Export limit exceeded: 390926 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 390926 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (390926 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-89260 | 2 Mogublog Project, Moxi624 | 2 Mogublog, Mogu Blog V2 | 2026-09-13 | 7.5 High |
| MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened dom4j SAXReader without DTD or external-entity restrictions. Unauthenticated remote attackers can submit DOCTYPE declarations with external parameter entities to read arbitrary local files or trigger outbound HTTP requests, with resolved entities reflected in error responses. | ||||
| CVE-2026-89261 | 2 Mogublog Project, Moxi624 | 2 Mogublog, Mogu Blog V2 | 2026-09-13 | 6.5 Medium |
| MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious index entries, causing search functionality to return incorrect or no results. | ||||
| CVE-2026-89262 | 2 Mogublog Project, Moxi624 | 2 Mogublog, Mogu Blog V2 | 2026-09-13 | 7.5 High |
| MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints. | ||||
| CVE-2026-89263 | 2 Mogublog Project, Moxi624 | 2 Mogublog, Mogu Blog V2 | 2026-09-13 | 5.3 Medium |
| MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users. Remote callers can modify the startEmailNotification flag in Redis cache for any user identifier to suppress reply notifications without authorization. | ||||
| CVE-2026-89264 | 2 Mogublog Project, Moxi624 | 2 Mogublog, Mogu Blog V2 | 2026-09-13 | 4.3 Medium |
| MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators. | ||||
| CVE-2026-89265 | 2 Mogublog Project, Moxi624 | 2 Mogublog, Mogu Blog V2 | 2026-09-13 | 4.3 Medium |
| MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office users without image-category permissions can supply a category uid to retrieve restricted image-category records including metadata such as name, cover file uid, sort order and timestamps. | ||||
| CVE-2026-54047 | 1 Lacisynchroni | 1 Server | 2026-09-13 | N/A |
| Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies on client-side state by trusting the `UID` field inside the `Authentications` object of a user's local `config.json` file. By manually editing this local file on their PC prior to logging in, a user can supply an arbitrary UID. Because the server fails to validate that the authenticated OAuth2 identity matches the requested UID, an attacker can fully impersonate any target user and perform actions on their behalf. This issue has been resolved in version 1.2.3. The patch modifies `AuthorizeOauthAsync` inside the `SecretKeyAuthenticatorService` to strictly bind the lookup of the requested User ID (`requestedUid`) to the record of the successfully authenticated identity (`primaryUid`). The server will no longer load or return session tokens for a requested UID unless it matches the verified, authenticated database record. No known workarounds are available. | ||||
| CVE-2026-7298 | 1 Ideasoft Software Industry And Trade Inc. | 1 Smart E-commerce | 2026-09-13 | 6.1 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in IdeaSoft Software Industry and Trade Inc. Smart E-Commerce allows Reflected XSS. This issue affects Smart E-Commerce: through 11092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-27378 | 2 Magepeopleteam, Wordpress | 2 Deposits And Partial Payments For Woocommerce, Wordpress | 2026-09-13 | 5.3 Medium |
| Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions. | ||||
| CVE-2026-62102 | 1 Gato Graphql | 1 Gato Graphql | 2026-09-13 | 8.8 High |
| Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions. | ||||
| CVE-2026-62106 | 2 Cozy Vision Technologies Pvt. Ltd., Wordpress | 2 Sms Alert Order Notifications, Wordpress | 2026-09-13 | 8.8 High |
| Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions. | ||||
| CVE-2026-62113 | 2 Anh Tran, Wordpress | 2 Slim Seo, Wordpress | 2026-09-13 | 4.3 Medium |
| Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4.10.0 versions. | ||||
| CVE-2026-62136 | 2 Wordpress, Wpdesk | 2 Wordpress, Flexible Quantity – Measurement Price Calculator For Woocommerce | 2026-09-13 | 5.3 Medium |
| Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 versions. | ||||
| CVE-2026-62089 | 2 Pixar Labs, Wordpress | 2 Master Addons For Elementor, Wordpress | 2026-09-13 | 7.1 High |
| Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2. | ||||
| CVE-2026-54072 | 1 Authorizerdev | 1 Authorizer | 2026-09-13 | 9.3 Critical |
| Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or `response_type=id_token`, the server appends `access_token`, `id_token`, and `refresh_token` as query parameters and issues a 302 redirect to the attacker-supplied URL. An unauthenticated attacker can obtain the required `client_id` from the public `/graphql?query={meta{client_id}}` endpoint. A partial fix was applied in v2.0.1 to other handlers (`oauth_login`, `verify_email`, `magic_link_login`, `forgot_password`, `invite_members`, `oauth_callback`) but `/authorize` was not included. Version 2.2.1 contains a more complete fix. | ||||
| CVE-2026-89329 | 1 Redhat | 3 Enterprise Linux, Openshift, Openshift Container Platform | 2026-09-13 | 6.2 Medium |
| A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity. | ||||
| CVE-2026-78547 | 1 Citrix | 1 Citrix Workspace App For Windows | 2026-09-13 | N/A |
| Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607. | ||||
| CVE-2026-78546 | 1 Citirx | 1 Workspace App For Windows | 2026-09-13 | N/A |
| Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607. | ||||
| CVE-2026-49463 | 1 Nl-portal | 2 Nl.nl-portal:besluiten, Nl.nl-portal:documenten-api | 2026-09-13 | 6.5 Medium |
| NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version 3.0.0 and the `nl.nl-portal:besluiten` package from version 1.5.0 through 3.0.0 lack per-user authorization in GraphQL resolvers, allowing an authenticated user to access other users’ document contents, decisions, audit trails, and decision attachments. Version 3.0.1 contains a patch. As a workaround, block the affected document-content and decision-related GraphQL operations at the API gateway or block their GraphQL types entirely. | ||||
| CVE-2026-54135 | 1 Simulpiscator | 1 Airsane | 2026-09-13 | 7.5 High |
| AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) via memory exhaustion (OOM). In httpserver.cpp, the HttpServer::Request::content function reads the Content-Length header and directly passes this value to std::string::resize() without any upper-bound validation or safe parsing. An attacker can send an HTTP POST request with an artificially large Content-Length value. This forces the daemon to attempt allocating gigabytes of memory, resulting in a std::bad_alloc exception and immediately crashing the AirSane process. Additionally, providing non-numeric characters in the Content-Length header leads to undefined behavior (NaN to integer conversion) due to the lack of error handling during header parsing. Version 0.4.12 patches the issue. | ||||