | ||||
| CVE-2026-42528 | 1 Apache | 1 Http Server | 2026-10-01 | 4.3 Medium |
| A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to version 2.4.69, which fixes this issue | ||||
| CVE-2026-101322 | 1 Eclipse | 1 Basyx Aas Web Ui | 2026-10-01 | N/A |
| In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260924, the shared request handler attached the selected infrastructure's `Authorization` header to outgoing requests without checking the destination origin. In deployments using authentication, an attacker could induce a user to open a crafted Web UI link whose `aas` or `path` query parameter points to an attacker-controlled endpoint. The user's browser would then send the configured Basic Authentication credentials, Bearer token, or an available OAuth2 access token to that endpoint. The attacker could reuse the disclosed credential to access protected AAS services with the victim's privileges. The issue is fixed in v2-260924. | ||||
| CVE-2026-12544 | 2 Redhat, Theforeman | 4 Satellite, Satellite Capsule, Satellite Utils and 1 more | 2026-10-01 | 7.7 High |
| A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection (SSTI) and insecure deserialization. This vulnerability can lead to remote code execution, total infrastructure compromise and supply chain risk. | ||||