Search

Search Results (402089 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-20522 1 Mediatek, Inc. 1 Mediatek Chipset 2026-10-05 8.4 High
In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249050; Issue ID: MSV-9172.
CVE-2026-20523 1 Mediatek, Inc. 1 Mediatek Chipset 2026-10-05 8.4 High
In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249062; Issue ID: MSV-9171.
CVE-2026-94669 2026-10-05 5.3 Medium
Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13.
CVE-2026-59788 1 Zabbix 1 Zabbix 2026-10-05 4.8 Medium
The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in the browser. This means a crafted media type configuration, deliverable as an import file, runs arbitrary JavaScript as the Super Admin who grants consent.
CVE-2026-59787 1 Zabbix 1 Zabbix 2026-10-05 4.3 Medium
The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity.
CVE-2026-59786 1 Zabbix 1 Zabbix 2026-10-05 5.3 Medium
Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity.
CVE-2026-59785 1 Zabbix 1 Zabbix 2026-10-05 4.3 Medium
Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them uncover it.
CVE-2026-59783 1 Zabbix 1 Zabbix 2026-10-05 6.5 Medium
The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database.
CVE-2026-59782 1 Zabbix 1 Zabbix 2026-10-05 4.9 Medium
The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator.
CVE-2026-105287 1 Feelec-yishu 1 Feelcrm-os 2026-10-05 6.3 Medium
A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpoint. This manipulation of the argument groups[] causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2025-58222 1 Wordpress 1 Wordpress 2026-10-05 5.3 Medium
Missing Authorization vulnerability in Dynamic Web Lab Team Manager wp-team-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team Manager: from n/a through 2.6.8.
CVE-2026-20541 1 Mediatek, Inc. 1 Mediatek Chipset 2026-10-05 5.3 Medium
In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8911.
CVE-2026-20543 1 Mediatek, Inc. 1 Mediatek Chipset 2026-10-05 5.5 Medium
In Modem, there is a possible information disclosure due to a logic error. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01645293; Issue ID: MSV-6761.
CVE-2026-20538 1 Mediatek, Inc. 1 Mediatek Chipset 2026-10-05 5.3 Medium
In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8914.
CVE-2026-17005 1 Wordpress-extensions 1 Horizontal Scrolling Announcements 2026-10-05 6.8 Medium
The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted) to perform Stored Cross-Site Scripting attacks that execute in the browser of anyone viewing the announcement.
CVE-2026-105291 1 Feelec-yishu 1 Feelcrm-os 2026-10-05 4.3 Medium
A vulnerability was identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function GroupController::index of the file App/Feelcrm/Index/Controller/GroupController.class.php of the component Department Search Endpoint. The manipulation of the argument keyword leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-104119 1 Wordpress-extensions 1 Simple Shopping Cart 2026-10-05 3.5 Low
The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where administrators do not have the unfiltered_html capability.
CVE-2026-104118 2 Razorpay, Wordpress-extensions 2 Razorpay For Woocommerce, Razorpay For Woocommerce 2026-10-05 5.3 Medium
The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.
CVE-2025-53345 2 Thimpress, Wordpress 2 Thim Core, Wordpress 2026-10-05 8.8 High
Missing Authorization vulnerability in ThimPress Thim Core thim-core.This issue affects Thim Core: from n/a through 2.3.3.
CVE-2026-80276 1 Comelit Group 1 1456b Multi-user Gateway 2026-10-05 7.5 High
Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 expose a network-accessible management interface that does not require authentication. Through this interface, sensitive device configuration data - including the Remote Configuration Password - can be read in cleartext by a remote, unauthenticated attacker.