Export limit exceeded: 402569 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (402569 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-77421 1 Jline 1 Jline 2026-09-27 6.5 Medium
JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's regex search mode passes a user-controlled search term from doSearch(String text) in builtins/src/main/java/org/jline/builtins/Nano.java to Java's backtracking regular expression engine without a timeout or backtracking bound. A nested-quantifier expression evaluated against non-matching buffer content can consume excessive CPU and indefinitely block the editor session thread, and remote multi-user deployments can lose a worker thread for each affected session. This issue is fixed in versions 3.30.15 and 4.3.1.
CVE-2026-77422 1 Jline 1 Jline 2026-09-27 7.5 High
JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command in builtins/src/main/java/org/jline/builtins/PosixCommands.java accepts a user-controlled regular expression in grep(...) and, unless line-regexp mode is used, automatically adds a dot-star prefix and suffix before compiling it with Java's backtracking regular expression engine. The wrapping expands the backtracking search space, so a short nested-quantifier expression evaluated against non-matching input can consume excessive CPU and indefinitely block a command worker, including in remotely exposed shell sessions. This issue is fixed in versions 3.30.15 and 4.3.1.
CVE-2026-93620 2 Payplus, Wordpress-extensions 2 Payplus Payment Gateway, Payplus Payment Gateway 2026-09-27 6.5 Medium
Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions.
CVE-2026-93773 2 Wobbie, Wordpress-extensions 2 Mollie Forms, Mollie Forms 2026-09-27 8.5 High
Contributor SQL Injection in Mollie Forms <= 2.11.0 versions.
CVE-2026-94079 2 Wordpress-extensions, Wpusermanager 2 Wp User Manager, Wp User Manager 2026-09-27 5.3 Medium
Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions.
CVE-2026-95528 2 Magazine3, Wordpress-extensions 2 Core Web Vitals & Pagespeed Booster, Core Web Vitals& Pagespeed Booster 2026-09-27 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions.
CVE-2026-95530 2 Pixelyoursite, Wordpress-extensions 2 Pixelyoursite – Your Smart Pixel (tag) Manager, Pixelyoursite 2026-09-27 6.5 Medium
Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions.
CVE-2026-95592 2 Radiustheme, Wordpress-extensions 2 Team, Team 2026-09-27 5.3 Medium
Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.
CVE-2026-95600 2 Trustedlogin, Wordpress-extensions 2 Trustedlogin, Trustedlogin Connector 2026-09-27 5.3 Medium
Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions.
CVE-2026-95602 2 Wordpress-extensions, Yithemes 2 Yith Woocommerce Request A Quote, Yith Woocommerce Request A Quote 2026-09-27 6.5 Medium
Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Request A Quote: from n/a before 4.46.1.
CVE-2026-88367 1 Memononen 1 Nanosvg 2026-09-27 6.5 Medium
NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization. A specially crafted SVG document containing an extremely large stroke-width can cause floating-point rounding to produce a zero subdivision angle. The subsequent arc division yields infinity, which is converted to int without range validation, resulting in undefined behavior and process termination, leading to denial of service.
CVE-2026-88362 1 Ghostscript 1 Mujs 2026-09-27 7.5 High
MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c. A specially crafted JavaScript input containing an excessively large numeric array index can cause an out-of-range floating-point value to be converted to an integer without proper range validation. This results in undefined behavior and can cause process termination, leading to denial of service.
CVE-2026-88368 1 Memononen 1 Nanosvg 2026-09-27 7.5 High
NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in the rasterizer's nsvg__addActive() function. A specially crafted SVG document containing sufficiently large geometry coordinates can cause fixed-point-scaled edge coordinates to exceed the range representable by int. The rasterizer subsequently converts these values to int without range validation, resulting in undefined behavior and possible process termination, leading to denial of service.
CVE-2026-88369 1 Zserge 1 Jsmn 2026-09-27 7.3 High
zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example/jsondump.c dump().
CVE-2026-88370 1 Madmurphy 1 Libconfini 2026-09-27 5.3 Medium
libconfini 1.16.4 contains a heap out-of-bounds write condition involving the bundled load_ini_buffer.h utility and strip_ini_cache(). The bundled utility allocates exactly ini_length bytes, while strip_ini_cache() unconditionally writes a NUL terminator at ini_source[ini_length], requiring an additional writable byte. Applications using the bundled allocation pattern can trigger deterministic heap memory corruption when processing any non-empty INI input, resulting in denial of service.
CVE-2026-51994 1 Geelen 1 Mcp-remote 2026-09-27 9.1 Critical
mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header
CVE-2026-51995 1 Geelen 1 Mcp-remote 2026-09-27 7.5 High
An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src/lib/authorization-server-metadata.ts, src/lib/utils.ts components
CVE-2026-51997 1 Geelen 1 Mcp-remote 2026-09-27 8.8 High
An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functions
CVE-2026-88359 1 Pantoniou 1 Libfyaml 2026-09-27 6.5 Medium
libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containing a very large literal or folded block scalar, the function repeatedly grows an internal buffer using alloca() inside a loop. The allocated stack memory is not released until the function returns, causing cumulative stack growth that can exceed the process stack limit and result in SIGSEGV and denial of service.
CVE-2026-80513 1 Wordpress-extensions 1 Wpforo Forum 2026-09-27 7.5 High
The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a PHP Object. No POP chain is present in the wpForo Forum WordPress plugin before 3.1.6 itself; if one is present via another installed wpForo Forum WordPress plugin before 3.1.6 or , this could lead to remote code execution, arbitrary file operations, or SQL injection. This is an incomplete fix of CVE-2026-49769.