Export limit exceeded: 403721 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403721 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403721 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-84224 | 2026-10-09 | 4.1 Medium | ||
| The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetching it, allowing users with editor-level access and above to make the site issue requests to internal services that are not otherwise reachable, and to tell which of those are live from the response. | ||||
| CVE-2026-84220 | 2026-10-09 | 4.8 Medium | ||
| The Kirki WordPress plugin before 6.3.2 does not prevent shortcodes held in comments from being executed when it renders them, and displays comments regardless of their moderation status, allowing unauthenticated visitors to run shortcodes registered on the site and to read private custom fields of the page being viewed. | ||||
| CVE-2026-84032 | 1 Ibm | 1 Guardium Data Protection | 2026-10-09 | 5.6 Medium |
| IBM Guardium Data Protection 12.2.2 could allow a remote attacker to conduct a man-in-the-middle attack due to improper certificate validation. | ||||
| CVE-2026-83947 | 1 Microsoft | 1 Azure Event Grid System | 2026-10-09 | 7.7 High |
| Missing authorization in Azure Event Grid allows an authorized attacker to perform spoofing over a network. | ||||
| CVE-2026-83943 | 1 Microsoft | 1 Azure Api Center | 2026-10-09 | 8.7 High |
| Exposure of sensitive information to an unauthorized actor in Azure API Center allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-78027 | 2026-10-09 | 5.8 Medium | ||
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Server-side request forgery. | ||||
| CVE-2026-78022 | 2026-10-09 | 6.8 Medium | ||
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Not Failing Securely ('Failing Open') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. | ||||
| CVE-2026-78017 | 2026-10-09 | 3.8 Low | ||
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Check for Unusual or Exceptional Conditions vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Protection mechanism bypass. | ||||
| CVE-2026-77900 | 1 Microsoft | 1 Azure App Service | 2026-10-09 | 9.8 Critical |
| Missing authentication for critical function in Azure App Service allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-76769 | 2026-10-09 | 4.3 Medium | ||
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | ||||
| CVE-2026-75875 | 1 Ibm | 1 Guardium Data Protection | 2026-10-09 | 9.8 Critical |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to path traversal. | ||||
| CVE-2026-69435 | 1 Microsoft | 1 Azure Sre Agent | 2026-10-09 | 9.6 Critical |
| Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-49243 | 1 Webmin | 1 Webmin | 2026-10-09 | 9.6 Critical |
| Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.650, Webmin users who click on a malicious link to their server are vulnerable to this XSS vulnerability that could be used to execute attacker-controlled commands. This issue has been patched in version 2.650. | ||||
| CVE-2026-108107 | 2026-10-09 | 9.8 Critical | ||
| PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to extract customer records and credentials via time-based blind SQL injection. | ||||
| CVE-2026-108102 | 1 Open5gs | 1 Open5gs | 2026-10-09 | 5.3 Medium |
| Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_volume_measurement() in lib/pfcp/types.c that allows remote unauthenticated attackers to read past IE buffers. Attackers can send a PFCP Session Report Request to the SMF on UDP port 8805 with a short, all-flags Volume Measurement IE, reading up to 48 bytes and potentially crashing the SMF. | ||||
| CVE-2026-107828 | 1 Banq | 1 Jivejdon | 2026-10-09 | 6.5 Medium |
| Jivejdon through 5.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access Weibo-created accounts by deriving predictable credentials from public Weibo user IDs. OAuthAccountServiceImp.transferSina() sets the password to the first four digits of the Weibo ID, letting attackers log in through normal form login to read or post as victims. | ||||
| CVE-2026-107800 | 1 Banq | 1 Jivejdon | 2026-10-09 | 5.4 Medium |
| Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script into private short messages because receiveshortmessage.jsp renders unfiltered message bodies. Attackers can send a short message containing script, which ToolsUtil.convertURL() passes through unchanged, to execute code in the recipient's browser when opened. | ||||
| CVE-2026-107797 | 1 Banq | 1 Jivejdon | 2026-10-09 | 6.1 Medium |
| Jivejdon through 5.0 contains a reflected cross-site scripting vulnerability in application/message/postThread.jsp that allows attackers to inject script via the to and tag parameters. Attackers can send crafted links to authenticated users, breaking out of unencoded inline JavaScript string literals to execute arbitrary JavaScript in the victim's session. | ||||
| CVE-2026-107793 | 1 Banq | 1 Jivejdon | 2026-10-09 | 4.3 Medium |
| Jivejdon through 5.0 contains an authorization bypass vulnerability in SubscriptionServiceImp.deleteSubscription that allows authenticated users to delete other users' subscriptions by ID. Attackers can submit a delete action to /account/protected/sub/subSaveAction with another user's subscriptionId to remove their thread, forum, tag or account subscriptions. | ||||
| CVE-2026-107725 | 1 Hazelcast | 1 Hazelcast | 2026-10-09 | 8.8 High |
| Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, missing authorization checks in the IMap Predicates API allow a malicious client with limited privileges to execute arbitrary code on a Hazelcast cluster member. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0. | ||||