Export limit exceeded: 403808 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 103010 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (103010 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-106498 1 Backstage 2 Backstage, Plugin-catalog-backend 2026-10-09 7.7 High
Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/plugin-catalog-backend package is affected by improper url validation in catalog entity placeholder resolution. An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under certain configurations, this could allow access to data not intended to be available to the user. This issue is fixed in versions 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1.
CVE-2025-70517 1 Fanvil 1 X7a 2026-10-09 8.8 High
The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.
CVE-2025-70522 1 Fanvil 1 X7a 2026-10-09 8.8 High
The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.
CVE-2026-59347 1 Vmware 2 Vmware Fusion, Vmware Workstation 2026-10-09 8.1 High
VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)
CVE-2026-104677 1 Wordpress-extensions 1 Wp Coder 2026-10-09 7.2 High
The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site.
CVE-2026-105316 1 Wordpress-extensions 1 Magee Shortcodes 2026-10-09 7.1 High
The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting.
CVE-2026-87782 1 Wordpress-extensions 1 Koinonia Link 2026-10-09 8.8 High
The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.
CVE-2026-87971 1 Wordpress-extensions 1 If-so Dynamic Content 2026-10-09 7.1 High
The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link.
CVE-2026-97188 1 Wordpress-extensions 1 String Locator 2026-10-09 8.8 High
The String locator WordPress plugin before 2.6.8 does not restrict the classes allowed when deserializing the content of a database row saved through its database editor, allowing unauthenticated attackers to store a serialized PHP object that is instantiated when an administrator later opens and saves that row. If a suitable POP chain is present via another installed String locator WordPress plugin before 2.6.8 or , this can lead to arbitrary file deletion, sensitive data disclosure or remote code execution.
CVE-2026-82211 1 Wordpress-extensions 1 Nexi Xpay Build 2026-10-09 8.2 High
The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing attackers to mark arbitrary orders as paid or failed, to cancel them, and to obtain order keys which expose guest buyers' details.
CVE-2026-82212 1 Wordpress-extensions 1 Nexi Xpay Build 2026-10-09 7.5 High
The Nexi XPay Build WordPress plugin through 7.6.2 does not correctly validate the security token on its payment notification route, accepting the request when the target order has no stored token, which allows unauthenticated attackers to mark arbitrary orders as paid, or to mark genuinely paid orders as failed.
CVE-2026-89417 2 Daanvandenbergh, Wordpress-extensions 2 Omgf, Omgf 2026-10-09 7.2 High
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 's' Search Parameter via comments-atom Feed in all versions up to, and including, 6.3.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that the front-end server serves the retained .tmp file without a Content-Type or X-Content-Type-Options header, enabling MIME-sniffing browsers such as Chromium to execute the injected script — a condition present by default on many Apache and nginx/php-fpm deployments.
CVE-2026-42721 2 Servit Software Solutions, Wordpress-extensions 2 Affiliate-toolkit, Affiliate-toolkit 2026-10-09 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SERVIT Software Solutions affiliate-toolkit affiliate-toolkit-starter allows Blind SQL Injection.This issue affects affiliate-toolkit: from n/a through 3.9.1.
CVE-2026-42720 2 Sarah Giles, Wordpress-extensions 2 Dynamic User Directory, Dynamic User Directory 2026-10-09 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sarah Giles Dynamic User Directory dynamic-user-directory allows Blind SQL Injection.This issue affects Dynamic User Directory: from n/a through 2.4.
CVE-2026-42714 2 Piggly Dev, Wordpress-extensions 2 Pix Por Piggly (para Woocommerce), Pix Por Piggly (para Woocommerce) 2026-10-09 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Piggly Dev Pix por Piggly (para Woocommerce) pix-por-piggly allows Blind SQL Injection.This issue affects Pix por Piggly (para Woocommerce): from n/a through 2.1.2.
CVE-2026-42713 2 Gopiplus, Wordpress-extensions 2 Post Title Marquee Scroll, Post Title Marquee Scroll 2026-10-09 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gopiplus Post title marquee scroll post-title-marquee-scroll allows Blind SQL Injection.This issue affects Post title marquee scroll: from n/a through 9.9.
CVE-2026-42710 2 10web, Wordpress-extensions 2 Sliderby10web, Slider By 10web 2026-10-09 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Slider by 10Web slider-wd allows Blind SQL Injection.This issue affects Slider by 10Web: from n/a through 1.2.63.
CVE-2026-42708 2 Afthemes, Wordpress-extensions 2 Wp Post Author, Wp Post Author 2026-10-09 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author wp-post-author allows Blind SQL Injection.This issue affects WP Post Author: from n/a through 4.0.0.
CVE-2026-103435 1 Anthropic 1 Claude Code 2026-10-09 7.0 High
Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at write time without repeating that validation. This time-of-check to time-of-use (TOCTOU) gap allowed an attacker who could write to the workspace to atomically replace a project file with a symlink, causing Claude Code to follow the symlink and write its output to an arbitrary file outside the project sandbox. Exploitation required the ability to win a race condition against the write operation and write access to the shared workspace, enabling a lower-privileged attacker to redirect benign edits to sensitive files (e.g., shell configuration) in a higher-privileged session. Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version. Thank you to hackerone.com/c_h4ck_0 for reporting this issue.
CVE-2026-106510 1 Backstage 2 Backstage, Plugin-techdocs-node 2026-10-09 7.7 High
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by remote code execution via crafted markdown_extensions in techdocs mkdocs.yml. An authenticated user who can register catalog entities can provide a crafted mkdocs.yml causing arbitrary OS command execution on the TechDocs build host when the docs are built. This issue is fixed in versions 1.14.6 and 1.15.4.