Search

Search Results (400209 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-69329 1 Microsoft 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more 2026-09-30 7.5 High
Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a network.
CVE-2026-69336 1 Microsoft 20 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 17 more 2026-09-30 7.1 High
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
CVE-2026-15815 1 Grafana 2 Grafana, Grafana Enterprise 2026-09-30 8.8 High
Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped executable runs with the privileges of the Grafana server process, resulting in remote code execution. Plugin archives are extracted before their signature is verified, so a valid plugin signature does not prevent the write. An operator can therefore be affected by installing a plugin that appears legitimate, as well as by installing a plugin from an arbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or preinstall configuration. Grafana Enterprise is affected because it includes the same plugin extraction code as Grafana OSS.
CVE-2026-76154 2 Grafana, Redhat 3 Grafana, Grafana Enterprise, Hummingbird 2026-09-30 7.3 High
A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin.
CVE-2026-69338 1 Microsoft 14 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 11 more 2026-09-30 7.1 High
Use after free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges over a network.
CVE-2026-69355 1 Microsoft 6 Exchange Server, Exchange Server 2016, Exchange Server 2019 and 3 more 2026-09-30 8.8 High
External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-69356 1 Microsoft 5 Exchange Server, Exchange Server 2016, Exchange Server 2019 and 2 more 2026-09-30 9.3 Critical
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-102385 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
CVE-2026-102384 2026-09-30 5.9 Medium
Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions.
CVE-2026-100513 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in CF7 Views &#8211; Complete Entry Management for Contact Form 7 <= 3.2.5 versions.
CVE-2026-100508 2026-09-30 5.3 Medium
Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions.
CVE-2026-100507 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions.
CVE-2026-97289 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.
CVE-2026-97288 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions.
CVE-2026-97287 2026-09-30 8.5 High
Contributor SQL Injection in Event Tickets <= 5.29.5 versions.
CVE-2026-97286 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in Strong Testimonials <= 3.3.11 versions.
CVE-2026-97285 2026-09-30 5.4 Medium
Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions.
CVE-2026-97282 2026-09-30 5.3 Medium
Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions.
CVE-2026-97279 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in Polylang <= 3.8.9 versions.
CVE-2026-97274 2026-09-30 9.8 Critical
Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.