Export limit exceeded: 391058 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 391058 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 391058 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (391058 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-81754 | 2 Fernandot, Wordpress | 2 Vigilant – 100% Free Security Suite: Firewall, 2fa, Login, Headers, Scanner…, Wordpress | 2026-09-13 | 7.2 High |
| The Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The malicious payload is delivered passively by any unauthenticated visitor who triggers a failed login attempt with a crafted User-Agent header, requiring no further interaction from the attacker once stored. | ||||
| CVE-2026-18562 | 2 Realmag777, Wordpress | 2 Husky – Products Filter For Woocommerce Professional, Wordpress | 2026-09-13 | 6.1 Medium |
| The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via SEO-friendly permalink filter URL segments in versions up to, and including, 1.4.3. This is due to insufficient input sanitization and output escaping in the wp_load_js() function, which reads filter values from the URL path via the url_request extension's parse_url_query() and embeds them into an inline JavaScript string using json_encode() without escaping single quotes. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link. | ||||
| CVE-2026-89169 | 1 Debian | 1 Live-boot | 2026-09-13 | N/A |
| live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing. | ||||
| CVE-2026-86781 | 2 Unknown, Wordpress | 2 Ssl Zen — Ssl Certificate Installer & Https Redirects, Wordpress | 2026-09-13 | 5.3 Medium |
| The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowing any authenticated user, including Subscribers, to download the site's TLS private key, certificates, and diagnostic logs. | ||||
| CVE-2026-73784 | 1 Hewlett Packard Enterprise | 1 Hpe Icewall Products | 2026-09-13 | 8.8 High |
| A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user. | ||||
| CVE-2026-73785 | 1 Hewlett Packard Enterprise | 1 Hpe Icewall Products | 2026-09-13 | 7.5 High |
| A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS). | ||||
| CVE-2026-89173 | 1 Kingdom Communication Associated | 4 Eh1000b, Eh2070, Eh3040 and 1 more | 2026-09-13 | 5.3 Medium |
| Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses. | ||||
| CVE-2026-89174 | 1 Kingdom Communication Associated | 4 Eh1000b, Eh2070, Eh3040 and 1 more | 2026-09-13 | 7.5 High |
| Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts. | ||||
| CVE-2026-89175 | 1 Kingdom Communication Associated | 4 Eh1000b, Eh2070, Eh3040 and 1 more | 2026-09-13 | 5.3 Medium |
| Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system configuration values. | ||||
| CVE-2026-89176 | 1 Howyar | 1 Weenygenius | 2026-09-13 | 8.8 High |
| WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a student can disrupt normal classroom operations, whereas impersonating a teacher can induce student computers to initiate connections, thereby gaining remote control over the student endpoints. | ||||
| CVE-2026-89177 | 1 Howyar | 1 Weenygenius | 2026-09-13 | 8.8 High |
| WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with forged commands to disrupt classroom operations. | ||||
| CVE-2026-89178 | 1 Howyar | 1 Weenygenius | 2026-09-13 | 8.8 High |
| WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student computers to attempt to establish a connection with the attacker. | ||||
| CVE-2026-89179 | 1 Howyar | 1 Weenygenius | 2026-09-13 | 4.3 Medium |
| WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability. Unauthenticated attackers on the same network can intercept a student's connection packet and replay it, thereby forging the appearance that the student remains connected. | ||||
| CVE-2025-15679 | 1 Bull | 2 Bullsequana Xh3406, Bullsequana Xh3515 | 2026-09-13 | N/A |
| Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515. | ||||
| CVE-2026-19486 | 1 Google Cloud | 1 Gemini Enterprise Agent Platform App Builder | 2026-09-13 | N/A |
| A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users will need to redeploy their previously deployed apps. | ||||
| CVE-2026-80469 | 1 Sick Ag | 1 Sentio Creator Extension 'device Manager' | 2026-09-13 | 8.3 High |
| An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-controlled code. User interaction is required. | ||||
| CVE-2026-77159 | 1 Redhat | 2 Enterprise Linux, Libvirt | 2026-09-13 | 5.5 Medium |
| A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can replace the logfile with a symlink, causing libvirtd (running as root) to transfer ownership of an arbitrary file to the swtpm user. | ||||
| CVE-2026-89146 | 1 Libp2p | 1 Libp2p-rendezvous | 2026-09-13 | 7.5 High |
| libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL value that causes the client node process to panic when computing the expiry timer. | ||||
| CVE-2026-87776 | 1 Expressjs | 1 Compression | 2026-09-13 | 7.5 High |
| compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never destroyed, so each aborted compressed response leaks its native zlib memory. A remote unauthenticated attacker can repeatedly open requests and disconnect early, exhausting the available memory and crashing the server. All applications using compression are affected. The issue is fixed in compression 1.8.2, and users should upgrade to 1.8.2 or later. | ||||
| CVE-2026-80462 | 1 Progress Software | 1 Chef Automate | 2026-09-13 | 10 Critical |
| A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions. | ||||