Export limit exceeded: 402734 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402734 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402734 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-32577 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Frontend File Manager <= 23.6 versions. | ||||
| CVE-2026-32575 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in SUMO Affiliates Pro <= 11.7.0 versions. | ||||
| CVE-2026-32574 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Smart Forms <= 2.6.104 versions. | ||||
| CVE-2026-32572 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WP User Frontend Pro <= 4.2.13 versions. | ||||
| CVE-2026-32571 | 2026-10-06 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in Ohio Extra <= 3.6.8 versions. | ||||
| CVE-2026-32570 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Progressify - Progressive Web App (PWA) <= 1.6.0 versions. | ||||
| CVE-2026-32569 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WP Media folder <= 6.2.2 versions. | ||||
| CVE-2026-32568 | 2026-10-06 | 9.9 Critical | ||
| Subscriber Remote Code Execution (RCE) in WooCommerce Designer Pro <= 1.9.33 versions. | ||||
| CVE-2026-32557 | 2026-10-06 | 9.3 Critical | ||
| Unauthenticated SQL Injection in WooCommerce Appointments <= 5.3.2 versions. | ||||
| CVE-2026-25434 | 2026-10-06 | 8.5 High | ||
| Subscriber SQL Injection in WP2LEADS <= 3.5.7 versions. | ||||
| CVE-2026-25433 | 2026-10-06 | 7.1 High | ||
| Subscriber Broken Access Control in WP2LEADS <= 3.5.7 versions. | ||||
| CVE-2026-105985 | 1 Craftcms | 1 Cms | 2026-10-06 | 8.8 High |
| Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components. Any authenticated user with basic Control Panel access can submit request-controlled component classes and property overrides. By first overriding an EntryType object’s uiLabelFormat and then rendering an Entry that resolves the same request-cached entry type, an attacker can cause arbitrary Twig supplied in the request to be evaluated by renderObjectTemplate(). This render path is not sandboxed. A Twig string callable can therefore reach PHP functions such as system(), resulting in operating-system command execution with the privileges of the PHP/web-server process. The issue was reproduced with an active non-admin Craft Team user with no optional permissions enabled. No access to entry-editing, Settings, utility, user-management, project-config, filesystem, Kubernetes, or environment variables was required. | ||||
| CVE-2026-105879 | 2026-10-06 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: from n/a through 2.9.2.2. | ||||
| CVE-2026-105072 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions. | ||||
| CVE-2026-105056 | 2026-10-06 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Stored XSS.This issue affects eCommerce Product Catalog: from n/a through 3.6.2. | ||||
| CVE-2026-104409 | 2026-10-06 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Stored XSS.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.13. | ||||
| CVE-2026-104407 | 2026-10-06 | 7.1 High | ||
| Cross-Site Request Forgery (CSRF) vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through 11.17.9. | ||||
| CVE-2026-104389 | 2026-10-06 | 8.5 High | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sirv Sirv sirv allows Blind SQL Injection.This issue affects Sirv: from n/a through 8.2.5. | ||||
| CVE-2026-104386 | 2026-10-06 | 6.5 Medium | ||
| Missing Authorization vulnerability in WPFunnels Team WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through 9.1.3. | ||||
| CVE-2026-103831 | 1 Truelayer | 1 Truelayer Magento 2 Plugin | 2026-10-06 | N/A |
| CVE-2026-103831: Insecure deserialization vulnerability in the Psr16CacheAdapter component of the TrueLayer Magento 2 Plugin, due to the use of PHP's native unserialize() function without restrictions on the classes allowed when retrieving data stored in the cache. An attacker who already has the ability to write manipulated data to the cache backend used by Magento—such as Redis or Memcached—could inject specially crafted PHP objects and trigger their deserialization, potentially leading to arbitrary code execution via gadget strings available in the application environment. Exploitation therefore requires a prerequisite condition that allows writing to the cache infrastructure, either through access to the local file system or to a cache infrastructure accessible from the Magento environment. | ||||