Export limit exceeded: 400496 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400496 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400496 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-94390 | 2026-10-01 | 7.2 High | ||
| Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions. | ||||
| CVE-2026-62073 | 2026-10-01 | 7.5 High | ||
| Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions. | ||||
| CVE-2026-62071 | 2026-10-01 | 9.3 Critical | ||
| Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions. | ||||
| CVE-2026-103752 | 2026-10-01 | 9.8 Critical | ||
| Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions. | ||||
| CVE-2026-103687 | 1 Rhukster | 1 Dom-sanitizer | 2026-10-01 | 7.3 High |
| A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.16 is sufficient to fix this issue. The name of the patch is 139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a. Upgrading the affected component is recommended. | ||||
| CVE-2026-47512 | 1 Nvidia | 5 Geforce, Nvs, Quadro and 2 more | 2026-10-01 | 7.8 High |
| NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read leading to kernel information disclosure. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-102587 | 1 Moodle | 1 Moodle | 2026-10-01 | 2.7 Low |
| A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized information disclosure by inferring hidden user data. | ||||
| CVE-2026-103491 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues | ||||
| CVE-2026-103497 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 5.5 Medium |
| In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration | ||||
| CVE-2026-103496 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 5.4 Medium |
| In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications | ||||
| CVE-2026-103495 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs | ||||
| CVE-2026-103494 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 6.6 Medium |
| In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes | ||||
| CVE-2026-103493 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 8.1 High |
| In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible | ||||
| CVE-2024-58388 | 2026-10-01 | 7.5 High | ||
| Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, including /etc/passwd, coredump files containing credentials, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30. | ||||
| CVE-2026-95366 | 1 Google | 1 Chrome | 2026-10-01 | 6.5 Medium |
| Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-102579 | 1 Moodle | 1 Moodle | 2026-10-01 | 4.3 Medium |
| A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other students enrolled in the same course that they should not have permission to view. This issue leads to unauthorized information disclosure. | ||||
| CVE-2026-103492 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments | ||||
| CVE-2026-96760 | 1 Authlib | 1 Authlib | 2026-10-01 | 9.8 Critical |
| Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key. | ||||
| CVE-2026-88789 | 2026-10-01 | 8.6 High | ||
| Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus from 3.2.0 before 3.33.3 and from 3.34.0 before 3.40.0 on all platforms allows an attacker who supplies the XML document being transformed to read local files or issue requests to internal network locations via an external entity declaration in that document. The extension supplies its own Xalan-backed TransformerFactory to the xslt component and registers it as the JAXP default. Xalan-J 2.7.x predates JAXP 1.5 and does not honour javax.xml.XMLConstants.ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_STYLESHEET, so the external access restrictions Apache Camel applies to the TransformerFactory it creates were not in effect. On the xslt component path this affects message bodies that reach the transformer already as a javax.xml.transform.Source; bodies of other types are converted to a SAXSource by Apache Camel with external entities and external DTD loading disabled, and are not affected. Because the factory is also the JAXP default, other code in the application obtaining one through TransformerFactory.newInstance() loses the same restrictions without error. Applications are affected if they use any of camel-quarkus-xslt, camel-quarkus-xslt-saxon, camel-quarkus-tika or camel-quarkus-xmlsecurity, each of which brings the XSLT support extension onto the classpath. For all but camel-quarkus-xslt, the exposure is limited to the JAXP default factory, since those extensions do not perform XSLT transformations themselves. Users are recommended to upgrade to version 3.33.3 or 3.40.0, which fixes this issue. | ||||
| CVE-2026-82806 | 1 Apache | 1 Apache Apisix | 2026-10-01 | N/A |
| Exposure of data element to wrong session vulnerability in Apache APISIX. This issue affects Apache APISIX: from 2.3.0 before 3.7.0. Under a supported authz-keycloak configuration, a request's authorization scope could persist into later requests on the same route, leading to unintended authorization expansion and inconsistent access-control decisions. Users are recommended to upgrade to version 3.7.0 or higher, which fixes the issue. | ||||