Export limit exceeded: 400602 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400602 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103679 | 1 Verdammelt | 1 Tnef | 2026-10-01 | 6.5 Medium |
| A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing multiple message bodies. During extraction, improper memory management triggers a use-after-free and double-free condition, causing the application to crash and resulting in a Denial of Service (DoS). | ||||
| CVE-2026-103067 | 2 Memberful, Wordpress-extensions | 2 Memberful - Membership Plugin, Memberful | 2026-10-01 | 8 High |
| Cross-Site Request Forgery (CSRF) vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Cross Site Request Forgery.This issue affects Memberful - Membership Plugin: from n/a through 1.81.0. | ||||
| CVE-2026-103340 | 2 Geminilabs, Wordpress-extensions | 2 Site Reviews, Site Reviews | 2026-10-01 | 5.3 Medium |
| Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 8.3.2. | ||||
| CVE-2026-102381 | 2 Ahmad, Wordpress-extensions | 2 Majestic Support, Majestic Support | 2026-10-01 | 5.3 Medium |
| Missing Authorization vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0. | ||||
| CVE-2026-102390 | 2 Villatheme, Wordpress-extensions | 2 Affi – Affiliate Marketing For Woocommerce, Affi - Affiliate Marketing For Woocommerce | 2026-10-01 | 5.3 Medium |
| Missing Authorization vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.9. | ||||
| CVE-2026-103063 | 2 Wordpress-extensions, Wpmet | 2 Elementskit Elementor Addons Lite, Elementskit Elementor Addons | 2026-10-01 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor addons Lite: from n/a through 4.0.6. | ||||
| CVE-2026-102379 | 2 Villatheme, Wordpress-extensions | 2 Buildkit – Product Builder For Woocommerce – Custom Pc Builder, Buildkit-product Builder For Woocommerce-custom Pc Builder | 2026-10-01 | 8.5 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Blind SQL Injection.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28. | ||||
| CVE-2026-62061 | 2 Metagauss, Wordpress-extensions | 2 Profilegrid, Profilegrid | 2026-10-01 | 5.3 Medium |
| Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 6.0.0.2. | ||||
| CVE-2026-62060 | 2 Captivateaudio, Wordpress-extensions | 2 Captivate Sync, Captivate Sync | 2026-10-01 | 7.6 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Blind SQL Injection.This issue affects Captivate Sync: from n/a through 3.3.2. | ||||
| CVE-2026-62059 | 2 Ultimatemember, Wordpress-extensions | 2 Ultimate Member, Ultimate Member | 2026-10-01 | 7.6 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ultimate Member: from n/a through 2.13.1. | ||||
| CVE-2026-79901 | 1 Fortra | 1 Boks Manager Boks-server | 2026-10-01 | 9.9 Critical |
| In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline. | ||||
| CVE-2026-79900 | 1 Fortra | 1 Boks Manager Boks-server | 2026-10-01 | 6.5 Medium |
| boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name but do not verify that the value fits in a fixed 16-byte checksum context field before copying it. An authenticated KSL client can supply an oversized, OpenSSL-recognized digest name and write beyond the end of the heap allocation. | ||||
| CVE-2024-58388 | 2 Sharp Corporation, Toshiba Tec Corporation | 2 Multiple Multifunction Printers, Multiple Multifunction Printers | 2026-10-01 | 7.5 High |
| Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../<path> to access files outside the intended manual directory, including /etc/passwd, coredump files containing credentials, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30. | ||||
| CVE-2026-103752 | 2 Paul Ryan, Wordpress-extensions | 2 Authorizer, Authorizer | 2026-10-01 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions. | ||||
| CVE-2026-62071 | 2 Nickboss, Wordpress-extensions | 2 Wordpress File Upload, Wordpress File Upload | 2026-10-01 | 9.3 Critical |
| Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions. | ||||
| CVE-2026-62073 | 2 Themeisle, Wordpress-extensions | 2 Wp Full Stripe Free, Wp Full Stripe Free | 2026-10-01 | 7.5 High |
| Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions. | ||||
| CVE-2026-94390 | 2 Dotstore, Wordpress-extensions | 2 Hide Shipping Method For Woocommerce, Hide Shipping Method For Woocommerce | 2026-10-01 | 7.2 High |
| Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions. | ||||
| CVE-2026-97260 | 2 Maxfoundry, Wordpress-extensions | 2 Maxgalleria, Maxgalleria | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions. | ||||
| CVE-2026-97269 | 2 Getwpfunnels, Wordpress-extensions | 2 Wpfunnels, Wpfunnels | 2026-10-01 | 6.5 Medium |
| Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions. | ||||
| CVE-2026-97273 | 2 Premmerce, Wordpress-extensions | 2 Wishlist For Woocommerce, Premmerce Wishlist For Woocommerce | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions. | ||||
