Export limit exceeded: 402016 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402016 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402016 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-92767 | 2 Wordpress-extensions, Zayedbaloch | 2 Twenty20 Image Before-after, Twenty20 Image Before-after | 2026-10-04 | 6.4 Medium |
| The Twenty20 Image Before-After plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'offset' Shortcode Attribute in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-103065 | 2 Themeum, Wordpress-extensions | 2 Kirki, Kirki | 2026-10-04 | 8.2 High |
| Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1. | ||||
| CVE-2026-103342 | 2 Unlimited-elements, Wordpress-extensions | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor | 2026-10-04 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20. | ||||
| CVE-2026-105124 | 2 Vincent-peugnet, Wcms | 2 Wcms, Wcms | 2026-10-04 | 6.1 Medium |
| W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges. | ||||
| CVE-2026-103355 | 2 Unlimited-elements, Wordpress-extensions | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor | 2026-10-04 | 9.3 Critical |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20. | ||||
| CVE-2026-75762 | 1 Redhat | 1 Multicluster Globalhub | 2026-10-04 | 6.8 Medium |
| No description is available for this CVE. | ||||
| CVE-2026-80220 | 1 Postgres-exporter | 1 Postgres-exporter | 2026-10-04 | 5.4 Medium |
| No description is available for this CVE. | ||||
| CVE-2026-76594 | 1 Advisor-backend | 1 Advisor-backend | 2026-10-04 | 8.1 High |
| A flaw was found in advisor-backend. A network-adjacent unauthenticated attacker could exploit a vulnerability in the `/private/import_content/` endpoint, which lacks proper authentication and permission checks. This allows the attacker to overwrite the global Advisor rule, resolution, and playbook catalogue. When combined with another vulnerability involving unsafe YAML deserialization, this could lead to arbitrary code execution on affected systems. | ||||
| CVE-2026-76595 | 1 Advisor-backend | 1 Advisor-backend | 2026-10-04 | N/A |
| A flaw was found in advisor-backend. Multiple code paths within the application deserialize YAML (YAML Ain't Markup Language) with an unsafe full Loader, which can instantiate arbitrary Python objects via YAML tags. An unauthenticated remote attacker can exploit this by submitting specially crafted YAML input, leading to remote code execution (RCE) within the `advisor-backend` pod. This compromise could allow access to shared database credentials and impact all tenants. | ||||
| CVE-2026-87052 | 1 Operator-foundry | 1 Operator-foundry | 2026-10-04 | 2.6 Low |
| A flaw was found in operator-foundry. The absence of automated dependency-update and vulnerability-scanning configurations in the repository increases the risk of undetected security vulnerabilities. This lack of automated security checks could potentially lead to the inclusion of known vulnerable components, which might then be exploited by an attacker if those underlying vulnerabilities are present and exploitable. | ||||
| CVE-2026-87054 | 1 Operator-sdk-builder | 1 Operator-sdk-builder | 2026-10-04 | 4.2 Medium |
| A flaw was found in operator-sdk-builder. The containers-policy.json configuration file defaults to insecureAcceptAnything for container image registries that are not explicitly listed. This default setting causes signature verification to be entirely skipped for images pulled from these unlisted registries, which could allow for the use of untrusted or malicious container images. | ||||
| CVE-2026-87057 | 1 Olm-operator-konflux-sample | 1 Olm-operator-konflux-sample | 2026-10-04 | 4.2 Medium |
| A flaw was found in olm-operator-konflux-sample. The build pipelines use mutable floating tags to reference runtime base images instead of immutable SHA256 digests. This configuration allows for the content of the base images to be altered without detection, potentially leading to the introduction of malicious code or unexpected changes in the build process. An attacker could exploit this to compromise the integrity of the software supply chain. | ||||
| CVE-2026-87061 | 1 Olm-operator-konflux-sample | 1 Olm-operator-konflux-sample | 2026-10-04 | 2.6 Low |
| A flaw was found in olm-operator-konflux-sample. The `bundle-hack/update_bundle.sh` script lacks mechanisms to stop execution immediately upon encountering an error. This oversight allows critical data processing steps, such as those involving `skopeo` or `jq` commands, to fail silently and proceed with outdated or incomplete information. Consequently, this could lead to data integrity issues within the system. | ||||
| CVE-2026-87064 | 1 Konflux-operator-tasks | 1 Konflux-operator-tasks | 2026-10-04 | 2.6 Low |
| A flaw was found in konflux-operator-tasks. The GitHub workflows used by this component do not explicitly define their required permissions. This oversight means the workflows may inherit default access tokens that grant broader privileges than intended. Such excessive permissions could potentially allow an attacker to gain unauthorized access or perform actions beyond the intended scope, leading to information disclosure or unauthorized modifications. | ||||
| CVE-2026-94282 | 2 Libxi, X.org | 2 Libxi, Libxi | 2026-10-04 | 5.6 Medium |
| An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client. | ||||
| CVE-2026-95622 | 1 Modemmanager | 1 Modemmanager | 2026-10-04 | 6.5 Medium |
| A flaw was found in ModemManager. When parsing a Cell Broadcast Message, some 3GPP data-coding-scheme values (8-bit and reserved character sets) are not handled. The process hits a reachable assertion and aborts. An attacker who can deliver a crafted Cell Broadcast PDU over the radio network, or via a modem AT channel, can cause ModemManager to exit. Repeated aborts can exhaust systemd's default start limit and leave the service failed. | ||||
| CVE-2026-94603 | 1 Podman Project | 1 Podman | 2026-10-04 | 8.6 High |
| A flaw was found in Podman. When a container image with checkpoint annotations is executed using the podman run command, Podman treats the image as a restored checkpoint and ignores user-specified sandboxing options, such as dropped privileges. An attacker can exploit this issue by enticing a user to run a specially crafted image, leading to a container sandbox bypass and potential execution with elevated system privileges. | ||||
| CVE-2026-103431 | 1 Collectl | 1 Collectl | 2026-10-04 | 7.7 High |
| colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored host to inject escape sequences into the terminal of an operator running colmux, via a crafted process name (argv[0]). | ||||
| CVE-2026-67172 | 1 Hcltech | 1 Bigfix Service Management | 2026-10-04 | 3.7 Low |
| HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to certain API endpoints . This information could enable an attacker to facilitate further attacks. | ||||
| CVE-2025-31980 | 1 Hcltech | 1 Bigfix Service Management | 2026-10-04 | 4.3 Medium |
| HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, enabling potential injection attacks or errors in downstream processing systems. | ||||