Export limit exceeded: 402914 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (402914 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-105170 1 Kishor-23 1 Food-waste-management-system 2026-10-06 7.3 High
A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file admin/signup.php of the component Admin Signup. This manipulation of the argument sign causes missing authentication. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-105166 1 Kishor-23 2 Food-waste-management-system, Food Waste Management System 2026-10-06 7.3 High
A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of the file fooddonateform.php of the component Food Donation Form. Performing a manipulation of the argument image-choice results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-105161 1 Invariant-systems-ai 1 Aiir 2026-10-06 5.3 Medium
A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The attack can be executed remotely. It is advisable to upgrade the affected component. The GitHub repository of this project is not available anymore. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-106508 2026-10-06 5.3 Medium
Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. When using the local TechDocs publisher (techdocs.publisher.type: 'local'), it was possible for the documentation serving endpoint to follow filesystem references outside the intended documentation tree, potentially exposing host files to authenticated users. This is mitigated by the fact that exploration requires preconditions that do not arise through normal MkDocs operation. Cloud-based publishers (S3, GCS, Azure Blob Storage) are not affected. This issue is fixed in version 1.15.4.
CVE-2026-104047 1 Redhat 2 Enterprise Linux, Openshift 2026-10-06 5.3 Medium
A flaw was found in SSSD. When configured to use Microsoft Entra ID, search inputs are not properly sanitized before being incorporated into directory query filters. A local user can exploit this vulnerability by submitting a crafted lookup request, manipulating the query logic to cause unauthorized information disclosure from the directory.
CVE-2026-39758 2 Midtrans, Wordpress-extensions 2 Midtrans-woocommerce, Midtrans-woocommerce 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Midtrans-WooCommerce <= 2.32.3 versions.
CVE-2026-39759 2 Amentotech, Wordpress-extensions 2 Workreap, Workreap 2026-10-06 9.9 Critical
Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions.
CVE-2026-39761 2 Elightup, Wordpress-extensions 2 Meta Box Aio, Meta Box Aio 2026-10-06 9.8 Critical
Unauthenticated Privilege Escalation in Meta Box AIO <= 3.7.1 versions.
CVE-2026-39762 2 Patterns In The Cloud, Wordpress-extensions 2 Autoship Cloud For Woocommerce Subscription Products, Autoship Cloud For Woocommerce Subscription Products 2026-10-06 6.5 Medium
Missing Authorization vulnerability in Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products autoship-cloud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.17.1.
CVE-2026-39764 2 Radiustheme, Wordpress-extensions 2 Radius Booking — Booking Calendar For Appointments & Services, Radius Booking 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments &amp; Services <= 1.0.19 versions.
CVE-2026-39765 2 Webappick, Wordpress-extensions 2 Challan, Challan 2026-10-06 7.2 High
Shop Manager Privilege Escalation in Challan <= 3.7.88 versions.
CVE-2026-39766 2 Reputeinfosystems, Wordpress-extensions 2 Arforms, Arforms 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.
CVE-2026-39767 2 Baseapp, Wordpress-extensions 2 Wpbase Cache, Wpbase Cache 2026-10-06 6.5 Medium
Subscriber Denial of Service Attack in WPBase Cache <= 5.5.6 versions.
CVE-2026-39769 2 Iqonicdesign, Wordpress-extensions 2 Graphina, Graphina 2026-10-06 7.5 High
Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions.
CVE-2026-39770 2 Amentotech, Wordpress-extensions 2 Doctreat Core, Doctreat 2026-10-06 10 Critical
Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions.
CVE-2026-39771 2 Mightynetworks Vs Buddyboss, Wordpress-extensions 2 Buddyboss Platform, Buddyboss Platform 2026-10-06 8.5 High
Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions.
CVE-2026-39772 2 Bestwebsoft, Wordpress-extensions 2 Captcha By Bestwebsoft, Captcha By Bestwebsoft 2026-10-06 5.3 Medium
Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions.
CVE-2026-39773 2 Amentotech, Wordpress-extensions 2 Doctreat Core, Doctreat Core 2026-10-06 10 Critical
Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions.
CVE-2026-39774 2 Tourfic Ai Studio, Wordpress-extensions 2 Tourfic Pro, Tourfic Pro 2026-10-06 8.8 High
Unauthenticated Privilege Escalation in Tourfic Pro <= 1.17.3 versions.
CVE-2026-39775 2 Dexignzone, Wordpress-extensions 2 Jobzilla - Job Board Wordpress Theme, Jobzilla 2026-10-06 8.8 High
Subscriber Privilege Escalation in JobZilla - Job Board WordPress Theme <= 2.2 versions.