Export limit exceeded: 100739 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (100739 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-4997 | 2026-09-23 | 8.6 High | ||
| The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes. | ||||
| CVE-2026-6285 | 1 Ankaref Innovation And Technology Inc. | 1 Librid/libref | 2026-09-23 | 7.5 High |
| Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9.26.2319. | ||||
| CVE-2026-93778 | 2 Jgwhite33, Wordpress | 2 Wp Yelp Review Slider, Wordpress | 2026-09-23 | 7.2 High |
| The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all versions up to, and including, 9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The malicious payload originates from an anonymous Yelp reviewer on a public platform and requires no WordPress account; it is introduced into the database during the site administrator's ordinary use of the plugin's Download Reviews feature, making the effective attacker unauthenticated. | ||||
| CVE-2026-95511 | 2 Cups, Redhat | 3 Cups, Enterprise Linux, Hardened Images | 2026-09-23 | 8.2 High |
| Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in cupsd admin role granted by a superuser. No privilege boundary is crossed. | ||||
| CVE-2026-95619 | 1 Redhat | 5 Enterprise Linux, Hardened Images, Hummingbird and 2 more | 2026-09-23 | 7.7 High |
| A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability. | ||||
| CVE-2026-81999 | 1 Adobe | 2 Aem 6.5 Forms Jee, Aem 6.5 Lts Forms Jee | 2026-09-23 | 8.7 High |
| Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed. | ||||
| CVE-2026-75744 | 1 Adobe | 2 Aem 6.5 Forms Jee, Aem 6.5 Lts Forms Jee | 2026-09-23 | 8.1 High |
| Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed. | ||||
| CVE-2026-75743 | 1 Adobe | 2 Aem 6.5 Forms Jee, Aem 6.5 Lts Forms Jee | 2026-09-23 | 7.1 High |
| Adobe Experience Manager Forms JEE is affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. | ||||
| CVE-2026-76712 | 1 Hewlett Packard Enterprise (hpe) | 1 Ale | 2026-09-23 | 7.3 High |
| A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service. An unauthenticated remote attacker could exploit the vulnerable system by sending specially crafted input or intercepting network communications. Successful exploitation could result in the disclosure of sensitive information, bypass of security controls, or a denial of service condition on the affected system. | ||||
| CVE-2026-76713 | 1 Hewlett Packard Enterprise (hpe) | 1 Ale | 2026-09-23 | 7.2 High |
| A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker to gain unauthorized access to the file system with root privileges, potentially resulting in full system compromise. | ||||
| CVE-2026-76714 | 1 Hewlett Packard Enterprise (hpe) | 1 Ale | 2026-09-23 | 7.2 High |
| Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise. | ||||
| CVE-2026-76715 | 1 Hewlett Packard Enterprise (hpe) | 1 Ale | 2026-09-23 | 7.1 High |
| A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-middle (MitM) attack. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the affected appliance. | ||||
| CVE-2026-63104 | 1 Usekaneo | 1 Kaneo | 2026-09-23 | 8.1 High |
| Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace members with viewer or member roles to delete and modify tasks beyond their assigned permissions by exploiting the bulk task endpoint that omits workspace permission checks. Attackers can send requests to the PATCH /api/task/bulk endpoint, which verifies only workspace membership without calling the role-based permission check enforced on all other task endpoints, to permanently delete all tasks or modify task status, priority, assignee, due date, and labels in a workspace. | ||||
| CVE-2026-61570 | 1 Joniles | 1 Mpxj | 2026-09-23 | 7.5 High |
| MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 5.5.5 until 16.4.1, MerlinReader creates a DocumentBuilder with default settings while parsing XML from the ZTIMEINTERVALS column of a Merlin project SQLite database, leaving doctype declarations and external entities enabled. A crafted database can cause the parser to read an arbitrary local file, although MPXJ's subsequent handling of the parsed XML makes disclosure of the file contents unlikely. This issue is fixed in version 16.4.1. | ||||
| CVE-2026-79906 | 1 Adobe | 1 Substance 3d Modeler | 2026-09-23 | 7.8 High |
| Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||||
| CVE-2026-83962 | 1 Adobe | 1 Substance 3d Modeler | 2026-09-23 | 7.8 High |
| Substance3D - Modeler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||||
| CVE-2026-65178 | 1 Nvidia | 1 Nemo Speech | 2026-09-23 | 7.8 High |
| NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted model_config.yaml can inject unsafe parameters. A successful exploit of this vulnerability may lead to code execution, data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-93749 | 1 7rulnik | 1 Source-map-js | 2026-09-23 | 7.5 High |
| source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronous event loop blocking for extended periods, preventing the service from handling other requests. | ||||
| CVE-2026-95924 | 1 Sourcecodester | 1 Online Reviewer Management System | 2026-09-23 | 7.3 High |
| A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=add. The manipulation of the argument difficulty_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2026-96272 | 1 Clip-bucket | 1 Clipbucket | 2026-09-23 | 7.5 High |
| ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into SQL WHERE and ORDER BY clauses. Unauthenticated attackers can exploit time-based blind SQL injection techniques to extract user credentials, email addresses, and administrator password hashes for account takeover. | ||||