Export limit exceeded: 403720 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (403720 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-84224 2026-10-09 4.1 Medium
The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetching it, allowing users with editor-level access and above to make the site issue requests to internal services that are not otherwise reachable, and to tell which of those are live from the response.
CVE-2026-84220 2026-10-09 4.8 Medium
The Kirki WordPress plugin before 6.3.2 does not prevent shortcodes held in comments from being executed when it renders them, and displays comments regardless of their moderation status, allowing unauthenticated visitors to run shortcodes registered on the site and to read private custom fields of the page being viewed.
CVE-2026-84032 1 Ibm 1 Guardium Data Protection 2026-10-09 5.6 Medium
IBM Guardium Data Protection 12.2.2 could allow a remote attacker to conduct a man-in-the-middle attack due to improper certificate validation.
CVE-2026-83947 1 Microsoft 1 Azure Event Grid System 2026-10-09 7.7 High
Missing authorization in Azure Event Grid allows an authorized attacker to perform spoofing over a network.
CVE-2026-83943 1 Microsoft 1 Azure Api Center 2026-10-09 8.7 High
Exposure of sensitive information to an unauthorized actor in Azure API Center allows an unauthorized attacker to disclose information over a network.
CVE-2026-78027 2026-10-09 5.8 Medium
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Server-side request forgery.
CVE-2026-78022 2026-10-09 6.8 Medium
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Not Failing Securely ('Failing Open') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
CVE-2026-78017 2026-10-09 3.8 Low
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Check for Unusual or Exceptional Conditions vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Protection mechanism bypass.
CVE-2026-77900 1 Microsoft 1 Azure App Service 2026-10-09 9.8 Critical
Missing authentication for critical function in Azure App Service allows an unauthorized attacker to execute code over a network.
CVE-2026-76769 2026-10-09 4.3 Medium
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
CVE-2026-75875 1 Ibm 1 Guardium Data Protection 2026-10-09 9.8 Critical
IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to path traversal.
CVE-2026-69435 1 Microsoft 1 Azure Sre Agent 2026-10-09 9.6 Critical
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
CVE-2026-49243 1 Webmin 1 Webmin 2026-10-09 9.6 Critical
Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.650, Webmin users who click on a malicious link to their server are vulnerable to this XSS vulnerability that could be used to execute attacker-controlled commands. This issue has been patched in version 2.650.
CVE-2026-108107 2026-10-09 9.8 Critical
PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to extract customer records and credentials via time-based blind SQL injection.
CVE-2026-108102 1 Open5gs 1 Open5gs 2026-10-09 5.3 Medium
Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_volume_measurement() in lib/pfcp/types.c that allows remote unauthenticated attackers to read past IE buffers. Attackers can send a PFCP Session Report Request to the SMF on UDP port 8805 with a short, all-flags Volume Measurement IE, reading up to 48 bytes and potentially crashing the SMF.
CVE-2026-107828 1 Banq 1 Jivejdon 2026-10-09 6.5 Medium
Jivejdon through 5.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access Weibo-created accounts by deriving predictable credentials from public Weibo user IDs. OAuthAccountServiceImp.transferSina() sets the password to the first four digits of the Weibo ID, letting attackers log in through normal form login to read or post as victims.
CVE-2026-107800 1 Banq 1 Jivejdon 2026-10-09 5.4 Medium
Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script into private short messages because receiveshortmessage.jsp renders unfiltered message bodies. Attackers can send a short message containing script, which ToolsUtil.convertURL() passes through unchanged, to execute code in the recipient's browser when opened.
CVE-2026-107797 1 Banq 1 Jivejdon 2026-10-09 6.1 Medium
Jivejdon through 5.0 contains a reflected cross-site scripting vulnerability in application/message/postThread.jsp that allows attackers to inject script via the to and tag parameters. Attackers can send crafted links to authenticated users, breaking out of unencoded inline JavaScript string literals to execute arbitrary JavaScript in the victim's session.
CVE-2026-107793 1 Banq 1 Jivejdon 2026-10-09 4.3 Medium
Jivejdon through 5.0 contains an authorization bypass vulnerability in SubscriptionServiceImp.deleteSubscription that allows authenticated users to delete other users' subscriptions by ID. Attackers can submit a delete action to /account/protected/sub/subSaveAction with another user's subscriptionId to remove their thread, forum, tag or account subscriptions.
CVE-2026-107725 1 Hazelcast 1 Hazelcast 2026-10-09 8.8 High
Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, missing authorization checks in the IMap Predicates API allow a malicious client with limited privileges to execute arbitrary code on a Hazelcast cluster member. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.