Export limit exceeded: 402067 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402067 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402067 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402067 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402067 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-102387 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in Xserver Migrator <= 1.6.6 versions. | ||||
| CVE-2026-100518 | 2026-10-06 | 5.3 Medium | ||
| Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions. | ||||
| CVE-2026-100515 | 2026-10-06 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Photo Reviews for WooCommerce woo-photo-reviews allows Reflected XSS.This issue affects Photo Reviews for WooCommerce: from n/a through 1.2.30. | ||||
| CVE-2026-100511 | 2026-10-06 | 8.8 High | ||
| Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1. | ||||
| CVE-2026-100506 | 2026-10-06 | 7.2 High | ||
| Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Check: from n/a through 12.1. | ||||
| CVE-2025-15643 | 2026-10-06 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Fernandez Adsmonetizer adsensei-b30 allows Reflected XSS.This issue affects Adsmonetizer: from n/a through 3.2.4. | ||||
| CVE-2026-59668 | 1 Repasat | 1 Repasat Application | 2026-10-06 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTamano” parameter is affected – endpoint “/es/companysizebills/store”. | ||||
| CVE-2026-59667 | 1 Repasat | 1 Repasat Application | 2026-10-06 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTamano” parameter is affected – endpoint “/es/companysizemployees/update”. | ||||
| CVE-2026-59666 | 1 Repasat | 1 Repasat Application | 2026-10-06 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomOrigen” parameter is affected – endpoint “/es/origins/store”. | ||||
| CVE-2026-59665 | 1 Repasat | 1 Repasat Application | 2026-10-06 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomMotivo” parameter is affected – endpoint “/es/lostmotives/store”. | ||||
| CVE-2026-59664 | 1 Repasat | 1 Repasat Application | 2026-10-06 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomServicioPrestado” parameter is affected – endpoint “/es/providedservices/store”. | ||||
| CVE-2026-59663 | 1 Repasat | 1 Repasat Application | 2026-10-06 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomDelegacion” parameter is affected – endpoint “/es/delegations/store”. | ||||
| CVE-2026-59662 | 1 Repasat | 1 Repasat Application | 2026-10-06 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomCompetidor” parameter is affected – endpoint “/es/competitors/store”. | ||||
| CVE-2026-59661 | 1 Repasat | 1 Repasat Application | 2026-10-06 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomRuta” parameter is affected – endpoint “/es/routes/update/693”. | ||||
| CVE-2026-96577 | 2 Oc-mirror, Redhat | 3 Oc-mirror, Assisted Installer, Openshift | 2026-10-06 | 7.1 High |
| A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an adjacent network can connect to the exposed service to push tampered container images, delete cached images, or access mirrored content. | ||||
| CVE-2026-83589 | 2 Oauth2 Proxy Project, Redhat | 2 Oauth2 Proxy, Openshift | 2026-10-06 | 6.1 Medium |
| A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft. | ||||
| CVE-2026-49329 | 1 Redhat | 2 Openshift, Openshift Container Platform | 2026-10-06 | 7.5 High |
| A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass of the CVE-2022-32149 mitigation exists: the upstream guard counts only '-' characters but the internal BCP 47 scanner aliases '_' to '-' after the guard check. An unauthenticated attacker can send a crafted Accept-Language header using '_' separators to trigger quadratic-time parsing, consuming excessive CPU and denying authentication to all cluster users. | ||||
| CVE-2026-59660 | 1 Repasat | 1 Repasat Application | 2026-10-06 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTransportista” parameter is affected – endpoint “/es/carriers/update”. | ||||
| CVE-2026-59659 | 1 Repasat | 1 Repasat Application | 2026-10-06 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomZonaGeo” parameter is affected – endpoint “/es/geozones/update/149979”. | ||||
| CVE-2026-59673 | 1 Repasat | 1 Repasat Application | 2026-10-06 | N/A |
| Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTipoCli” parameter is affected – endpoint “/es/clientypes/update/109441”. | ||||