Export limit exceeded: 401546 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (401546 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-94669 | 2026-10-05 | 5.3 Medium | ||
| Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13. | ||||
| CVE-2026-59788 | 1 Zabbix | 1 Zabbix | 2026-10-05 | N/A |
| The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in the browser. This means a crafted media type configuration, deliverable as an import file, runs arbitrary JavaScript as the Super Admin who grants consent. | ||||
| CVE-2026-59787 | 1 Zabbix | 1 Zabbix | 2026-10-05 | N/A |
| The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity. | ||||
| CVE-2026-59786 | 1 Zabbix | 1 Zabbix | 2026-10-05 | N/A |
| Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity. | ||||
| CVE-2026-59785 | 1 Zabbix | 1 Zabbix | 2026-10-05 | N/A |
| Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them uncover it. | ||||
| CVE-2026-59783 | 1 Zabbix | 1 Zabbix | 2026-10-05 | N/A |
| The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database. | ||||
| CVE-2026-59782 | 1 Zabbix | 1 Zabbix | 2026-10-05 | N/A |
| The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator. | ||||
| CVE-2026-105287 | 1 Feelec-yishu | 1 Feelcrm-os | 2026-10-05 | 6.3 Medium |
| A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpoint. This manipulation of the argument groups[] causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2025-58222 | 1 Wordpress | 1 Wordpress | 2026-10-05 | 5.3 Medium |
| Missing Authorization vulnerability in Dynamic Web Lab Team Manager wp-team-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team Manager: from n/a through 2.6.8. | ||||
| CVE-2026-19395 | 1 Qt | 1 Qt For Mcus | 2026-10-05 | N/A |
| In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty values. The check fails and reports an error, and the default error handler halts the device. | ||||
| CVE-2026-20541 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 5.3 Medium |
| In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8911. | ||||
| CVE-2026-20543 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 5.5 Medium |
| In Modem, there is a possible information disclosure due to a logic error. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01645293; Issue ID: MSV-6761. | ||||
| CVE-2026-20538 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 5.3 Medium |
| In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8914. | ||||
| CVE-2026-17005 | 1 Wordpress-extensions | 1 Horizontal Scrolling Announcements | 2026-10-05 | 6.8 Medium |
| The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context on the front end, allowing users granted access to the announcement management page (Contributor and above, once permitted) to perform Stored Cross-Site Scripting attacks that execute in the browser of anyone viewing the announcement. | ||||
| CVE-2026-105291 | 1 Feelec-yishu | 1 Feelcrm-os | 2026-10-05 | 4.3 Medium |
| A vulnerability was identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function GroupController::index of the file App/Feelcrm/Index/Controller/GroupController.class.php of the component Department Search Endpoint. The manipulation of the argument keyword leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-104119 | 1 Wordpress-extensions | 1 Simple Shopping Cart | 2026-10-05 | 3.5 Low |
| The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where administrators do not have the unfiltered_html capability. | ||||
| CVE-2026-104118 | 2 Razorpay, Wordpress-extensions | 2 Razorpay For Woocommerce, Razorpay For Woocommerce | 2026-10-05 | 5.3 Medium |
| The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders. | ||||
| CVE-2025-53345 | 2 Thimpress, Wordpress | 2 Thim Core, Wordpress | 2026-10-05 | 8.8 High |
| Missing Authorization vulnerability in ThimPress Thim Core thim-core.This issue affects Thim Core: from n/a through 2.3.3. | ||||
| CVE-2025-6170 | 2 Redhat, Xmlsoft | 14 Ai Inference Server, Cert Manager, Discovery and 11 more | 2026-10-05 | 2.5 Low |
| A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections. | ||||
| CVE-2026-58015 | 2 Gnome, Redhat | 17 Glib, Ai Inference Server, Cert Manager and 14 more | 2026-10-05 | 5.9 Medium |
| A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash. | ||||