Export limit exceeded: 404369 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (404369 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-108610 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AigcWordTemplateController edit handler that allows any authenticated user to modify word templates. Low-privileged attackers can send PUT or POST requests to /airag/word/edit to overwrite shared templates that other users rely on to generate documents.
CVE-2026-108591 1 Innocommerce 1 Innoshop 2026-10-10 4.4 Medium
InnoShop 0.9.2 contains a local file disclosure vulnerability that allows authenticated administrators with files_create permission to read server files by abusing the AI Core MCP file_upload tool's source argument. Attackers can supply file:// or php:// stream wrappers passed to file_get_contents(), storing contents on the public media disk to expose the .env file with APP_KEY and database credentials.
CVE-2026-103685 2026-10-10 4.3 Medium
Missing Authorization vulnerability in VillaTheme ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce woo-alidropship allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce: from n/a through 2.2.4.
CVE-2026-97853 1 Ericmj 1 Decimal 2026-10-10 N/A
Memory Allocation with Excessive Size Value vulnerability in ericmj decimal allows Denial of Service. Decimal.round/3 builds the full result for the requested number of decimal places before the context precision (34 digits by default) is applied, so its cost grows with the places argument instead of with the size of the result. For positive places it appends places zero digits to the coefficient as a charlist before converting it to an integer, and for negative places it builds a charlist of -places zero digits. A single call such as Decimal.round(Decimal.new("1.5"), -50_000_000) allocates about 5.5 GB of memory, which can exhaust available memory and get the BEAM VM killed. The oldest releases instead loop once per decimal place, consuming CPU in proportion to places. Any application that passes a user-supplied number of decimal places or scale to Decimal.round/2 or Decimal.round/3 without bounding it is exposed. The input limits added for CVE-2026-32686 do not cover the places argument. This issue affects decimal: from 0.1.0 before 3.1.2.
CVE-2026-66480 2026-10-10 5.3 Medium
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in YITH YITH WooCommerce Product Add-Ons allows Retrieve Embedded Sensitive Data. This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.34.0.
CVE-2026-81797 2026-10-10 9.8 Critical
Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme <= 1.0.2 versions.
CVE-2026-78535 2026-10-10 9.8 Critical
Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions.
CVE-2026-78533 2026-10-10 9.8 Critical
Unauthenticated PHP Object Injection in Qwery <= 3.6.1 versions.
CVE-2026-78531 2026-10-10 9.8 Critical
Unauthenticated PHP Object Injection in Jacqueline <= 2.22 versions.
CVE-2026-78530 2026-10-10 7.7 High
Subscriber Arbitrary File Deletion in FoodBakery <= 4.6 versions.
CVE-2026-78529 2026-10-10 9.8 Critical
Unauthenticated PHP Object Injection in Alliance <= 3.11 versions.
CVE-2026-66569 2026-10-10 9.8 Critical
Unauthenticated PHP Object Injection in Kicker <= 2.2.1 versions.
CVE-2026-66568 2026-10-10 9.8 Critical
Unauthenticated PHP Object Injection in Original <= 1.9.0 versions.
CVE-2026-66567 2026-10-10 9.8 Critical
Unauthenticated PHP Object Injection in Anesta <= 1.5.3 versions.
CVE-2026-66566 2026-10-10 8.1 High
Unauthenticated Local File Inclusion in Ambient <= 1.7 versions.
CVE-2026-66565 2026-10-10 9.8 Critical
Unauthenticated PHP Object Injection in FC United <= 1.1.1 versions.
CVE-2026-66564 2026-10-10 9.8 Critical
Unauthenticated PHP Object Injection in ShiftCV <= 3.0.14 versions.
CVE-2026-66563 2026-10-10 9.8 Critical
Unauthenticated PHP Object Injection in Windsor <= 2.10 versions.
CVE-2026-66483 2026-10-10 9.8 Critical
Unauthenticated PHP Object Injection in Education Center <= 3.6.12 versions.
CVE-2026-66482 2026-10-10 9.8 Critical
Unauthenticated PHP Object Injection in Drone Media <= 2.2.0 versions.