Export limit exceeded: 404216 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404216 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-106609 | 2026-10-10 | 7.5 High | ||
| Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcash-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bayarcash WooCommerce: from n/a through 4.4.2. | ||||
| CVE-2026-94160 | 2026-10-10 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeStek ThemeStek Extras for LabtechCO Theme themestek-labtechco-extras allows Reflected XSS.This issue affects ThemeStek Extras for LabtechCO Theme: from n/a through 8.4. | ||||
| CVE-2026-62044 | 2026-10-10 | 7.2 High | ||
| Deserialization of Untrusted Data vulnerability in bPlugins Super Video Player super-video-player allows Object Injection.This issue affects Super Video Player: from n/a through 1.8.13. | ||||
| CVE-2025-8787 | 1 Portabilis | 1 I-diario | 2026-10-10 | 3.5 Low |
| A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. The affected element is an unknown function of the file /registros-de-conteudos-por-disciplina/ of the component Registro das atividades. The manipulation of the argument Registro de atividades/Conteúdos results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as 821342cd8d952e8bd214cb16145da785a92f5681. A patch should be applied to remediate this issue. The vendor confirms: "Audited values shown on that screen are now sanitized on output: only a minimal allowlist of basic formatting tags is kept and all attributes are stripped, so injected <script> or event-handler markup is removed and displayed as inert text." | ||||
| CVE-2025-8786 | 1 Portabilis | 1 I-diario | 2026-10-10 | 3.5 Low |
| A vulnerability was identified in Portabilis i-Diario up to 1.5.0. Impacted is an unknown function of the file /registros-de-conteudos-por-areas-de-conhecimento/ of the component Registro das atividades. The manipulation of the argument Registro de atividades/Conteúdos leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used. The identifier of the patch is 821342cd8d952e8bd214cb16145da785a92f5681. It is suggested to install a patch to address this issue. The vendor confirms: "Audited values shown on that screen are now sanitized on output: only a minimal allowlist of basic formatting tags is kept and all attributes are stripped, so injected <script> or event-handler markup is removed and displayed as inert text." | ||||
| CVE-2025-8511 | 1 Portabilis | 1 I-diario | 2026-10-10 | 3.5 Low |
| A vulnerability was found in Portabilis i-Diario 1.5.0. Impacted is an unknown function of the file /diario-de-observacoes/ of the component Observações. Performing a manipulation of the argument Descrição results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The patch is named 821342cd8d952e8bd214cb16145da785a92f5681. It is suggested to install a patch to address this issue. The vendor confirms: "Audited values shown on that screen are now sanitized on output: only a minimal allowlist of basic formatting tags is kept and all attributes are stripped, so injected <script> or event-handler markup is removed and displayed as inert text." | ||||
| CVE-2026-108586 | 2026-10-10 | 5.4 Medium | ||
| 1MCP Agent (@1mcp/agent) 0.20.0 through 0.39.0 contains an incorrect authorization vulnerability that allows authenticated clients to bypass OAuth tag-scope enforcement using negated advanced tag-filter expressions. Attackers holding a single-tag token can send a filter like not <granted-tag> to list and invoke tools on backend MCP servers outside their granted scopes. | ||||
| CVE-2026-108583 | 2026-10-10 | 4.2 Medium | ||
| zotero-mcp 0.10.0 through 0.14.1 contains a server-side request forgery vulnerability that allows attackers to reach internal services because _fetch_embedded_metadata fetches URLs without destination validation. Attackers can steer the agent via prompt injection into calling zotero_add_by_url, causing requests to loopback, private, or link-local hosts directly or via redirects, leaking citation meta-tags and error details. | ||||
| CVE-2026-108582 | 2026-10-10 | 5.5 Medium | ||
| GenOffice through 0.11.505 contains an incorrect permissions vulnerability in its HTTP MCP server file store that allows local unprivileged users to read uploaded and generated documents. Attackers can list the world-readable genoffice-mcp-http directory under the system temporary directory to read client uploads and converted outputs, bypassing the HTTP bearer token. | ||||
