Export limit exceeded: 404370 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 404370 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404370 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-108269 | 1 Privasys | 1 Ra-tls-clients | 2026-10-11 | N/A |
| Remote Attestation TLS Clients provides multi-language utilities for verifying attested TLS connections. Prior to 0.5.0, the Rust and Go RA-TLS challenge verifiers accepted quote ReportData that was bound to the certificate public key and client nonce but not to the active TLS session before permitting application traffic. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing the clients to accept an attacker-terminated connection as the attested enclave. This issue is fixed in 0.5.0. | ||||
| CVE-2026-108474 | 1 Jetbrains | 1 Exposed | 2026-10-11 | 9.8 Critical |
| In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of several SQL functions | ||||
| CVE-2026-108501 | 1 Zte | 1 Zte Z80 Ultra | 2026-10-11 | 5.7 Medium |
| ZTE Z80 Ultra has a system interface permission verification defect. The interface lacks necessary access control, and relevant information can be read by reflectively invoking the interface. | ||||
| CVE-2026-108502 | 1 Zte | 1 Z80 Ultra | 2026-10-11 | 3.3 Low |
| ZTE Z80 Ultra contains an information disclosure vulnerability, through which third-party applications can read relevant information by hooking system APIs. | ||||
| CVE-2026-108503 | 1 Zte | 1 Z80 Ultra | 2026-10-11 | 3.3 Low |
| ZTE Z80 Ultra has an interface permission validation vulnerability. The callable functions provided by the system lack sufficient access control. An attacker can leverage these functions to read relevant information. | ||||
| CVE-2026-93931 | 2 Themerex Group, Wordpress-extensions | 2 Smash, Smash | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Smash smash allows Object Injection.This issue affects Smash: from n/a through 1.12.0. | ||||
| CVE-2026-93932 | 2 Themerex Group, Wordpress-extensions | 2 Smart Casa, Smart Casa | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Smart Casa smart-casa allows Object Injection.This issue affects Smart Casa: from n/a through 1.0.12. | ||||
| CVE-2026-93933 | 2 Themerex Group, Wordpress-extensions | 2 Rosalinda, Rosalinda | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Rosalinda rosalinda allows Object Injection.This issue affects Rosalinda: from n/a through 1.2.4. | ||||
| CVE-2026-93934 | 2 Themerex Group, Wordpress-extensions | 2 Partiso, Partiso | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Partiso partiso allows Object Injection.This issue affects Partiso: from n/a through 1.1.13. | ||||
| CVE-2026-93935 | 2 Themerex Group, Wordpress-extensions | 2 Let's Play, Let's Play | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play playhockey allows Object Injection.This issue affects Let's Play: from n/a through 1.1.15. | ||||
| CVE-2026-93936 | 2 Themerex Group, Wordpress-extensions | 2 Ipharm, Ipharm | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4. | ||||
| CVE-2026-93937 | 2 Themerex Group, Wordpress-extensions | 2 Hygia, Hygia | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0. | ||||
| CVE-2026-93938 | 2 Themerex Group, Wordpress-extensions | 2 Hogwords, Hogwords | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7. | ||||
| CVE-2026-93940 | 2 Themerex Group, Wordpress-extensions | 2 Greeny, Greeny | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0. | ||||
| CVE-2026-93941 | 2 Themerex Group, Wordpress-extensions | 2 Edema, Edema | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2. | ||||
| CVE-2026-93942 | 2 Themerex Group, Wordpress-extensions | 2 Dwell, Dwell | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a through 1.16.0. | ||||
| CVE-2026-93943 | 2 Themerex Group, Wordpress-extensions | 2 Convex, Convex | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0. | ||||
| CVE-2026-93944 | 2 Themerex Group, Wordpress-extensions | 2 Camelia, Camelia | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15. | ||||
| CVE-2026-93945 | 2 Axiomthemes, Wordpress-extensions | 2 Balance, Balance | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0. | ||||
| CVE-2026-62046 | 2 Themerex Group, Wordpress-extensions | 2 Gutentype, Gutentype | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12. | ||||