Export limit exceeded: 399927 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 399927 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399927 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-7171 | 1 Tpvenlanube | 1 Cloud Web Application | 2026-09-30 | N/A |
| Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7171: parameter 'Apellido 1' in the endpoint '/administrator/index.php?page=admin.user_add&user_id=45&option=com_virtuemart'. Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent. | ||||
| CVE-2026-7170 | 1 Tpvenlanube | 1 Cloud Web Application | 2026-09-30 | N/A |
| Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7170: parameter 'vendor_store_name' in the endpoint '/administrator/index.php?pshop_mode=admin&page=store.store_add&option=com_virtuemart&vendor_id=[ID]'. Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent. | ||||
| CVE-2026-75873 | 2026-09-30 | 9.8 Critical | ||
| The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution. | ||||
| CVE-2026-75824 | 2026-09-30 | 5.3 Medium | ||
| The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled. The created account receives the site's default role. | ||||
| CVE-2026-75823 | 2026-09-30 | 7.4 High | ||
| The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor. This affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained this way. | ||||
| CVE-2026-62085 | 2026-09-30 | 7.6 High | ||
| Administrator SQL Injection in WP Activity Log <= 5.6.6 versions. | ||||
| CVE-2026-62083 | 2026-09-30 | 5.4 Medium | ||
| Subscriber Other Vulnerability Type in Creator LMS <= 1.2.19 versions. | ||||
| CVE-2026-62081 | 2026-09-30 | 5.4 Medium | ||
| Contributor Insecure Direct Object References (IDOR) in Flexible PDF Coupons <= 1.14.11 versions. | ||||
| CVE-2026-62080 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Happy Addons for Elementor <= 3.23.1 versions. | ||||
| CVE-2026-62079 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions. | ||||
| CVE-2026-62078 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. | ||||
| CVE-2026-27371 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions. | ||||
| CVE-2026-27085 | 2026-09-30 | 2.7 Low | ||
| Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions. | ||||
| CVE-2026-103117 | 1 Os4ed | 1 Opensis-classic | 2026-09-30 | 4.7 Medium |
| A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-103109 | 1 Pexip | 1 Infinity | 2026-09-30 | 7.7 High |
| Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve memory corruption. | ||||
| CVE-2026-103104 | 1 Pexip | 1 Infinity | 2026-09-30 | 7.5 High |
| Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. | ||||
| CVE-2026-103099 | 1 Pexip | 1 Infinity | 2026-09-30 | 7.5 High |
| Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service. | ||||
| CVE-2026-103057 | 2026-09-30 | 4.3 Medium | ||
| AiSOC versions 5.1.0 before 12.0.0 contain an authentication bypass vulnerability in the realtime service internal endpoints POST /internal/agent-event and POST /internal/push. Attackers can post arbitrary events with spoofed tenant identifiers to broadcast malicious content over WebSocket and Redis SSE channels or send unauthorized notifications to registered devices. | ||||
| CVE-2026-103053 | 2026-09-30 | 5.4 Medium | ||
| AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and AISOC_ACTIONS_SERVICE_TOKEN is empty in the default Docker Compose deployment. Unauthenticated attackers can list response-action integrations, submit and approve actions on behalf of arbitrary principals, and dispatch containment actions using vendor credentials. | ||||
| CVE-2026-103041 | 1 Modeltc | 1 Lightllm | 2026-09-30 | 9.8 Critical |
| LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges. | ||||