Search

Search Results (382439 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-62071 2026-10-01 9.3 Critical
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.
CVE-2026-103752 2026-10-01 9.8 Critical
Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions.
CVE-2026-103687 1 Rhukster 1 Dom-sanitizer 2026-10-01 7.3 High
A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.16 is sufficient to fix this issue. The name of the patch is 139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a. Upgrading the affected component is recommended.
CVE-2026-19253 2026-10-01 8.7 High
The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated users to delete arbitrary files and directories on sites where another installed Cache Enabler WordPress plugin before 1.8.17 or passes a request-derived URL to its public cache-clearing hook.
CVE-2026-90972 2026-10-01 5.4 Medium
The WP Fusion Lite WordPress plugin before 3.48.0 does not perform a capability check on two of its admin AJAX handlers, allowing any authenticated subscriber to read other users' email addresses and to trigger a cross-user CRM re-sync.
CVE-2026-66247 2026-10-01 4.3 Medium
iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabling an attacker to access and exfiltrate sensitive data within the context of the victim's active session.
CVE-2026-47512 1 Nvidia 5 Geforce, Nvs, Quadro and 2 more 2026-10-01 7.8 High
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read leading to kernel information disclosure. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
CVE-2026-102587 1 Moodle 1 Moodle 2026-10-01 2.7 Low
A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized information disclosure by inferring hidden user data.
CVE-2026-103491 1 Jetbrains 1 Youtrack 2026-10-01 6.5 Medium
In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
CVE-2026-103497 1 Jetbrains 1 Youtrack 2026-10-01 5.5 Medium
In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
CVE-2026-103496 1 Jetbrains 1 Youtrack 2026-10-01 5.4 Medium
In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications
CVE-2026-103495 1 Jetbrains 1 Youtrack 2026-10-01 4.3 Medium
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs
CVE-2026-103494 1 Jetbrains 1 Youtrack 2026-10-01 6.6 Medium
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes
CVE-2026-103493 1 Jetbrains 1 Youtrack 2026-10-01 8.1 High
In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
CVE-2024-58388 2026-10-01 7.5 High
Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, including /etc/passwd, coredump files containing credentials, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.
CVE-2026-95366 1 Google 1 Chrome 2026-10-01 6.5 Medium
Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-102579 1 Moodle 1 Moodle 2026-10-01 4.3 Medium
A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other students enrolled in the same course that they should not have permission to view. This issue leads to unauthorized information disclosure.
CVE-2026-103492 1 Jetbrains 1 Youtrack 2026-10-01 6.5 Medium
In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments
CVE-2026-96760 1 Authlib 1 Authlib 2026-10-01 9.8 Critical
Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.
CVE-2026-94276 2026-10-01 N/A
Improper Authentication vulnerability in Apache APISIX. On a route using openid-connect plugin with remote introspection against an authorization server that serves multiple issuers, a token that introspects as active for one issuer may get accepted on a route restricted to another. This issue affects Apache APISIX: from 3.12.0 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.