Export limit exceeded: 396013 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 396013 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (396013 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-90990 | 1 Checkmk | 1 Checkmk | 2026-09-22 | N/A |
| Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional Livestatus query headers, bypassing object visibility restrictions in count queries to infer information about hosts and services outside their contact groups and occupying web server and Livestatus workers for an attacker-controlled duration. | ||||
| CVE-2026-92882 | 1 Checkmk | 1 Checkmk | 2026-09-22 | N/A |
| Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read stored SNMP community strings, SNMPv3 auth and privacy pass phrases and IPMI passwords in clear text from GET responses, although the setup GUI never displays these values. | ||||
| CVE-2026-94117 | 2 Devitems, Wordpress | 2 Hashbar – Wordpress Notification Bar, Wordpress | 2026-09-22 | 7.6 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.3. | ||||
| CVE-2026-7891 | 1 Divd | 1 Verysecureapp | 2026-09-22 | 9.1 Critical |
| This CVE has been retracted. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute. | ||||
| CVE-2026-16778 | 2 Livecomposer, Wordpress | 2 Live Composer – Free Wordpress Website Builder, Wordpress | 2026-09-22 | 6.4 Medium |
| The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_module_downloads_output' Shortcode Content in all versions up to, and including, 2.1.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The save-time wp_kses_post check is bypassed because the payload is stored as a serialized string containing no HTML tags for kses to tokenize, and the shortcode callback re-emits attacker-controlled values — including view_all_link (href attribute), main_heading_title (h2 body), button_text (anchor body), and button_inline_svg (anchor body) — without any escaping at render time. | ||||
| CVE-2025-1281 | 2 Seatheme, Wordpress | 2 Bm Content Builder, Wordpress | 2026-09-22 | 8.8 High |
| The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ux_cb_remove_layout_ajax() and ux_cb_tools_export_ajax() functions in all versions up to, and excluding, 3.17.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). | ||||
| CVE-2025-1280 | 2 Seatheme, Wordpress | 2 Bm Content Builder, Wordpress | 2026-09-22 | 6.5 Medium |
| The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1 (exclusive) via the ux_cb_page_customize_save_layout_ajax() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. | ||||
| CVE-2026-93928 | 2 Magepeople, Wordpress | 2 Taxi Booking Manager For Woocommerce, Wordpress | 2026-09-22 | 7.3 High |
| Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. This issue affects Taxi Booking Manager for WooCommerce: from n/a before 2.0.8. | ||||
| CVE-2026-86482 | 1 Jetbrains | 1 Youtrack | 2026-09-22 | 8.8 High |
| In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation | ||||
| CVE-2026-25265 | 2026-09-22 | 8.8 High | ||
| Privilege escalation due to weak configuration while temporary file handling. | ||||
| CVE-2026-25264 | 2026-09-22 | 8.8 High | ||
| Privilege escalation due to weak configuration during package extraction process. | ||||
| CVE-2026-25262 | 2026-09-22 | 6.9 Medium | ||
| Memory corruption while processing a crafted ELF file in the Primary Bootloader. | ||||
| CVE-2026-25255 | 2026-09-22 | 8.8 High | ||
| Exposed dangerous function lead to privilege escalation via gRPC server. | ||||
| CVE-2026-93836 | 2 Wordpress, Wpclever | 2 Wordpress, Wpc Product Bundles For Woocommerce | 2026-09-22 | 7.2 High |
| The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' parameter in all versions up to, and including, 8.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The float cast used during quantity validation allows a numeric-prefixed payload such as '1<img src=x onerror=...>' to pass validation while retaining its malicious HTML, which is then stored verbatim in order item metadata under the '_woosb_ids' key. | ||||
| CVE-2026-91092 | 2 Tomdever, Wordpress | 2 Wpforo Forum, Wordpress | 2026-09-22 | 4.3 Medium |
| The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to take over another guest author's forum post and modify its title, body, author name, and stored owner email address. This requires that guest posting and editing are enabled on the forum, and that the attacker knows the target guest author's email address. | ||||
| CVE-2026-92235 | 2 Roxnor, Wordpress | 2 Wp Ultimate Review, Wordpress | 2026-09-22 | 8.1 High |
| The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes. | ||||
| CVE-2026-9231 | 2 Wordpress, Wptravelengine | 2 Wordpress, Wp Travel Engine – Tour Booking Plugin – Tour Operator Software | 2026-09-22 | 7.5 High |
| The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.8.0 via the wte_get_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. | ||||
| CVE-2026-25254 | 2026-09-22 | 9.8 Critical | ||
| Improper authorization leads to Remote Code Execution via SocketIO interface. | ||||
| CVE-2025-48043 | 1 Ash-project | 1 Ash | 2026-09-22 | N/A |
| Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 0.1.1 before 3.6.2. | ||||
| CVE-2025-48044 | 1 Ash-project | 1 Ash | 2026-09-22 | N/A |
| Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 3.6.3 before 3.7.1. | ||||