Search

Search Results (371273 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-11080 2 Pickplugins, Wordpress 2 Post Grid, Wordpress 2026-09-07 9.8 Critical
The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress, granted no other security controls are present in the function.
CVE-2026-85640 1 Zohocorp 1 Manageengine Endpoint Central 2026-09-07 6.3 Medium
Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component
CVE-2026-77699 1 Zohocorp 1 Manageengine Endpoint Central 2026-09-07 5 Medium
Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path.
CVE-2026-77698 1 Zohocorp 1 Manageengine Endpoint Central 2026-09-07 5.7 Medium
Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade.
CVE-2026-86294 1 Sourcecodester 1 Simple Traffic Offense System 2026-09-07 4.3 Medium
A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the argument site_name/site_desc leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
CVE-2026-86289 1 Ollama 1 Ollama 2026-09-07 4.3 Medium
A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a manipulation results in integer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 0.31.2-rc1 is capable of addressing this issue. The patch is named 67b6a1c2d45321e0cb3c04a18073f9818de7724b. It is recommended to upgrade the affected component.
CVE-2025-15489 2 Passster Project, Wordpress 2 Passster, Wordpress 2026-09-07 5.3 Medium
The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content
CVE-2026-84849 2 Brightplugins, Wordpress 2 Pre-orders For Woocommerce, Wordpress 2026-09-07 6.5 Medium
Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.
CVE-2026-81773 2 Saturdaydrive, Wordpress 2 Ninja Forms - File Uploads, Wordpress 2026-09-07 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
CVE-2026-84753 2 Getwpfunnels, Wordpress 2 Mail Mint, Wordpress 2026-09-07 9.8 Critical
Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
CVE-2026-84754 2 Getwpfunnels, Wordpress 2 Wpfunnels, Wordpress 2026-09-07 6.5 Medium
Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions.
CVE-2026-84755 2 Getwpfunnels, Wordpress 2 Mail Mint, Wordpress 2026-09-07 6.5 Medium
Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions.
CVE-2026-84758 2 Strategy11team, Wordpress 2 Business Directory Plugin, Wordpress 2026-09-07 6.5 Medium
Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.
CVE-2026-84766 2 Wordpress, Wpmanageninja 2 Wordpress, Fluent Booking 2026-09-07 5.9 Medium
Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.
CVE-2026-84812 2 Wordplus, Wordpress 2 Better Messages, Wordpress 2026-09-07 7.1 High
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.
CVE-2026-85303 2 Magepeople, Wordpress 2 Booking & Rental Manager, Wordpress 2026-09-07 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking and Rental Manager: from n/a through 2.7.7.
CVE-2026-75160 1 Mbs-solutions 1 X-serie Gateway 2026-09-07 9.1 Critical
An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.
CVE-2026-31020 1 Arc53 1 Docsgpt 2026-09-07 9.8 Critical
In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without input sanitization or sandboxing. An unauthenticated attacker can inject malicious template expressions, leading to a server-side template injection (SSTI) vulnerability that can be exploited to achieve full remote code execution (RCE).
CVE-2026-75430 1 Powerjob 1 Powerjob 2026-09-07 9.8 Critical
PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.
CVE-2021-44320 1 Parrot 1 Ar.drone 2026-09-07 7.5 High
Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., video streaming and control) by using tool to perform an IPv4 flood attack. Verified attacks includes SYN flooding and UDP flooding.