| CVE-2026-108581 | 2026-10-10 | 6.5 Medium | ||
| TencentCloud Octop through 1.0.2b6 contains a missing authorization vulnerability that allows authenticated low-privileged users to read stored provider API keys via GET /api/providers and GET /api/voice/providers. Attackers can query these endpoints, which only validate the JWT, to obtain plaintext LLM and voice provider API keys and abuse the upstream provider accounts. | ||||
| CVE-2026-108580 | 2026-10-10 | 6.5 Medium | ||
| AniWorld Downloader before 5.3.0 contains an improper restriction of authentication attempts vulnerability in the WebUI /login POST handler that allows unauthenticated attackers to guess passwords without throttling. Attackers can enumerate usernames through verify_user response timing and brute-force passwords on exposed WebUI instances to take over accounts. | ||||
| CVE-2026-108579 | 1 Openpanel | 1 Openpanel | 2026-10-10 | 4.2 Medium |
| OpenPanel through 2.3.0 contains a CSV formula injection vulnerability that allows unauthenticated attackers to embed spreadsheet formulas by supplying crafted profile IDs to the /track endpoint. Attackers can send tracking events with profile IDs like =HYPERLINK(...) matching a cohort, so exported cohort CSVs execute formulas that exfiltrate adjacent cell data. | ||||
| CVE-2026-108162 | 1 Smp46 | 1 Pingvin-share-x | 2026-10-10 | 6.5 Medium |
| Pingvin Share X before 1.22.0 contains a rate limit bypass vulnerability that allows unauthenticated remote attackers to evade per-IP throttling because backend/src/main.ts unconditionally trusts proxy headers. Attackers can rotate spoofed X-Forwarded-For values against /api/auth/signIn, /api/auth/signIn/totp, and /api/auth/resetPassword to brute-force passwords and TOTP codes and forge logged client IP addresses. | ||||
| CVE-2026-108163 | 1 Smp46 | 1 Pingvin-share-x | 2026-10-10 | 6.5 Medium |
| Pingvin Share X before 1.22.0 contains an ineffective rate limiting vulnerability because throttler TTL values specified in seconds are interpreted as milliseconds. Unauthenticated attackers can send effectively unthrottled requests to /api/auth/signIn, /api/auth/signIn/totp and /api/auth/resetPassword to brute-force passwords and TOTP codes. | ||||
| CVE-2026-108114 | 1 Strapi | 1 Strapi | 2026-10-10 | 4.3 Medium |
| Strapi 5.47.0 through 5.57.0 contains an improper authorization vulnerability that allows admin API tokens to retain all-field Content Manager access after the owner's role is field-restricted. Because reconcileTokenPermissionsToUserCeiling ignores token permissions with omitted or null fields, token holders can keep reading content fields an administrator removed from the role. | ||||
| CVE-2026-108115 | 1 Kortix-ai | 1 Suna | 2026-10-10 | 4.9 Medium |
| Kortix Suna 0.10.7 before 0.13.52 contains a server-side request forgery vulnerability that allows project managers to bypass the isPrivateIp guard by supplying IPv6 6to4 or Teredo addresses that embed private IPv4 destinations. Attackers holding project.connector.write can set connector base_url, OpenAPI, Postman, or MCP URLs to reach internal services and cloud metadata endpoints and read responses. | ||||
| CVE-2026-108549 | 1 Chenhg5 | 1 Cc-connect | 2026-10-10 | 8.1 High |
| cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webhook listener on port 8080 can forge updates with an allowed or admin user_id to run privileged commands like /shell on the host. | ||||
| CVE-2026-108555 | 2026-10-10 | 4.2 Medium | ||
| PairDrop through 1.11.2 contains an IP spoofing vulnerability in Peer._setIP that allows remote attackers to join other networks' discovery rooms by supplying a forged cf-connecting-ip header. Attackers who know a victim's public IP can appear as a local device on self-hosted instances not behind Cloudflare to send or receive files. | ||||
| CVE-2026-108554 | 2026-10-10 | 5.3 Medium | ||
| PDFMathTranslate (pdf2zh) through 1.9.11 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the server fetch arbitrary URLs via the Link input. The translate_file handler passes user URLs to download_with_limit without scheme or address validation, letting attackers reach internal services and cloud metadata endpoints and retrieve returned PDFs. | ||||
| CVE-2026-108553 | 1 Openrefine | 1 Openrefine | 2026-10-10 | 7.5 High |
| OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a crafted engine parameter, executing operating system commands as the OpenRefine user. | ||||