Export limit exceeded: 402649 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402649 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-106508 | 2026-10-06 | 5.3 Medium | ||
| Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. When using the local TechDocs publisher (techdocs.publisher.type: 'local'), it was possible for the documentation serving endpoint to follow filesystem references outside the intended documentation tree, potentially exposing host files to authenticated users. This is mitigated by the fact that exploration requires preconditions that do not arise through normal MkDocs operation. Cloud-based publishers (S3, GCS, Azure Blob Storage) are not affected. This issue is fixed in version 1.15.4. | ||||
| CVE-2026-106507 | 2026-10-06 | 5.3 Medium | ||
| Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. Unsafe path resolution in TechDocs source tree handling allows an authenticated user who can register documentation sources to include content from outside the intended documentation boundary. Depending on deployment, this may expose files readable by the build process. This issue is fixed in version 1.15.4. | ||||
| CVE-2026-104047 | 1 Redhat | 2 Enterprise Linux, Openshift | 2026-10-06 | 5.3 Medium |
| A flaw was found in SSSD. When configured to use Microsoft Entra ID, search inputs are not properly sanitized before being incorporated into directory query filters. A local user can exploit this vulnerability by submitting a crafted lookup request, manipulating the query logic to cause unauthorized information disclosure from the directory. | ||||
| CVE-2026-106505 | 2026-10-06 | 7.7 High | ||
| Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by bypass of mkdocs configuration sanitizer in techdocs backend. Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer introduced in response to CVE-2026-25153 and execute arbitrary code on the TechDocs backend host during documentation generation. This issue is fixed in versions 1.14.6 and 1.15.4. | ||||
| CVE-2026-39758 | 2 Midtrans, Wordpress-extensions | 2 Midtrans-woocommerce, Midtrans-woocommerce | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Midtrans-WooCommerce <= 2.32.3 versions. | ||||
| CVE-2026-39759 | 2 Amentotech, Wordpress-extensions | 2 Workreap, Workreap | 2026-10-06 | 9.9 Critical |
| Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions. | ||||
| CVE-2026-39761 | 2 Elightup, Wordpress-extensions | 2 Meta Box Aio, Meta Box Aio | 2026-10-06 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Meta Box AIO <= 3.7.1 versions. | ||||
| CVE-2026-39762 | 2 Patterns In The Cloud, Wordpress-extensions | 2 Autoship Cloud For Woocommerce Subscription Products, Autoship Cloud For Woocommerce Subscription Products | 2026-10-06 | 6.5 Medium |
| Missing Authorization vulnerability in Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products autoship-cloud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.17.1. | ||||
| CVE-2026-39764 | 2 Radiustheme, Wordpress-extensions | 2 Radius Booking — Booking Calendar For Appointments & Services, Radius Booking | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments & Services <= 1.0.19 versions. | ||||
| CVE-2026-39765 | 2 Webappick, Wordpress-extensions | 2 Challan, Challan | 2026-10-06 | 7.2 High |
| Shop Manager Privilege Escalation in Challan <= 3.7.88 versions. | ||||
| CVE-2026-39766 | 2 Reputeinfosystems, Wordpress-extensions | 2 Arforms, Arforms | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions. | ||||
| CVE-2026-39767 | 2 Baseapp, Wordpress-extensions | 2 Wpbase Cache, Wpbase Cache | 2026-10-06 | 6.5 Medium |
| Subscriber Denial of Service Attack in WPBase Cache <= 5.5.6 versions. | ||||
| CVE-2026-39768 | 2 Cleantalk, Wordpress-extensions | 2 Security & Malware Scan, Security & Malware Scan By Cleantalk | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Security & Malware scan by CleanTalk <= 2.189 versions. | ||||
| CVE-2026-39769 | 2 Iqonicdesign, Wordpress-extensions | 2 Graphina, Graphina | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions. | ||||
| CVE-2026-39770 | 2 Amentotech, Wordpress-extensions | 2 Doctreat Core, Doctreat | 2026-10-06 | 10 Critical |
| Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions. | ||||
| CVE-2026-39771 | 2 Mightynetworks Vs Buddyboss, Wordpress-extensions | 2 Buddyboss Platform, Buddyboss Platform | 2026-10-06 | 8.5 High |
| Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions. | ||||
| CVE-2026-39772 | 2 Bestwebsoft, Wordpress-extensions | 2 Captcha By Bestwebsoft, Captcha By Bestwebsoft | 2026-10-06 | 5.3 Medium |
| Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions. | ||||
| CVE-2026-39773 | 2 Amentotech, Wordpress-extensions | 2 Doctreat Core, Doctreat Core | 2026-10-06 | 10 Critical |
| Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions. | ||||
| CVE-2026-39774 | 2 Tourfic Ai Studio, Wordpress-extensions | 2 Tourfic Pro, Tourfic Pro | 2026-10-06 | 8.8 High |
| Unauthenticated Privilege Escalation in Tourfic Pro <= 1.17.3 versions. | ||||
| CVE-2026-39775 | 2 Dexignzone, Wordpress-extensions | 2 Jobzilla - Job Board Wordpress Theme, Jobzilla | 2026-10-06 | 8.8 High |
| Subscriber Privilege Escalation in JobZilla - Job Board WordPress Theme <= 2.2 versions. | ||||
