Export limit exceeded: 401352 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (401352 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-92767 | 2 Wordpress-extensions, Zayedbaloch | 2 Twenty20 Image Before-after, Twenty20 Image Before-after | 2026-10-04 | 6.4 Medium |
| The Twenty20 Image Before-After plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'offset' Shortcode Attribute in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-103065 | 2 Themeum, Wordpress-extensions | 2 Kirki, Kirki | 2026-10-04 | 8.2 High |
| Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1. | ||||
| CVE-2026-103342 | 2 Unlimited-elements, Wordpress-extensions | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor | 2026-10-04 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20. | ||||
| CVE-2026-96451 | 2 Ultimatemember, Wordpress-extensions | 2 Ultimate Member, Ultimate Member | 2026-10-04 | 8.8 High |
| Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1. | ||||
| CVE-2026-105123 | 2 Vincent-peugnet, Wcms | 2 Wcms, Wcms | 2026-10-04 | 8.8 High |
| W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path]. | ||||
| CVE-2026-105124 | 2 Vincent-peugnet, Wcms | 2 Wcms, Wcms | 2026-10-04 | 6.1 Medium |
| W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges. | ||||
| CVE-2026-103354 | 2 Stellarwp, Wordpress-extensions | 2 Gutenberg Blocks By Kadence Blocks, Gutenberg Blocks By Kadence Blocks | 2026-10-04 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Stored XSS.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.7.11.1. | ||||
| CVE-2026-97276 | 2 Veronalabs, Wordpress-extensions | 2 Wp Statistics, Wp Statistics | 2026-10-04 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics wp-statistics allows Reflected XSS.This issue affects WP Statistics: from n/a through 14.16.14. | ||||
| CVE-2026-103062 | 2 Cozmoslabs, Wordpress-extensions | 2 Translatepress, Translatepress | 2026-10-04 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Stored XSS.This issue affects TranslatePress: from n/a through 3.3.6. | ||||
| CVE-2026-103344 | 2 Unlimited-elements, Wordpress-extensions | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor | 2026-10-04 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20. | ||||
| CVE-2026-103355 | 2 Unlimited-elements, Wordpress-extensions | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor | 2026-10-04 | 9.3 Critical |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20. | ||||
| CVE-2026-97307 | 2 Stylemixthemes, Wordpress-extensions | 2 Cost Calculator Builder, Cost Calculator Builder | 2026-10-04 | 7.5 High |
| Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17. | ||||
| CVE-2026-104402 | 2 Farvisun, Wordpress-extensions | 2 Mindio Magic Mcp, Mindio Magic Mcp | 2026-10-04 | 4.3 Medium |
| Insertion of Sensitive Information Into Sent Data vulnerability in farvisun Mindio Magic MCP mindio-magic-mcp allows Retrieve Embedded Sensitive Data.This issue affects Mindio Magic MCP: from n/a through 0.5.6. | ||||
| CVE-2026-105218 | 1 Go-pay | 1 Gopay | 2026-10-04 | 7.4 High |
| gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses. | ||||
| CVE-2026-75762 | 1 Redhat | 1 Multicluster Globalhub | 2026-10-04 | 6.8 Medium |
| No description is available for this CVE. | ||||
| CVE-2026-80220 | 1 Postgres-exporter | 1 Postgres-exporter | 2026-10-04 | 5.4 Medium |
| No description is available for this CVE. | ||||
| CVE-2026-76594 | 1 Advisor-backend | 1 Advisor-backend | 2026-10-04 | 8.1 High |
| A flaw was found in advisor-backend. A network-adjacent unauthenticated attacker could exploit a vulnerability in the `/private/import_content/` endpoint, which lacks proper authentication and permission checks. This allows the attacker to overwrite the global Advisor rule, resolution, and playbook catalogue. When combined with another vulnerability involving unsafe YAML deserialization, this could lead to arbitrary code execution on affected systems. | ||||
| CVE-2026-76595 | 1 Advisor-backend | 1 Advisor-backend | 2026-10-04 | N/A |
| A flaw was found in advisor-backend. Multiple code paths within the application deserialize YAML (YAML Ain't Markup Language) with an unsafe full Loader, which can instantiate arbitrary Python objects via YAML tags. An unauthenticated remote attacker can exploit this by submitting specially crafted YAML input, leading to remote code execution (RCE) within the `advisor-backend` pod. This compromise could allow access to shared database credentials and impact all tenants. | ||||
| CVE-2026-87052 | 1 Operator-foundry | 1 Operator-foundry | 2026-10-04 | 2.6 Low |
| A flaw was found in operator-foundry. The absence of automated dependency-update and vulnerability-scanning configurations in the repository increases the risk of undetected security vulnerabilities. This lack of automated security checks could potentially lead to the inclusion of known vulnerable components, which might then be exploited by an attacker if those underlying vulnerabilities are present and exploitable. | ||||
| CVE-2026-87054 | 1 Operator-sdk-builder | 1 Operator-sdk-builder | 2026-10-04 | 4.2 Medium |
| A flaw was found in operator-sdk-builder. The containers-policy.json configuration file defaults to insecureAcceptAnything for container image registries that are not explicitly listed. This default setting causes signature verification to be entirely skipped for images pulled from these unlisted registries, which could allow for the use of untrusted or malicious container images. | ||||