Export limit exceeded: 385962 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (385962 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104754 | 2026-10-10 | N/A | ||
| The Rank Math SEO WordPress plugin before 1.0.280 does not escape a stored redirection source value before outputting it in an administrative list view, allowing users who can manage redirections (Administrators by default) to store JavaScript that executes in the session of any user who later opens that view, including a Super Administrator on multisite. | ||||
| CVE-2026-105989 | 2026-10-10 | N/A | ||
| The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization or request-validation checks on one of its AJAX actions, allowing unauthenticated attackers to forge the stored transaction status of records and to write the Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7's status metadata onto arbitrary posts. | ||||
| CVE-2026-105990 | 2026-10-10 | N/A | ||
| The Accept PayPal Payments using Contact Form 7 WordPress plugin before 4.0.7 does not perform any authorization checks before exporting stored form submissions, allowing unauthenticated attackers to download the personal data (name, email, telephone, postal address, message) and payment metadata of everyone who submitted a payment form. | ||||
| CVE-2026-105995 | 2026-10-10 | N/A | ||
| The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens. | ||||
| CVE-2026-85571 | 2026-10-10 | N/A | ||
| The Tutor LMS WordPress plugin before 4.1.1 does not verify that the posts named in its course content ordering requests belong to a course the requester manages, allowing users with instructor level access to reassign the parent of any post on the site, taking other instructors' course content into their own courses and making arbitrary published content unreachable. | ||||
| CVE-2026-87780 | 2026-10-10 | N/A | ||
| The LTL Freight Quotes WordPress plugin before 4.2.19 does not sanitise and escape values submitted through an unauthenticated endpoint before storing them and outputting them back in an administrative page, leading to Stored XSS which will execute in the session of any administrator viewing it. | ||||
| CVE-2026-94256 | 2026-10-10 | N/A | ||
| The SMS Alert WordPress plugin before 4.0.1 does not verify that the account being logged in is the one the verified one-time code belongs to, allowing unauthenticated attackers to sign in as any user with a stored phone number, including an administrator, by completing a code challenge on a phone they control. | ||||
| CVE-2026-108504 | 2026-10-10 | 5.5 Medium | ||
| ZTE Z80 Ultra has an unauthorized information disclosure vulnerability. The access control for methods within the framework is insufficient. An attacker can exploit this method to read device-related information. | ||||
| CVE-2026-95116 | 1 Libming | 1 Libming | 2026-10-10 | 7.5 High |
| An issue in libming through 0.4.8 allows a remote attacker to cause a denial of service via the readtag_file() in src/blocks/fromswf.c. | ||||
| CVE-2026-62045 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0. | ||||
| CVE-2026-62046 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12. | ||||
| CVE-2026-93945 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0. | ||||
| CVE-2026-93944 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15. | ||||
| CVE-2026-93943 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0. | ||||
| CVE-2026-93942 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a through 1.16.0. | ||||
| CVE-2026-93941 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2. | ||||
| CVE-2026-93940 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0. | ||||
| CVE-2026-93938 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7. | ||||
| CVE-2026-93937 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0. | ||||
| CVE-2026-93936 | 2026-10-10 | 9.8 Critical | ||
| Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4. | ||||