Search

Search Results (402632 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-104672 2 Nexcess, Wordpress-extensions 2 Givewp, Givewp 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.17.0 versions.
CVE-2026-104747 2 Edge-themes, Wordpress-extensions 2 Haaken, Haaken 2026-10-06 8.1 High
Unauthenticated PHP Object Injection in Haaken <= 1.5 versions.
CVE-2026-104757 2 Carazo, Wordpress-extensions 2 Import And Export Users And Customers, Import And Export Users And Customers 2026-10-06 7.2 High
Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions.
CVE-2026-104814 2 Epiph, Wordpress-extensions 2 Form Block, Form Block 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Form Block <= 1.8.1 versions.
CVE-2026-105057 2 Ben Marshall, Wordpress-extensions 2 Zero Spam, Zero Spam 2026-10-06 5.3 Medium
Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions.
CVE-2026-105058 2 John James Jacoby, Wordpress-extensions 2 Wp User Profiles, Wp User Profiles 2026-10-06 8.8 High
Subscriber Privilege Escalation in WP User Profiles <= 2.7.3 versions.
CVE-2026-105059 2 Royalnavneet, Wordpress-extensions 2 Delete All Comments Of Wordpress, Delete All Comments Of Wordpress 2026-10-06 6.5 Medium
Subscriber Broken Access Control in Delete All Comments of wordpress <= 7.1 versions.
CVE-2026-105061 2 Brandtoss, Wordpress-extensions 2 Wpmailster, Wp Mailster 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP Mailster <= 1.9.0.0 versions.
CVE-2026-105070 2 Dimitri Grassi, Wordpress-extensions 2 Salon Booking System, Salon Booking System 2026-10-06 8.8 High
Unauthenticated Privilege Escalation in Salon booking system <= 10.31.7 versions.
CVE-2026-105071 2 Royal Plugins, Wordpress-extensions 2 Sitevault, Sitevault 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1.5.17 versions.
CVE-2026-105317 2 Cozmoslabs, Wordpress-extensions 2 Paid Member Subscriptions, Paid Member Subscriptions 2026-10-06 8.5 High
Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions.
CVE-2026-104399 2 Stylemix, Wordpress-extensions 2 Motors, Motors 2026-10-06 N/A
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124.
CVE-2026-106494 2026-10-06 4.4 Medium
Backstage is an open framework for building developer portals. Prior to 0.17.8, the @backstage/backend-defaults package is affected by improper input validation in cloud storage url readers. An attacker with write access to a cloud storage bucket used by Backstage could craft object names that could collide with protected files in the output directory. In certain deployment configurations, this could lead to content injection. This issue is fixed in version 0.17.8.
CVE-2026-106493 2026-10-06 3 Low
Backstage is an open framework for building developer portals. Prior to 1.54.6, cloud storage catalog providers did not sufficiently validate object paths. A principal able to create or rename objects in a configured Azure Blob Storage or AWS S3 catalog source could cause catalog descriptors to be read from outside the intended storage boundary, limited to locations reachable with the backend's configured credentials. This issue is fixed in 1.54.6.
CVE-2026-86104 1 Watchguard 2 Fireware, Fireware Os 2026-10-06 7.5 High
An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request.
CVE-2026-106492 2026-10-06 7.6 High
Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @backstage/backend-defaults package is affected by improper preservation of access restrictions during service credential delegation. An external service credential configured with access restrictions (e.g., read-only) could bypass those restrictions by routing requests through plugin delegation paths. This could allow a restricted service to perform operations beyond its intended scope, including write operations on plugins it was restricted to read-only access for. This issue is fixed in versions 0.16.1 and 0.17.8.
CVE-2026-86105 1 Watchguard 2 Fireware, Fireware Os 2026-10-06 7.1 High
An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.
CVE-2026-106491 2026-10-06 6.4 Medium
Backstage is an open framework for building developer portals. Prior to 0.6.17, the @backstage/plugin-proxy-backend package is affected by improper input validation in proxy-backend. An authenticated Backstage user could craft a request URL that causes the proxy-backend to forward the request to a path outside the configured base path on the target server. This is limited to target servers already configured as proxy endpoints and requires Backstage authentication by default. This issue is fixed in version 0.6.17.
CVE-2026-98239 1 Linux 1 Linux Kernel 2026-10-06 N/A
In the Linux kernel, the following vulnerability has been resolved: net: lan743x: fix RX checksum use-after-free lan743x_rx_process_buffer() adds each non-first receive buffer to the head skb's frag_list. On the last descriptor, lan743x_rx_trim_skb() linearizes the head and frees the fragment skb metadata. The checksum-success path then writes ip_summed through the local skb pointer, which still points to the final fragment. This causes a use-after-free write when a packet spans more than one receive buffer. Set ip_summed on the surviving head skb instead. Multi-buffer receive can occur after a live MTU increase because existing ring entries keep their old buffer size until they are replenished. A KUnit test invoking lan743x_rx_process_buffer() with a two-buffer packet produced a one-byte KASAN use-after-free write before this change. The same test passed after the change. The driver object also builds with W=1. This was not tested on physical LAN743x hardware.
CVE-2026-98257 1 Linux 1 Linux Kernel 2026-10-06 N/A
In the Linux kernel, the following vulnerability has been resolved: rds: ib: use rds_conn_drop() on protocol version mismatch rds_ib_cm_connect_complete() runs from the RDMA-CM event handler with conn->c_cm_lock held. When the peer negotiates a protocol version older than RDS_PROTOCOL_COMPAT_VERSION, the handler calls rds_conn_destroy(), which is only safe in the rmmod path: it synchronously tears the connection down and flush_work()es the shutdown work cp_down_w. That shutdown work (rds_conn_shutdown()) needs cp_cm_lock, which is the very lock the event handler still holds, so the flush never completes: the two workers wait on each other and the RDS connection workqueues stall for good. All other RDMA-CM failure paths (REJECTED, CONNECT_ERROR, DISCONNECTED) use rds_conn_drop(), which marks the connection RDS_CONN_ERROR and schedules the shutdown work asynchronously. Use it here as well.