Export limit exceeded: 395622 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (395622 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-75878 | 1 Ibm | 1 Sterling File Gateway | 2026-09-19 | 9.1 Critical |
| IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header. | ||||
| CVE-2026-73999 | 2026-09-19 | 5.4 Medium | ||
| Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions. | ||||
| CVE-2026-66626 | 2026-09-19 | 7.6 High | ||
| Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions. | ||||
| CVE-2026-66617 | 2 Publishpress, Wordpress | 2 Publishpress Series, Wordpress | 2026-09-19 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions. | ||||
| CVE-2026-66577 | 2026-09-19 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions. | ||||
| CVE-2026-66572 | 2026-09-19 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions. | ||||
| CVE-2026-61516 | 1 Netis-systems | 1 Nx10 | 2026-09-19 | 9.8 Critical |
| Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device. | ||||
| CVE-2026-56795 | 1 Dell | 3 Driver Pack For Linux Os, Driver Pack For Windows Os, Server Update Utility | 2026-09-19 | 8.2 High |
| Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. | ||||
| CVE-2026-2585 | 2 Themefusecom, Wordpress | 2 Brizy – Page Builder, Wordpress | 2026-09-19 | 6.4 Medium |
| The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ parameter in all versions up to, and including, 2.8.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-20072 | 1 Cisco | 1 Identity Services Engine Software | 2026-09-19 | 4.9 Medium |
| A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are outside the security group that the attacker is assigned to. This vulnerability exists because certain files lack proper authorization enforcement. An attacker with administrative privileges and management rights over network users could exploit this vulnerability by exporting the users. A successful exploit could allow the attacker to view passwords that are normally not visible to administrators. | ||||
| CVE-2026-1031 | 1 Ibm | 1 Common Licensing | 2026-09-19 | 6.1 Medium |
| IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | ||||
| CVE-2026-1030 | 1 Ibm | 1 Common Licensing | 2026-09-19 | 4.3 Medium |
| IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data. | ||||
| CVE-2026-1025 | 1 Ibm | 1 Common Licensing | 2026-09-19 | 6.1 Medium |
| IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | ||||
| CVE-2026-18442 | 2 Wclovers, Wordpress | 2 Wcfm Marketplace – Multivendor Marketplace For Woocommerce, Wordpress | 2026-09-19 | 7.5 High |
| The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'wcfmmp_user_location_lng' parameter in all versions up to, and including, 3.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-18441 | 2 Latepoint, Wordpress | 2 Appointment Booking Plugin – Latepoint | Calendar & Scheduling For Wordpress, Wordpress | 2026-09-19 | 4.3 Medium |
| The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.9 via the set_customer_object due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to enumerate arbitrary customer records and disclose personally identifiable information - including first name, last name, email address, and phone number - by iterating the customer[id] parameter. This issue is exploitable only when the site is configured with customer authentication disabled (guest checkout enabled). | ||||
| CVE-2026-17619 | 1 Ibm | 1 Spectrum Lsf Ibm Platform Rtm | 2026-09-19 | 8.6 High |
| IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | ||||
| CVE-2026-17262 | 1 Ibm | 1 I | 2026-09-19 | 5.4 Medium |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands. | ||||
| CVE-2026-15797 | 2 Danieliser, Wordpress | 2 Popup Maker – Boost Sales, Conversions, Optins, Subscribers With The Ultimate Wp Popup Builder, Wordpress | 2026-09-19 | 6.4 Medium |
| The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post_title in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacker to create a post with an HTML entity-encoded payload in the title, which bypasses sanitize_text_field on save and is later decoded and executed by the browser when rendered by the Select2 component. | ||||
| CVE-2026-15275 | 2026-09-19 | 7.5 High | ||
| The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The injection occurs in a numeric, unquoted SQL context, meaning WordPress's wp_magic_quotes() addslashes-based protection cannot neutralize the payload, and the AJAX handler is registered on wp_ajax_nopriv_make_search_request with no nonce or capability check, making it fully accessible without authentication. | ||||
| CVE-2026-15004 | 2026-09-19 | 5.4 Medium | ||
| The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions up to, and including, 6.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||