Export limit exceeded: 403739 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 403739 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 403739 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (403739 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-93548 2026-10-09 8.8 High
The FooSales WordPress plugin before 1.43.3 does not verify that an authenticated caller is entitled to act as the user a request names, allowing any authenticated user to have the FooSales WordPress plugin before 1.43.3 act as an arbitrary other user, including an administrator, resulting in that user's account details being exposed and their account being taken over.
CVE-2026-92990 2026-10-09 5.3 Medium
The SendPress Newsletters WordPress plugin through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the same on every site rather than a per-site secret, allowing unauthenticated users to read newsletter sending logs, including recipient email addresses.
CVE-2026-92989 2026-10-09 4.3 Medium
The SendPress Newsletters WordPress plugin through 1.26.1.20 does not check the user's capability on several newsletter-management actions, allowing any authenticated subscriber-level user to synchronise all site users into a mailing list and to drive the newsletter send queue.
CVE-2026-89235 2026-10-09 6.8 Medium
The Testimonials by BestWebSoft WordPress plugin through 1.0.8 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL to the query.
CVE-2026-88931 2026-10-09 5.3 Medium
The Social Web Suite WordPress plugin through 4.1.12 does not restrict which of its settings may be written through an unauthenticated endpoint, allowing attackers to overwrite arbitrary Social Web Suite WordPress plugin through 4.1.12 options, including the shared secret that guards its own privileged endpoints.
CVE-2026-88131 1 Microsoft 1 Dataverse 2026-10-09 9.8 Critical
Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network.
CVE-2026-87846 2026-10-09 5.3 Medium
The Shipping for Nova Poshta WordPress plugin through 1.19.8 does not perform any authorisation, nonce or ownership checks on one of its AJAX actions available to unauthenticated users, allowing anyone to delete the shipment records of arbitrary orders and to make the store issue the carrier's waybill-deletion request for those orders using the store's own stored API credentials.
CVE-2026-87841 2026-10-09 5.3 Medium
The UnitechPay WordPress plugin through 1.0.6.3 does not verify the authenticity of the payment notifications it receives, allowing unauthenticated attackers to mark orders placed through it as paid without any payment being made, as well as to force other orders into a failed state.
CVE-2026-86851 2026-10-09 6.5 Medium
The Livees Checkout WordPress plugin through 7.0.2 does not perform any capability, nonce or order-key check before acting on request parameters on the order confirmation page, allowing unauthenticated users to change the status of arbitrary orders, store arbitrary data and notes on them, and recover their order keys.
CVE-2026-86850 2026-10-09 6.5 Medium
The SKU Error Fixer for WooCommerce WordPress plugin through 1.0 does not perform any capability or nonce checks on two of its AJAX actions, which are also available to unauthenticated users, allowing them to permanently delete product variations it classifies as obsolete, and to disclose those variations' details, with no recoverable copy left behind.
CVE-2026-85348 2026-10-09 4.3 Medium
The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF protection when updating one of its settings, allowing attackers to change that setting via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2026-84224 2026-10-09 4.1 Medium
The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetching it, allowing users with editor-level access and above to make the site issue requests to internal services that are not otherwise reachable, and to tell which of those are live from the response.
CVE-2026-84220 2026-10-09 4.8 Medium
The Kirki WordPress plugin before 6.3.2 does not prevent shortcodes held in comments from being executed when it renders them, and displays comments regardless of their moderation status, allowing unauthenticated visitors to run shortcodes registered on the site and to read private custom fields of the page being viewed.
CVE-2026-84032 1 Ibm 1 Guardium Data Protection 2026-10-09 5.6 Medium
IBM Guardium Data Protection 12.2.2 could allow a remote attacker to conduct a man-in-the-middle attack due to improper certificate validation.
CVE-2026-83947 1 Microsoft 1 Azure Event Grid System 2026-10-09 7.7 High
Missing authorization in Azure Event Grid allows an authorized attacker to perform spoofing over a network.
CVE-2026-83943 1 Microsoft 1 Azure Api Center 2026-10-09 8.7 High
Exposure of sensitive information to an unauthorized actor in Azure API Center allows an unauthorized attacker to disclose information over a network.
CVE-2026-78027 2026-10-09 5.8 Medium
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Server-side request forgery.
CVE-2026-78022 2026-10-09 6.8 Medium
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Not Failing Securely ('Failing Open') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
CVE-2026-78017 2026-10-09 3.8 Low
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Check for Unusual or Exceptional Conditions vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Protection mechanism bypass.
CVE-2026-77900 1 Microsoft 1 Azure App Service 2026-10-09 9.8 Critical
Missing authentication for critical function in Azure App Service allows an unauthorized attacker to execute code over a network.