Export limit exceeded: 391119 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (391119 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-78085 | 1 Joomshaper.com | 1 Sp Property Extension For Joomla | 2026-09-13 | N/A |
| Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks. | ||||
| CVE-2026-84828 | 1 Redhat | 5 Enterprise Linux, Openshift, Openshift Container Platform and 2 more | 2026-09-13 | 6.5 Medium |
| A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the files are shorter than 256 bytes. The file contents are read with root privileges by the pcsd daemon and can be exfiltrated by the attacker through subsequent cluster node communication. This allows disclosure of sensitive data such as API keys, tokens, or configuration secrets that would otherwise be inaccessible to the attacker. | ||||
| CVE-2026-9161 | 1 Dernekplus | 1 Website Template | 2026-09-13 | 5.3 Medium |
| Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting. This issue affects Website Template: through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-88038 | 1 Pillarjs | 1 Cookies | 2026-09-13 | 4.8 Medium |
| cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator, but the domain and path options are checked only against a permissive RFC 7230 field-content matcher that allows semicolons, and both are written into the Set-Cookie header unescaped. An application that passes untrusted or request-derived data into the domain or path option can therefore inject additional cookie attributes, overriding SameSite, Secure, HttpOnly, or Domain on the cookies the application issues. This is a Set-Cookie attribute injection issue (CWE-74). The issue is fixed in cookies 0.9.2, which validates domain and path against RFC 6265 character sets. As a workaround, keep domain and path application-set rather than derived from untrusted input. | ||||
| CVE-2026-85544 | 1 Hikvision | 13 Ds-kd8003, Ds-kd8005, Ds-kv6103 and 10 more | 2026-09-13 | 5.2 Medium |
| There is an Improper Encryption Configuration Vulnerability in some Hikvision Intercom Products. This could allow attackers to forge M1 cards. | ||||
| CVE-2026-85545 | 1 Hikvision | 1 Hikcentral Access Control | 2026-09-13 | 7.1 High |
| There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that their role is not authorized to access. | ||||
| CVE-2026-85543 | 1 Hikvision | 1 Wi-fi Series Camera | 2026-09-13 | 4.3 Medium |
| Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces. | ||||
| CVE-2026-12683 | 1 Ankaref Innovation And Technology Inc. | 1 Librid/libref | 2026-09-13 | 5.4 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-6285 | 1 Ankaref Innovation And Technology Inc. | 1 Librid/libref | 2026-09-13 | 7.5 High |
| Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-12682 | 1 Ankaref Innovation And Technology Inc. | 1 Librid/libref | 2026-09-13 | 5.4 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-81783 | 2 Mailmunch, Wordpress | 2 Mailmunch – Grow Your Email List, Wordpress | 2026-09-13 | 7.1 High |
| Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions. | ||||
| CVE-2026-81791 | 2 Ashan Perera, Wordpress | 2 Eventon, Wordpress | 2026-09-13 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions. | ||||
| CVE-2026-81794 | 2 Mlfactory, Wordpress | 2 Shirt Product Designer For Woocommerce, Wordpress | 2026-09-13 | 7.5 High |
| Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions. | ||||
| CVE-2026-81795 | 2 Denis Botić, Wordpress | 2 Page Visits Counter – Lite, Wordpress | 2026-09-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter – Lite <= 1.2.3 versions. | ||||
| CVE-2026-81800 | 2 Par Avisverifies, Wordpress | 2 Verified Reviews (avis Vérifiés), Wordpress | 2026-09-13 | 9.3 Critical |
| Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions. | ||||
| CVE-2026-81801 | 2 Udx Usability Dynamics, Wordpress | 2 Wp-stateless, Wordpress | 2026-09-13 | 8.1 High |
| Subscriber Settings Change in WP-Stateless <= 4.4.1 versions. | ||||
| CVE-2026-81804 | 2 Wordpress, Zain Hassan | 2 Wordpress, Zhbackup – Backup, Restore & Migration | 2026-09-13 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions. | ||||
| CVE-2026-81805 | 2 Siteskite, Wordpress | 2 Siteskite, Wordpress | 2026-09-13 | 8.1 High |
| Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions. | ||||
| CVE-2026-88924 | 2 Gnome, Redhat | 2 Gvfs, Enterprise Linux | 2026-09-13 | 7 High |
| A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root. | ||||
| CVE-2026-15417 | 1 Silicon Labs | 1 Silabser.sys Driver | 2026-09-13 | N/A |
| In the silabser.sys Windows 8 driver for CP210x devices, a local unprivileged user can use incorrect driver settings to cause a kernel crash. | ||||