Export limit exceeded: 399158 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399158 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-13018 | 1 Google | 1 Chrome | 2026-09-29 | 4.3 Medium |
| Insufficient validation of untrusted input in Codecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially perform out of bounds memory access via a crafted video file. (Chromium security severity: Low) | ||||
| CVE-2026-16750 | 2 Stylemixthemes, Wordpress-extensions | 2 Motors - Car Dealer, Classifieds & Listing, Motors – Car Dealership & Classified Listings | 2026-09-29 | 5.3 Medium |
| The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_load_cars() function in all versions up to, and including, 1.4.120. This makes it possible for unauthenticated attackers to retrieve draft, pending, private, and future car listings belonging to arbitrary users. | ||||
| CVE-2026-16582 | 2 Ameliabooking, Wordpress-extensions | 2 Booking For Appointments And Events Calendar, Booking For Appointments And Events Calendar – Amelia | 2026-09-29 | 5.3 Medium |
| The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.4.5. This is due to the plugin accepting a client-supplied package-redemption identifier as proof of payment without validating it. This makes it possible for unauthenticated attackers to create approved appointment bookings without completing payment | ||||
| CVE-2026-14311 | 2 Ameliabooking, Wordpress-extensions | 2 Booking For Appointments And Events Calendar, Booking For Appointments And Events Calendar – Amelia | 2026-09-29 | 5.4 Medium |
| The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with wpamelia-provider role, to view and modify arbitrary customers, including password reset. Takeover of WordPress user accounts, with the roles up to Editor, is also possible if that user had made an Amelia booking. This vulnerability affects only the Premium version of the plugin, where the Employee Panel is present. | ||||
| CVE-2016-15059 | 1 Perl | 1 Net::idn::punycode | 2026-09-29 | 9.8 Critical |
| Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns, sized from the input length. The loop that emits the digits of each code point checks for room before every write, but the write of the last digit of each round and the write of the terminating NUL do not, so an input whose encoded form fills the buffer writes past its end. Only the XS backend is affected. Encoding an attacker-supplied string corrupts the heap. | ||||
| CVE-2026-101108 | 1 Ordasoft.com | 1 Vehicle Manager (free) Extension For Joomla | 2026-09-29 | N/A |
| Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three separate anonymous-reachable frontend entry points (category listing, search, and the all-vehicles listing) through a sanitizing function that applies real escaping, but the value is then placed into an unquoted ORDER BY clause, where escaping has no protective effect. | ||||
| CVE-2026-100752 | 1 Ordasoft.com | 1 Real Estate Manager (free) Extension For Joomla | 2026-09-29 | N/A |
| Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field parameter, concatenated directly into an unquoted SQL clause with no allow-list of real column names and no cast. | ||||
| CVE-2026-100753 | 1 Ordasoft.com | 1 Real Estate Manager (free) Extension For Joomla | 2026-09-29 | N/A |
| Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title field directly from the request with no escaping and no filtering function of any kind, unlike the adjacent comment field on the same form, which at least receives partial tag-stripping. A " character in the title query parameter breaks out of the HTML attribute the value is placed in, allowing a following <script> element to execute in the browser of anyone who loads the crafted link. | ||||
| CVE-2026-101110 | 1 Ordasoft.com | 1 Book Library (free) Extension For Joomla | 2026-09-29 | N/A |
| Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes each through a function called protectInjectionWithoutQuote(), whose only real protection is a keyword blacklist that, on detecting the literal substring select, wraps the value in $db->quote() instead of rejecting it. The value is then concatenated directly into an unquoted ORDER BY clause, a position where quoting provides no protection at all. Reaching the vulnerable code path requires two conditions: a first request to prime session-stored sort defaults, and a trailing decoy comment (-- xselect) that satisfies the blacklist’s substring check without altering the payload’s effect. | ||||
| CVE-2026-101109 | 1 Ordasoft.com | 1 Vehicle Manager (free) Extension For Joomla | 2026-09-29 | N/A |
| Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-detail page (task=view) echoes the title request parameter directly into a double-quoted HTML attribute with no output encoding of any kind. A double-quote character in the parameter closes the attribute, allowing arbitrary markup, including a <script> tag, to be injected into the page. | ||||
| CVE-2026-101111 | 1 Ordasoft.com | 1 Book Library (free) Extension For Joomla | 2026-09-29 | N/A |
| Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail page template, site/views/view_book/tmpl/default.php, echoes the raw title request parameter directly into a double-quoted HTML attribute with no escaping function of any kind (echo $_REQUEST["title"];). A value containing a double quote closes the attribute early and allows arbitrary HTML/JavaScript to follow. | ||||
| CVE-2026-102010 | 2 Gnu, Redhat | 6 Gcc, Enterprise Linux, Hardened Images and 3 more | 2026-09-29 | 7 High |
| A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption. | ||||
| CVE-2026-102004 | 1 Windriver | 1 Vxworks | 2026-09-29 | 7.8 High |
| Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption within the memory management subsystem. Fixed in Version 26.09 | ||||
| CVE-2026-102006 | 1 Windriver | 1 Vxworks | 2026-09-29 | 5.5 Medium |
| In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process management subsystem failing to properly release allocated kernel memory before terminating the calling application. Fixed in Version 26.09 | ||||
| CVE-2024-42002 | 1 Open Source Robotics Foundation | 1 Robot Operating System 2 (ros 2) | 2026-09-29 | 8.4 High |
| A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the --filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code. | ||||
| CVE-2026-102333 | 1 Cle-b | 1 Httpdbg | 2026-09-29 | 6.1 Medium |
| httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascript: scheme URLs that execute malicious scripts in the application origin when clicked, allowing access to captured request and response data including headers and tokens. | ||||
| CVE-2026-102361 | 1 Gz-yami | 1 Mall4j | 2026-09-29 | 9.1 Critical |
| mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data. | ||||
| CVE-2026-102362 | 1 Gz-yami | 1 Mall4j | 2026-09-29 | 5.3 Medium |
| mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in ProdCommController. Unauthenticated attackers can delete arbitrary product reviews by supplying the prodCommId parameter without authorization checks. | ||||
| CVE-2026-102363 | 1 Gz-yami | 1 Mall4j | 2026-09-29 | 3.7 Low |
| mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an order number parameter. Attackers can access carrier names, waybill numbers, and complete logistics trails for any order without authentication or ownership verification. | ||||
| CVE-2026-102364 | 1 Gz-yami | 1 Mall4j | 2026-09-29 | 5.4 Medium |
| mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office users by reusing their session tokens. Attackers can register on the public storefront and use their customer session token to access admin endpoints lacking @PreAuthorize permission checks, including menu listings, file uploads, and configuration endpoints. | ||||