Search

Search Results (399542 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-69530 1 Microsoft 6 Windows 10 1809, Windows Server 2019, Windows Server 2019 (server Core Installation) and 3 more 2026-09-29 8.1 High
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
CVE-2026-86450 2026-09-29 7.5 High
Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects DetaWix Mobile Web Portal: before v1.0.19.
CVE-2026-77255 2 Mcp-atlassian, Sooperset 2 Mcp Atlassian, Mcp-atlassian 2026-09-29 8.6 High
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira update_issue attachments argument is converted into local paths and routed to the attachment upload implementation without workspace validation. A caller can make the MCP server read arbitrary local files and attach them to a Jira issue, using the server as a confused deputy to exfiltrate the contents. The advisory traces the vulnerable input and processing flow through jira update_issue, attachments, upload_attachment, and file_path, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.
CVE-2026-69384 1 Microsoft 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more 2026-09-29 7.1 High
Null pointer dereference in Virtual Hard Disk (VHD) Miniport Driver allows an unauthorized attacker to deny service locally.
CVE-2026-77825 1 Ibm 3 Contextforge, Contextforge-mcp-gateway, Contextforge Mcp Gateway 2026-09-29 4.9 Medium
IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files outside the configured `LOG_FOLDER` by supplying a filename that resolves into a sibling directory whose absolute path shares the log directory's string prefix.
CVE-2026-76654 1 Kubernetes 1 Kubelet 2026-09-29 5.8 Medium
A flaw was found in Kubernetes kubelet on Windows nodes. When kubelet resolves a volume subPath that is a symbolic link, it does not reject an ordinary UNC network path. Following that link causes Windows to authenticate to the remote share with NTLM, exposing the NetNTLMv2 hash of the kubelet account. That hash may be cracked or, if the node is domain-joined, used in an NTLM relay.
CVE-2026-13018 1 Google 1 Chrome 2026-09-29 4.3 Medium
Insufficient validation of untrusted input in Codecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially perform out of bounds memory access via a crafted video file. (Chromium security severity: Low)
CVE-2026-73446 1 Arista 1 Eos 2026-09-29 7.4 High
On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.
CVE-2026-73459 1 Arista 1 Eos 2026-09-29 7.4 High
On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database. This may result in traffic loss.
CVE-2026-73460 1 Arista 1 Eos 2026-09-29 6.1 Medium
On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely. This may result in traffic loss following a restart event.
CVE-2026-73450 1 Arista 1 Eos 2026-09-29 6.9 Medium
On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-primary state. If the MLAG primary switch fails while these packets are present, the secondary switch incorrectly concludes it is in a dual-primary condition and err-disables its interfaces, leading to a traffic interruption.
CVE-2026-87963 1 Wordpress-extensions 1 Yo 2026-09-29 8.6 High
The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attackers to perform SQL injection and read arbitrary database contents including administrator password hashes.
CVE-2026-66618 2 Flippercode, Wordpress-extensions 2 Wp Maps, Wp Maps 2026-09-29 7.6 High
Administrator SQL Injection in WP Maps <= 4.9.9 versions.
CVE-2026-66619 2 Tribulant, Wordpress-extensions 2 Newsletters, Newsletters 2026-09-29 7.6 High
Administrator SQL Injection in Newsletters <= 4.18 versions.
CVE-2026-66631 2 Moreconvert, Wordpress-extensions 2 Woocommerce Wishlist, Mc Woocommerce Wishlist 2026-09-29 7.6 High
Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.
CVE-2026-73999 2 Goratech, Wordpress-extensions 2 Cooked, Cooked 2026-09-29 5.4 Medium
Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.
CVE-2026-78528 2 Berqier, Wordpress-extensions 2 Berqwp, Berqwp 2026-09-29 5.3 Medium
Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.
CVE-2026-16750 2 Stylemixthemes, Wordpress-extensions 2 Motors - Car Dealer, Classifieds & Listing, Motors – Car Dealership & Classified Listings 2026-09-29 5.3 Medium
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_load_cars() function in all versions up to, and including, 1.4.120. This makes it possible for unauthenticated attackers to retrieve draft, pending, private, and future car listings belonging to arbitrary users.
CVE-2026-16582 2 Ameliabooking, Wordpress-extensions 2 Booking For Appointments And Events Calendar, Booking For Appointments And Events Calendar – Amelia 2026-09-29 5.3 Medium
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.4.5. This is due to the plugin accepting a client-supplied package-redemption identifier as proof of payment without validating it. This makes it possible for unauthenticated attackers to create approved appointment bookings without completing payment
CVE-2026-14311 2 Ameliabooking, Wordpress-extensions 2 Booking For Appointments And Events Calendar, Booking For Appointments And Events Calendar – Amelia 2026-09-29 5.4 Medium
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with wpamelia-provider role, to view and modify arbitrary customers, including password reset. Takeover of WordPress user accounts, with the roles up to Editor, is also possible if that user had made an Amelia booking. This vulnerability affects only the Premium version of the plugin, where the Employee Panel is present.