Export limit exceeded: 102065 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (102065 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-97474 | 1 Linux | 1 Linux Kernel | 2026-10-01 | 7.4 High |
| In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: purge async notifications upon nic error This fixes a kernel panic in reconfig failure: 1. we have a BSS connection 2. we have a NAN connection 3. FW error occurs 4. reconfig restores the BSS connection 5. however, restoring the NAN connection fails due to a FW error. 6. erroneously, ieee80211_handle_reconfig_failure is called and marks all interfaces as not-in-driver (will be fixed in a different patch). 7. mac80211 frees the links of the BSS connection but doesn't tell the driver about that, as it thinks that this vif is not in the driver. 8. in ieee80211_stop_device, *ALL* wiphy works are getting flushed (erroneously?) 9. Therefore, async_handlers_wk is being executed, processing the statistics notification that was received after we restored the BSS connection. 10. the notification handler dereferences fw_id_to_bss_conf[id], which is now a dangling pointer, as mac80211 already freed this link in (7). 11. On the first access to one of the links fields, we panic. While this can and should be fixed by removing the call to ieee80211_handle_reconfig_failure in (6), it is also not a good idea to carry and maybe handle notifications from a dead FW. We do purge the notifications when we stop the FW, but in reconfig failure we stop the FW too late, after the notifications are processed. In addition, async_handlers_wk can always be scheduled before the reconfig work. Purge the notifications immediately when transport notifies about a nic error. | ||||
| CVE-2026-97284 | 2026-10-01 | 8.8 High | ||
| Contributor PHP Object Injection in Icegram <= 3.1.31 versions. | ||||
| CVE-2026-100268 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 7.7 High |
| In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates | ||||
| CVE-2026-84842 | 2 Ibm, Linux | 2 Guardium Data Protection, Linux Kernel | 2026-10-01 | 8.1 High |
| IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity. | ||||
| CVE-2026-84440 | 2 Ibm, Linux | 2 Guardium Data Protection, Linux Kernel | 2026-10-01 | 7.5 High |
| IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges. | ||||
| CVE-2026-103398 | 1 Liquid-co | 1 Opensave | 2026-10-01 | 8.1 High |
| OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest and sync routes. | ||||
| CVE-2026-103471 | 1 Corvusoft | 1 Restbed | 2026-10-01 | 7.5 High |
| restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP connections and stream bytes indefinitely without sending the header delimiter, forcing the server to allocate unbounded heap memory until the process is killed. | ||||
| CVE-2026-103474 | 1 Yii2-starter-kit | 1 Yii2-starter-kit | 2026-10-01 | 8.8 High |
| yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute arbitrary code on the server. | ||||
| CVE-2026-101880 | 1 Openclaw | 1 Openclaw Windows Node | 2026-10-01 | 8.8 High |
| OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving arbitrary command execution on Windows hosts. | ||||
| CVE-2026-101884 | 1 Openclaw | 1 Openclaw Windows Node | 2026-10-01 | 7.5 High |
| OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution. | ||||
| CVE-2026-101885 | 1 Zeroclaw-labs | 1 Zeroclaw | 2026-10-01 | 7.8 High |
| ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins that write arbitrary files to paths outside the plugins directory, such as shell startup files, enabling code execution. | ||||
| CVE-2026-96561 | 2 Tigroumeow, Wordpress-extensions | 2 Ai Engine – The Chatbot And Ai Framework For Wordpress, Ai Engine | 2026-10-01 | 7.2 High |
| The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.0 This is due to a chain of missing input neutralization and output escaping across the /mwai-ui/v1/chats/submit REST endpoint, the PHP error-log parser (MeowKit_MWAI_Helpers::php_error_logs), the Advisor task (Meow_MWAI_Modules_Advisor::run_advisor), and the Advisor dashboard widget (advisor_metabox): the server-parameter denylist in chat_submit strips only exact key names such as 'model' while convert_keys() later canonicalizes 'model_' back to 'model', allowing an unauthenticated caller to place an attacker-controlled string (including CR/LF) into $query->model; final_checks() throws an Exception whose message embeds that raw string, and the non-streaming, non-admin catch branch writes it to the PHP error log unmodified — creating a forged log line that the plugin's own parser subsequently returns as recent PHP-error content; run_advisor() then appends that content verbatim to the AI prompt (indirect prompt injection — CWE-1427), the returned JSON is stored in the mwai_advisor_data option with no schema validation or HTML sanitization, and advisor_metabox() concatenates the resulting 'title' and 'description' values directly into the WordPress dashboard widget without esc_html(), wp_kses(), or equivalent escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the WordPress dashboard. | ||||
| CVE-2026-101147 | 1 Wordpress-extensions | 2 Featured Image From Url (fifu) Free, Featured Image From Url (fifu) Premium | 2026-10-01 | 8.8 High |
| The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Premium WordPress plugin before 8.2.8 do not correctly enforce the REST API nonce, disabling the check for the whole request when a crafted URL is used, which could allow attackers to make a logged-in administrator perform any REST API action, such as creating a new administrator account, via a CSRF attack. | ||||
| CVE-2026-19253 | 1 Wordpress-extensions | 1 Cache Enabler | 2026-10-01 | 8.7 High |
| The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated users to delete arbitrary files and directories on sites where another installed Cache Enabler WordPress plugin before 1.8.17 or passes a request-derived URL to its public cache-clearing hook. | ||||
| CVE-2026-81739 | 2 Paytm, Wordpress-extensions | 2 Payment Gateway, Paytm Payment Gateway | 2026-10-01 | 7.5 High |
| The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts that will run in the session of a store administrator. | ||||
| CVE-2026-81809 | 2 Paytm, Wordpress-extensions | 2 Payment Gateway, Paytm Payment Gateway | 2026-10-01 | 7.5 High |
| The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-89296 | 1 Wordpress-extensions | 1 Pro Like Button | 2026-10-01 | 8.6 High |
| The Pro Like Button WordPress plugin before 2.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-92412 | 1 Wordpress-extensions | 1 Five Star Restaurant Reviews | 2026-10-01 | 7.1 High |
| The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in administrator. | ||||
| CVE-2026-96255 | 1 Wordpress-extensions | 1 Payments For Hubtel | 2026-10-01 | 7.5 High |
| The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plain text, allowing unauthenticated attackers to obtain those credentials. | ||||
| CVE-2026-14995 | 2 Optimizingmatters, Wordpress-extensions | 2 Autooptimize, Autoptimize | 2026-10-01 | 7.2 High |
| The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Path in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Critical CSS feature to be active with a valid API key configured, as this is the precondition for unauthenticated frontend requests to trigger queue entries via ao_ccss_enqueue(). | ||||