Search

Search Results (402689 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-57554 2026-10-06 7.8 High
Memory Corruption when asynchronous threads access shared performance counter data simultaneously during FastRPC invocations.
CVE-2026-98233 1 Linux 1 Linux Kernel 2026-10-06 N/A
In the Linux kernel, the following vulnerability has been resolved: net/packet: clear RX owner on VNET header error Commit 61fad6816fc1 ("net/packet: tpacket_rcv: avoid a producer race condition") added rx_owner_map and made tpacket_rcv() claim a V1 or V2 ring slot before converting the virtio-net header. If the conversion fails, the drop path leaves the slot claimed. With a one-frame TPACKET_V2 ring, an unsupported UDP GSO packet leaves the only slot unavailable, so the ring also drops the next valid packet. Clear the ownership bit on this error path. TPACKET_V3 already clears its block state here.
CVE-2026-105918 1 Kusalkasilva 1 Learning-management-system 2026-10-06 7.3 High
A vulnerability has been found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. Impacted is the function mysql_error of the file login.php of the component Login Endpoint. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-97309 2026-10-06 N/A
Missing Authorization vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy: from n/a through 4.1226.
CVE-2026-97303 2026-10-06 7.6 High
Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scratch & Win – Giveaways and Contests: from n/a through 3.0.2.
CVE-2026-97300 2026-10-06 6.5 Medium
Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.
CVE-2026-97275 2026-10-06 5.3 Medium
Improper Validation of Specified Quantity in Input vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Input Data Manipulation.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28.
CVE-2026-97257 2026-10-06 8.8 High
Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.
CVE-2026-97071 2026-10-06 5.3 Medium
Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17.
CVE-2026-94299 2026-10-06 6.5 Medium
The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers to forge payment confirmations and change the status of arbitrary orders on any installation where that secret has been left at its default empty value.
CVE-2026-94278 2026-10-06 5.5 Medium
The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belonging to other users, including administrators, and to corrupt unrelated stored site data that referenced the old file path.
CVE-2026-93617 2026-10-06 7.2 High
Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1.
CVE-2026-41563 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions.
CVE-2026-41558 2026-10-06 7.5 High
Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.
CVE-2026-39791 2026-10-06 5.3 Medium
Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions.
CVE-2026-39789 2026-10-06 7.5 High
Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.
CVE-2026-39760 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.
CVE-2026-39757 2026-10-06 9.9 Critical
Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions.
CVE-2026-39756 2026-10-06 6.5 Medium
Unauthenticated Insecure Direct Object References (IDOR) in Wappointment <= 2.7.7 versions.
CVE-2026-39755 2026-10-06 9.9 Critical
Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions.