Export limit exceeded: 400095 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (400095 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-94673 2026-09-30 5.3 Medium
Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions.
CVE-2026-94672 2026-09-30 4.3 Medium
Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions.
CVE-2026-94499 2026-09-30 7.1 High
Subscriber Broken Access Control in FormGent <= 1.12.2 versions.
CVE-2026-94389 2026-09-30 9 Critical
Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions.
CVE-2026-94297 2026-09-30 2.7 Low
The Media Library Organizer WordPress plugin before 2.1.4 does not verify that the requesting user holds the target taxonomy's management capability before creating a new term, allowing users with contributor-level access and above to create publicly visible terms in any taxonomy registered on the site.
CVE-2026-94274 2026-09-30 5.3 Medium
The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content.
CVE-2026-94194 1 Elixir-mint 1 Mint 2026-09-30 N/A
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint client on a pooled connection, poisoning the responses to subsequent requests that share the connection. message_body/1 in lib/mint/http1.ex selects chunked framing when chunked is the first coding listed in a response's Transfer-Encoding fields. RFC 9112 section 6.3 applies chunked framing only when chunked is the final coding, and otherwise reads the body until the server closes the connection. For a response such as Transfer-Encoding: chunked, gzip, an intermediary that follows the RFC treats every byte up to the close as the body, while Mint ends the body at the zero-length chunk and parses the remaining bytes as the response to the next request on the connection. Mint also keeps the connection open after an HTTP/1.0 response, final or 1xx, that carries Transfer-Encoding and Connection: keep-alive. RFC 9112 section 6.1 requires treating the framing of such a message as faulty and closing the connection after it, so bytes after its chunked body are parsed as the response to the next request in the same way. This issue affects mint: from 0.1.0 before 1.10.2.
CVE-2026-94178 2026-09-30 7.5 High
Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions.
CVE-2026-94177 2026-09-30 8.5 High
Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions.
CVE-2026-94173 2026-09-30 5.4 Medium
Contributor Insecure Direct Object References (IDOR) in Business Directory <= 6.4.27 versions.
CVE-2026-94123 2026-09-30 7.5 High
Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions.
CVE-2026-94122 2026-09-30 7.2 High
Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions.
CVE-2026-94121 2026-09-30 8.8 High
Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions.
CVE-2026-94120 2026-09-30 7.5 High
Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.
CVE-2026-94115 2026-09-30 8.5 High
Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions.
CVE-2026-94082 2026-09-30 7.6 High
Author SQL Injection in Quiz Cat <= 3.1.1 versions.
CVE-2026-94081 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.
CVE-2026-94078 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions.
CVE-2026-94077 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions.
CVE-2026-94076 2026-09-30 8.8 High
Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.