Search
Search Results (394121 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-89418 | 2026-09-17 | N/A | ||
| google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nested START_GROUP wire bytes to any Node.js service that calls the generated deserializeBinary() API, causing a RangeError: Maximum call stack size exceeded and crashing the process. No authentication or prior knowledge of the schema is required. | ||||
| CVE-2026-14850 | 1 Mobiapparc | 1 Mobiapparc | 2026-09-17 | N/A |
| The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership. | ||||
| CVE-2026-66572 | 2026-09-17 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions. | ||||
| CVE-2026-66573 | 2026-09-17 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions. | ||||
| CVE-2026-66576 | 2026-09-17 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions. | ||||
| CVE-2026-66577 | 2026-09-17 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions. | ||||
| CVE-2026-66579 | 2026-09-17 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. | ||||
| CVE-2026-90986 | 2026-09-17 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions. | ||||
| CVE-2026-90887 | 2026-09-17 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions. | ||||
| CVE-2026-78528 | 2026-09-17 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions. | ||||
| CVE-2026-78295 | 2026-09-17 | 8.8 High | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions. | ||||
| CVE-2026-78294 | 2026-09-17 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions. | ||||
| CVE-2026-74017 | 2026-09-17 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions. | ||||
| CVE-2026-74005 | 2026-09-17 | 5.4 Medium | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions. | ||||
| CVE-2026-74002 | 2026-09-17 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions. | ||||
| CVE-2026-74000 | 2026-09-17 | 5.3 Medium | ||
| Contributor Broken Access Control in Simple Membership <= 4.8.2 versions. | ||||
| CVE-2026-73999 | 2026-09-17 | 5.4 Medium | ||
| Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions. | ||||
| CVE-2026-66676 | 2026-09-17 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions. | ||||
| CVE-2026-66631 | 2026-09-17 | 7.6 High | ||
| Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions. | ||||
| CVE-2026-66630 | 2026-09-17 | 7.6 High | ||
| Administrator SQL Injection in PublishPress Series <= 3.1.3 versions. | ||||