Search
Search Results (102089 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-13808 | 1 Orionsec | 2 Orion-ops, Orion Ops | 2026-09-30 | 7.3 High |
| A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this vulnerability is the function update of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/UserController.java of the component User Profile Handler. This manipulation of the argument ID causes improper authorization. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-62540 | 1 Oracle | 2 Cost Management, E-business Suite | 2026-09-30 | 7.2 High |
| Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). | ||||
| CVE-2026-97293 | 2026-09-30 | 8.5 High | ||
| Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions. | ||||
| CVE-2026-97253 | 2026-09-30 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kreatura LayerSlider allows Reflected XSS. This issue affects LayerSlider: from n/a through 8.4.0. | ||||
| CVE-2026-97245 | 2026-09-30 | 7.2 High | ||
| Shop Worker Privilege Escalation in SureCart <= 4.7.2 versions. | ||||
| CVE-2026-97244 | 2026-09-30 | 7.5 High | ||
| Contributor Path Traversal in Creator LMS <= 1.2.19 versions. | ||||
| CVE-2026-97241 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions. | ||||
| CVE-2026-97240 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions. | ||||
| CVE-2026-97237 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. | ||||
| CVE-2026-97235 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions. | ||||
| CVE-2026-97197 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions. | ||||
| CVE-2026-97077 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Ad Inserter <= 2.8.18 versions. | ||||
| CVE-2026-97065 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions. | ||||
| CVE-2026-96838 | 2026-09-30 | 8.8 High | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification <= 2.3.1 versions. | ||||
| CVE-2026-96837 | 2026-09-30 | 8.8 High | ||
| Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions. | ||||
| CVE-2026-96836 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Parsi Date <= 6.3 versions. | ||||
| CVE-2026-96833 | 2026-09-30 | 7.2 High | ||
| Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions. | ||||
| CVE-2026-96832 | 2026-09-30 | 7.2 High | ||
| Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions. | ||||
| CVE-2026-96831 | 2026-09-30 | 8.8 High | ||
| Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions. | ||||
| CVE-2026-96830 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.9 versions. | ||||