Export limit exceeded: 399237 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399237 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-101111 | 1 Ordasoft.com | 1 Book Library (free) Extension For Joomla | 2026-09-29 | N/A |
| Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail page template, site/views/view_book/tmpl/default.php, echoes the raw title request parameter directly into a double-quoted HTML attribute with no escaping function of any kind (echo $_REQUEST["title"];). A value containing a double quote closes the attribute early and allows arbitrary HTML/JavaScript to follow. | ||||
| CVE-2026-97023 | 2 Flatpak, Redhat | 2 Flatpak, Enterprise Linux | 2026-09-29 | 7.1 High |
| A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is installed or upgraded. In system-wide installations, the deletion is performed as root. | ||||
| CVE-2026-102010 | 2 Gnu, Redhat | 6 Gcc, Enterprise Linux, Hardened Images and 3 more | 2026-09-29 | 7 High |
| A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption. | ||||
| CVE-2026-102004 | 1 Windriver | 1 Vxworks | 2026-09-29 | 7.8 High |
| Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption within the memory management subsystem. Fixed in Version 26.09 | ||||
| CVE-2026-87741 | 2 Brainstormforce, Wordpress-extensions | 2 Convertplug, Convertplus | 2026-09-29 | 8.8 High |
| The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action. The vulnerability exists because the action's nonce guard is gated behind an isset() check and fails open when the cp_admin_page_nonce parameter is omitted entirely, no capability check is performed on the callback, and sanitize_text_field() — applied to the $style value before it is concatenated directly into a shortcode string evaluated by do_shortcode() — does not strip shortcode delimiters, allowing an attacker to inject a second, fully attacker-controlled [smile_modal] invocation that causes smile_modal_popup() to pass attacker-supplied base64-decoded bytes to maybe_unserialize() with no allowed_classes restriction. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. | ||||
| CVE-2026-102006 | 1 Windriver | 1 Vxworks | 2026-09-29 | 5.5 Medium |
| In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process management subsystem failing to properly release allocated kernel memory before terminating the calling application. Fixed in Version 26.09 | ||||
| CVE-2026-97025 | 2 Flatpak, Redhat | 2 Flatpak, Enterprise Linux | 2026-09-29 | 3.2 Low |
| Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate the authenticated user against the OCI repository. Only OCI-based sources (e.g. as used by Fedora) are affected; libostree-based sources such as Flathub are not. | ||||
| CVE-2026-97026 | 2 Flatpak, Redhat | 2 Flatpak, Enterprise Linux | 2026-09-29 | 3.9 Low |
| Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used while installing apps or runtimes, potentially causing installation failures (denial of service); tampered content would fail signature/digest verification rather than being trusted. | ||||
| CVE-2026-97027 | 2 Flatpak, Redhat | 2 Flatpak, Enterprise Linux | 2026-09-29 | 3.6 Low |
| Flatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.desktop) and D-Bus Service (.service) files, instead of validating against an allowlist. A malicious Flatpak app can use this to cause denial of service (e.g. forced application restart loops) or to influence host D-Bus/systemd activation behavior beyond what the sandbox is intended to permit. | ||||
| CVE-2024-42002 | 1 Open Source Robotics Foundation | 1 Robot Operating System 2 (ros 2) | 2026-09-29 | 8.4 High |
| A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the --filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code. | ||||
| CVE-2026-102333 | 1 Cle-b | 1 Httpdbg | 2026-09-29 | 6.1 Medium |
| httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascript: scheme URLs that execute malicious scripts in the application origin when clicked, allowing access to captured request and response data including headers and tokens. | ||||
| CVE-2026-102361 | 1 Gz-yami | 1 Mall4j | 2026-09-29 | 9.1 Critical |
| mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data. | ||||
| CVE-2026-102362 | 1 Gz-yami | 1 Mall4j | 2026-09-29 | 5.3 Medium |
| mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in ProdCommController. Unauthenticated attackers can delete arbitrary product reviews by supplying the prodCommId parameter without authorization checks. | ||||
| CVE-2026-102363 | 1 Gz-yami | 1 Mall4j | 2026-09-29 | 3.7 Low |
| mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an order number parameter. Attackers can access carrier names, waybill numbers, and complete logistics trails for any order without authentication or ownership verification. | ||||
| CVE-2026-102364 | 1 Gz-yami | 1 Mall4j | 2026-09-29 | 5.4 Medium |
| mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office users by reusing their session tokens. Attackers can register on the public storefront and use their customer session token to access admin endpoints lacking @PreAuthorize permission checks, including menu listings, file uploads, and configuration endpoints. | ||||
| CVE-2026-102365 | 1 Gz-yami | 1 Mall4j | 2026-09-29 | 6.5 Medium |
| mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer address data. Authenticated attackers can call /user/addr/page and /user/addr/info endpoints to harvest all customer addresses including names, phone numbers, and postal information. | ||||
| CVE-2026-102366 | 1 Gz-yami | 1 Mall4j | 2026-09-29 | 4.4 Medium |
| mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorization checks and accept arbitrary file types without validation. Attackers with any authenticated token can upload HTML or SVG files that execute scripts in administrator browsers when accessed from the local storage path, resulting in stored cross-site scripting. | ||||
| CVE-2026-102367 | 1 Gz-yami | 1 Mall4j | 2026-09-29 | 5.4 Medium |
| mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to validate the enabled flag when issuing new sessions. Disabled user accounts can indefinitely renew their sessions through the POST /token/refresh endpoint, retaining access that account disabling was intended to remove. | ||||
| CVE-2026-96326 | 2 Htplugins, Wordpress-extensions | 2 Ht Contact Form – Drag & Drop Form Builder For Wordpress, Ht Contact Form | 2026-09-29 | 7.2 High |
| The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-97024 | 2 Flatpak, Redhat | 2 Flatpak, Enterprise Linux | 2026-09-29 | 7.1 High |
| A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be emptied or replaced with a symlink when the app is installed or upgraded. In system-wide installations, the write is performed as root. | ||||