Export limit exceeded: 402754 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402754 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-39796 | 2 Flipper Code, Wordpress-extensions | 2 Advanced Posts Listing – Show Post List Easily, Advanced Posts Listing–show Post List Easily | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions. | ||||
| CVE-2026-39797 | 2 Data443, Wordpress-extensions | 2 Gdpr Framework By Data443, Gdpr Framework By Data443 | 2026-10-06 | 9.8 Critical |
| Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions. | ||||
| CVE-2026-39798 | 2 Themetechmount, Wordpress-extensions | 2 Truebooker, Truebooker | 2026-10-06 | 6.5 Medium |
| Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions. | ||||
| CVE-2026-40806 | 2 Plugin-devs, Wordpress-extensions | 2 Blog, Posts And Category Filter For Elementor, Blog Posts And Category Filter For Elementor | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions. | ||||
| CVE-2026-40807 | 2 Aman, Wordpress-extensions | 2 Cf7 Views – Complete Entry Management For Contact Form 7, Cf7 Views | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.6 versions. | ||||
| CVE-2026-41555 | 2 Weblizar, Wordpress-extensions | 2 Newsletter Subscription Form – User Subscriptions Form, Capture Email, Newsletter Subscription Form – User Subscriptions Form, Capture Email | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions. | ||||
| CVE-2026-41559 | 2 Pluginjoy, Wordpress-extensions | 2 Safesnap – Verified Wordpress Backup & Restore, Safesnap | 2026-10-06 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in SafeSnap – Verified WordPress Backup & Restore <= 2.1.2 versions. | ||||
| CVE-2026-41560 | 2 Wordpress-extensions, Wxdlabs | 2 Wxd Backup Lite, Wxd Backup Lite | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions. | ||||
| CVE-2026-41561 | 2 Adrian Lin, Wordpress-extensions | 2 Museder Restoreone, Museder Restoreone | 2026-10-06 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Museder RestoreOne <= 2.7.276 versions. | ||||
| CVE-2026-41562 | 2 Norvisgabriel, Wordpress-extensions | 2 Norvis Backup, Norvis Backup | 2026-10-06 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions. | ||||
| CVE-2026-42413 | 2 Daftplug, Wordpress-extensions | 2 Snapshotify, Snapshotify | 2026-10-06 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in Snapshotify – All-in-One Backup & Restore & Migrate <= 1.3.2 versions. | ||||
| CVE-2026-98356 | 1 Linux | 1 Linux Kernel | 2026-10-06 | 7.0 High |
| In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup bnxt_re_init_dcb_wq() ignores a failed allocation. The async DCB handler later calls queue_work() on the NULL pointer. | ||||
| CVE-2026-106497 | 2026-10-06 | 4.3 Medium | ||
| Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent catalog property permission evaluation. In deployments that use affected value-based catalog permission conditions as a confidentiality boundary, an authenticated user could receive catalog entity data that policy authors intended to restrict. This issue is fixed in version 3.9.1. | ||||
| CVE-2026-106496 | 2026-10-06 | 3.1 Low | ||
| Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host. This issue is fixed in version 3.9.1. | ||||
| CVE-2026-102169 | 2026-10-06 | 6.5 Medium | ||
| On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can crash the portal service with a crafted HTTP request. The service automatically restarts, but a sustained low-rate attack can cause a persistent denial of service of the captive portal. Remote code execution is not possible. | ||||
| CVE-2026-102168 | 2026-10-06 | 6.5 Medium | ||
| On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is not possible. | ||||
| CVE-2026-102167 | 2026-10-06 | 7.5 High | ||
| On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access point's wired uplink. | ||||
| CVE-2026-102165 | 2026-10-06 | 7.5 High | ||
| On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the service to crash or potentially achieve remote code execution. This exploit requires an uncommonly used non-default streaming mode. | ||||
| CVE-2026-102164 | 2026-10-06 | 3.1 Low | ||
| On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific configuration unique to the VESPA use-case), a wireless client associated to the tunnelled SSID can send a crafted packet, causing the access point to reveal memory contents in network traffic. No write primitive or remote code execution is possible. | ||||
| CVE-2026-102163 | 2026-10-06 | 8.8 High | ||
| On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthenticated attacker within radio frequency (RF) proximity can send a crafted frame to crash the sensor service, disabling WIPS monitoring on the access point, or potentially achieve remote code execution. No wireless association or authentication is required. | ||||