Export limit exceeded: 10545 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10545 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-94669 | 2 Wordpress-extensions, Wpmanageninja | 2 Fluent Forms Pro Add On Pack, Fluent Forms Pro Add On Pack | 2026-10-06 | 5.3 Medium |
| Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13. | ||||
| CVE-2026-103684 | 2 Arraytics, Wordpress-extensions | 2 Wp Event Solution, Wp Event Solution | 2026-10-06 | 5.3 Medium |
| Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through 4.1.25. | ||||
| CVE-2026-39783 | 2 Wordpress-extensions, Wp Syntex | 2 Polylang, Polylang | 2026-10-06 | 4.3 Medium |
| Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a through 3.8.7. | ||||
| CVE-2026-105421 | 2 Nathanbarry, Wordpress-extensions | 2 Kit (formerly Convertkit) For Woocommerce, Kit (formerly Convertkit) For Woocommerce | 2026-10-06 | 5.3 Medium |
| Missing Authorization vulnerability in Kit Kit (formerly ConvertKit) for WooCommerce convertkit-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kit (formerly ConvertKit) for WooCommerce: from n/a through 2.2.0. | ||||
| CVE-2026-102780 | 1 Joomlafry.com | 1 Tf Content For Joomla | 2026-10-06 | N/A |
| Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4 - The extension unconditionally authorizes both creation and editing in its public `RecordController`. Its shared frontend save controller accepts the raw `jform` array, assigns the request-selected existing record ID, and saves it without filtering submitted properties through the configured form. A Guest can obtain a valid token from Joomla's public login form and modify any TF Content row, including mass-assigning `published`, `access`, and `created_by`. | ||||
| CVE-2026-102779 | 1 Joomlafry.com | 1 Tf Content For Joomla | 2026-10-06 | N/A |
| Joomla Extension - joomlafry.com - Unauthenticated forced execution of published automation tasks in TF Content 2.9.0 - 2.9.4 - The extension exposes the site task `records.custom_action` without authentication, ACL, CSRF, task-trigger, content-binding, or cron-token enforcement. A Guest can supply the numeric ID of any published TF Content task and make the component dispatch its configured executor immediately. | ||||
| CVE-2026-103433 | 1 Docker | 1 Buildx | 2026-10-06 | N/A |
| Docker Buildx Bake does not request the expected fs.read approval for certain filesystem inputs. An untrusted Bake definition can expose a readable file through a pathless secret whose ID is interpreted as a client-side pathname, or consume a local OCI image layout outside the project after entitlement validation checks a different path representation. Users who run untrusted Bake definitions are affected. | ||||
| CVE-2026-42637 | 2 Payplug, Wordpress-extensions | 2 Payplug For Woocommerce (official), Payplug For Woocommerce (official) | 2026-10-06 | 6.5 Medium |
| Unauthenticated Settings Change in PayPlug for WooCommerce (Official) <= 3.1.0 versions. | ||||
| CVE-2026-48199 | 2 Beplusthemes, Wordpress-extensions | 2 Sermon'e, Sermon'e | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in Sermon'e <= 1.0.2 versions. | ||||
| CVE-2026-62072 | 2 Progress Planner, Wordpress-extensions | 2 Progress Planner, Progress Planner | 2026-10-06 | 8.8 High |
| Subscriber Broken Access Control in Progress Planner <= 1.10.0 versions. | ||||
| CVE-2026-66588 | 2 Dream-theme, Wordpress-extensions | 2 The7, The7 | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Access Control in The7 <= 14.2.2 versions. | ||||
| CVE-2026-95526 | 2 Realmag777, Wordpress-extensions | 2 Bear, Bear | 2026-10-06 | 7.3 High |
| Unauthenticated Broken Access Control in BEAR <= 1.2.2 versions. | ||||
| CVE-2026-102915 | 2 Marco Van Wieren, Wordpress-extensions | 2 Wpo365, Wpo365 | 2026-10-06 | 8.5 High |
| Subscriber Broken Access Control in WPO365 <= 44.1 versions. | ||||
| CVE-2026-104387 | 2 Blubrry, Wordpress-extensions | 2 Powerpress Podcasting, Powerpress Podcasting | 2026-10-06 | 7.2 High |
| Unauthenticated Broken Access Control in PowerPress Podcasting <= 11.17.9 versions. | ||||
| CVE-2026-104406 | 2 Picu, Wordpress-extensions | 2 Picu, Picu | 2026-10-06 | 7.3 High |
| Unauthenticated Broken Access Control in picu <= 3.10.1 versions. | ||||
| CVE-2026-105059 | 2 Royalnavneet, Wordpress-extensions | 2 Delete All Comments Of Wordpress, Delete All Comments Of Wordpress | 2026-10-06 | 6.5 Medium |
| Subscriber Broken Access Control in Delete All Comments of wordpress <= 7.1 versions. | ||||
| CVE-2026-105680 | 1 Ghost | 1 Ghost | 2026-10-06 | 6.5 Medium |
| Ghost is a Node.js content management system. From 5.81.0 until 6.60.0, staff with the Author role could delete posts and pages that they did not author. This issue is fixed in version 6.60.0. | ||||
| CVE-2026-105698 | 1 Langflow | 2 Langflow, Langflow-base | 2026-10-06 | 5.4 Medium |
| Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.0.0 until 1.10.1, Langflow did not verify flow ownership in the deprecated POST /api/v1/build/{flow_id}/vertices and POST /api/v1/build/{flow_id}/vertices/{vertex_id} handlers. Through version 1.7.1, an unauthenticated caller who knew another user's flow UUID could reach these handlers; from version 1.7.2 through 1.10.0, callers had to authenticate but needed no elevated privileges. Such a caller could cause retrieve_vertices_order to load and cache the private graph, enumerate its vertex identifiers, and use build_vertex to execute selected vertices and receive their results. build_graph_from_db_no_cache performed a primary-key lookup without an owner filter. This could disclose private flow structure, configured values, and selected outputs and could trigger victim-configured side effects and build-history records, although it did not expose the victim's variable-store credentials or permit modification of the stored flow. This issue is fixed in Langflow 1.10.1 and langflow-base 0.10.1. | ||||
| CVE-2026-86136 | 1 Watchguard | 2 Fireware, Fireware Os | 2026-10-06 | 8.1 High |
| A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request. | ||||
| CVE-2026-90441 | 1 Watchguard | 2 Fireware, Fireware Os | 2026-10-06 | 8.1 High |
| A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request. | ||||