Search
Search Results (400089 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-93464 | 1 Basercms Users Community | 1 Basercms | 2026-09-30 | N/A |
| Stored Cross-Site Scripting via custom content descriptions vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused. | ||||
| CVE-2026-93462 | 1 Basercms Users Community | 1 Basercms | 2026-09-30 | N/A |
| Missing authentication for critical function vulnerability exists in baserCMS . If a remote unauthenticated attacker there is a possibility that sensitive information could be obtained. | ||||
| CVE-2026-92872 | 2026-09-30 | N/A | ||
| Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information. | ||||
| CVE-2026-69355 | 1 Microsoft | 6 Exchange Server, Exchange Server 2016, Exchange Server 2019 and 3 more | 2026-09-30 | 8.8 High |
| External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-69356 | 1 Microsoft | 5 Exchange Server, Exchange Server 2016, Exchange Server 2019 and 2 more | 2026-09-30 | 9.3 Critical |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | ||||
| CVE-2026-102399 | 2026-09-30 | 5.4 Medium | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions. | ||||
| CVE-2026-102396 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions. | ||||
| CVE-2026-102395 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions. | ||||
| CVE-2026-102386 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions. | ||||
| CVE-2026-102385 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. | ||||
| CVE-2026-102384 | 2026-09-30 | 5.9 Medium | ||
| Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions. | ||||
| CVE-2026-100513 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.5 versions. | ||||
| CVE-2026-100508 | 2026-09-30 | 5.3 Medium | ||
| Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions. | ||||
| CVE-2026-100507 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions. | ||||
| CVE-2026-97289 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions. | ||||
| CVE-2026-97288 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions. | ||||
| CVE-2026-97287 | 2026-09-30 | 8.5 High | ||
| Contributor SQL Injection in Event Tickets <= 5.29.5 versions. | ||||
| CVE-2026-97286 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Strong Testimonials <= 3.3.11 versions. | ||||
| CVE-2026-97285 | 2026-09-30 | 5.4 Medium | ||
| Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions. | ||||
| CVE-2026-97282 | 2026-09-30 | 5.3 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions. | ||||