Export limit exceeded: 10076 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10076 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100690 | 2 Gohugo, Redhat | 2 Hugo, Hummingbird | 2026-09-30 | 7.5 High |
| Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission model validates only the lexical path and follows symbolic links that point outside the allowed set, Hugo did not detect symlinks escaping the sandbox. An attacker who can contribute content to a Hugo project (for example via a pull request) can commit a symlink such as assets/css/x.css -> /etc/passwd together with a PostCSS plugin that reads it, allowing any file readable by the Hugo build process to be disclosed and potentially embedded in the published site. This affects builds using the default security configuration; projects that do not invoke Node.js tools are unaffected. Fixed in v0.166.0, which scans allowed paths and fails the build when a symbolic link resolves outside them. | ||||
| CVE-2026-97248 | 2026-09-30 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions. | ||||
| CVE-2026-97246 | 2026-09-30 | 4.9 Medium | ||
| Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions. | ||||
| CVE-2026-96833 | 2026-09-30 | 7.2 High | ||
| Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions. | ||||
| CVE-2026-96832 | 2026-09-30 | 7.2 High | ||
| Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions. | ||||
| CVE-2026-96831 | 2026-09-30 | 8.8 High | ||
| Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions. | ||||
| CVE-2026-96344 | 2026-09-30 | 7.2 High | ||
| Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions. | ||||
| CVE-2026-96343 | 2026-09-30 | 7.2 High | ||
| Custom role PHP Object Injection in WP ERP <= 1.17.9 versions. | ||||
| CVE-2026-95531 | 2026-09-30 | 8.8 High | ||
| Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions. | ||||
| CVE-2026-94683 | 2026-09-30 | 8.8 High | ||
| Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions. | ||||
| CVE-2026-94678 | 2026-09-30 | 8.8 High | ||
| Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions. | ||||
| CVE-2026-94677 | 2026-09-30 | 7.2 High | ||
| Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions. | ||||
| CVE-2026-94122 | 2026-09-30 | 7.2 High | ||
| Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions. | ||||
| CVE-2026-94121 | 2026-09-30 | 8.8 High | ||
| Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions. | ||||
| CVE-2026-94076 | 2026-09-30 | 8.8 High | ||
| Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions. | ||||
| CVE-2026-93771 | 2026-09-30 | 7.2 High | ||
| Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. | ||||
| CVE-2026-93651 | 2026-09-30 | 7.2 High | ||
| Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions. | ||||
| CVE-2026-93624 | 2026-09-30 | 7.2 High | ||
| Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions. | ||||
| CVE-2026-91051 | 2026-09-30 | 6.6 Medium | ||
| The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta field that is deserialized when the post is rendered, allowing them to perform PHP Object Injection, which can lead to remote code execution when a suitable gadget chain is present via another installed EWWW Image Optimizer WordPress plugin before 8.8.0 or . | ||||
| CVE-2026-81867 | 1 Google | 1 Application Integration | 2026-09-30 | N/A |
| A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards. This vulnerability was patched on 28 June 2026, and no customer action is needed. | ||||