Export limit exceeded: 399870 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399870 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-95587 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions. | ||||
| CVE-2026-97253 | 2026-09-30 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kreatura LayerSlider allows Reflected XSS. This issue affects LayerSlider: from n/a through 8.4.0. | ||||
| CVE-2026-69338 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 11 more | 2026-09-30 | 7.1 High |
| Use after free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-95311 | 1 Google | 1 Chrome | 2026-09-30 | 9.6 Critical |
| Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-92994 | 2026-09-30 | N/A | ||
| The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it. | ||||
| CVE-2026-93580 | 2026-09-30 | N/A | ||
| The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an IP check that is not enforced, allowing unauthenticated attackers who know a target order's parcel tracking number to forge its shipment status and prematurely mark the order completed. | ||||
| CVE-2026-93463 | 1 Basercms Users Community | 1 Basercms | 2026-09-30 | N/A |
| Cross-Site Scripting via Script Validation Bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused. | ||||
| CVE-2026-93464 | 1 Basercms Users Community | 1 Basercms | 2026-09-30 | N/A |
| Stored Cross-Site Scripting via custom content descriptions vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused. | ||||
| CVE-2026-93462 | 1 Basercms Users Community | 1 Basercms | 2026-09-30 | N/A |
| Missing authentication for critical function vulnerability exists in baserCMS . If a remote unauthenticated attacker there is a possibility that sensitive information could be obtained. | ||||
| CVE-2026-92872 | 2026-09-30 | N/A | ||
| Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information. | ||||
| CVE-2026-69355 | 1 Microsoft | 6 Exchange Server, Exchange Server 2016, Exchange Server 2019 and 3 more | 2026-09-30 | 8.8 High |
| External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-10739 | 1 Catonetworks | 1 Sdp Client | 2026-09-30 | N/A |
| Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe. | ||||
| CVE-2026-10726 | 1 Catonetworks | 1 Sdp Client | 2026-09-30 | N/A |
| Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement. | ||||
| CVE-2026-69356 | 1 Microsoft | 5 Exchange Server, Exchange Server 2016, Exchange Server 2019 and 2 more | 2026-09-30 | 9.3 Critical |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | ||||
| CVE-2026-102399 | 2026-09-30 | 5.4 Medium | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions. | ||||
| CVE-2026-102398 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions. | ||||
| CVE-2026-102396 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions. | ||||
| CVE-2026-102395 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions. | ||||
| CVE-2026-102386 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions. | ||||
| CVE-2026-102385 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. | ||||