Search

Search Results (400945 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100793 1 Mozilla 1 Firefox 2026-10-01 6.5 Medium
JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
CVE-2026-95314 1 Google 1 Chrome 2026-10-01 8.1 High
Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95303 1 Google 1 Chrome 2026-10-01 6.5 Medium
Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95275 1 Google 1 Chrome 2026-10-01 6.5 Medium
Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-51856 2026-10-01 9.8 Critical
In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to Toolkit.call_tool_function, which invokes execute_python_code without an additional approval or isolation boundary on that path.
CVE-2026-51860 1 Dataelement 1 Bisheng 2026-10-01 7.5 High
bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Directory Traversal in src/backend/bisheng/linsight/domain/task_exec.py.
CVE-2026-88408 1 Falkordb 1 Falkordb 2026-10-01 6.5 Medium
FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function (/ops/op_aggregate.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2026-62084 1 Jeff Starr 1 User Submitted Posts 2026-10-01 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS. This issue affects User Submitted Posts: from n/a through 20260810.
CVE-2026-103445 1 Wikimedia 1 Mediawiki-page Forms Extension 2026-10-01 N/A
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43.
CVE-2026-103437 1 Wikimedia 1 Mediawiki-readinglists Extension 2026-10-01 N/A
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS. This issue affects MediaWiki ReadingLists extension: 1.46 and 1.45.
CVE-2026-103438 1 Wikimedia 1 Mediawiki-wikistories Extension 2026-10-01 N/A
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikistories extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki Wikistories extension: 1.46, 1.45, and 1.43.
CVE-2026-102397 2 Supsystic, Wordpress-extensions 2 Ultimate Maps By Supsystic, Ultimate Maps By Supsystic 2026-10-01 6.5 Medium
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions.
CVE-2026-94171 2 Villatheme, Wordpress-extensions 2 Curcy, Curcy 2026-10-01 7.1 High
Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions.
CVE-2026-97256 2 Greg–siteorigin, Wordpress-extensions 2 Page Builder By Siteorigin, Page Builder By Siteorigin 2026-10-01 7.2 High
Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.
CVE-2026-97265 2 Crocoblock. Jetimpex Inc., Wordpress-extensions 2 Jetengine, Jetengine 2026-10-01 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.8.15.3.
CVE-2026-97290 2 Sayontan Sinha, Wordpress-extensions 2 Photonic Gallery & Lightbox For Flickr, Smugmug & Others, Photonic Gallery & Lightbox For Flickr, Smugmug & Others 2026-10-01 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions.
CVE-2026-97291 2 Magazine3, Wordpress-extensions 2 Schema & Structured Data For Wp & Amp, Schema & Structured Data For Wp & Amp 2026-10-01 8.8 High
Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.
CVE-2026-100510 2 Boldgrid, Wordpress-extensions 2 Post And Page Builder, Post And Page Builder By Boldgrid 2026-10-01 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.
CVE-2026-100512 2 Hook & Filter, Wordpress-extensions 2 Nested Pages, Nested Pages 2026-10-01 9.8 Critical
Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
CVE-2026-102375 2 Optimole, Wordpress-extensions 2 Optimole, Optimole 2026-10-01 6.5 Medium
Subscriber Broken Access Control in Optimole <= 4.2.14 versions.