Export limit exceeded: 389454 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 389454 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (389454 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-85640 | 1 Zohocorp | 1 Manageengine Endpoint Central | 2026-09-07 | 6.3 Medium |
| Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component | ||||
| CVE-2026-77699 | 1 Zohocorp | 1 Manageengine Endpoint Central | 2026-09-07 | 5 Medium |
| Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path. | ||||
| CVE-2026-77698 | 1 Zohocorp | 1 Manageengine Endpoint Central | 2026-09-07 | 5.7 Medium |
| Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade. | ||||
| CVE-2026-86294 | 1 Sourcecodester | 1 Simple Traffic Offense System | 2026-09-07 | 4.3 Medium |
| A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the argument site_name/site_desc leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2026-86289 | 1 Ollama | 1 Ollama | 2026-09-07 | 4.3 Medium |
| A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a manipulation results in integer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 0.31.2-rc1 is capable of addressing this issue. The patch is named 67b6a1c2d45321e0cb3c04a18073f9818de7724b. It is recommended to upgrade the affected component. | ||||
| CVE-2025-15489 | 2 Passster Project, Wordpress | 2 Passster, Wordpress | 2026-09-07 | 5.3 Medium |
| The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content | ||||
| CVE-2026-84849 | 2 Brightplugins, Wordpress | 2 Pre-orders For Woocommerce, Wordpress | 2026-09-07 | 6.5 Medium |
| Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions. | ||||
| CVE-2026-81773 | 2 Saturdaydrive, Wordpress | 2 Ninja Forms - File Uploads, Wordpress | 2026-09-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | ||||
| CVE-2026-84753 | 2 Getwpfunnels, Wordpress | 2 Mail Mint, Wordpress | 2026-09-07 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. | ||||
| CVE-2026-84754 | 2 Getwpfunnels, Wordpress | 2 Wpfunnels, Wordpress | 2026-09-07 | 6.5 Medium |
| Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions. | ||||
| CVE-2026-84755 | 2 Getwpfunnels, Wordpress | 2 Mail Mint, Wordpress | 2026-09-07 | 6.5 Medium |
| Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions. | ||||
| CVE-2026-84758 | 2 Strategy11team, Wordpress | 2 Business Directory Plugin, Wordpress | 2026-09-07 | 6.5 Medium |
| Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions. | ||||
| CVE-2026-84766 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluent Booking | 2026-09-07 | 5.9 Medium |
| Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions. | ||||
| CVE-2026-84812 | 2 Wordplus, Wordpress | 2 Better Messages, Wordpress | 2026-09-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions. | ||||
| CVE-2026-85303 | 2 Magepeople, Wordpress | 2 Booking & Rental Manager, Wordpress | 2026-09-07 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking and Rental Manager: from n/a through 2.7.7. | ||||
| CVE-2026-75160 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-07 | 9.1 Critical |
| An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi. | ||||
| CVE-2026-75162 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-07 | N/A |
| An information disclosure vulnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows any remote authenticated user, including users with the low-privileged Standard role, to retrieve the configured OPC-UA authentication credentials in cleartext via the JSON API response. | ||||
| CVE-2026-79419 | 1 Emxtecnologia | 1 Gestao X Business Suite | 2026-09-07 | N/A |
| A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao/Imagens.aspx endpoint, allowing an authenticated attacker to inject arbitrary JavaScript code that is reflected and executed in the context of a victim's browser. | ||||
| CVE-2026-31020 | 1 Arc53 | 1 Docsgpt | 2026-09-07 | 9.8 Critical |
| In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without input sanitization or sandboxing. An unauthenticated attacker can inject malicious template expressions, leading to a server-side template injection (SSTI) vulnerability that can be exploited to achieve full remote code execution (RCE). | ||||
| CVE-2026-75430 | 1 Powerjob | 1 Powerjob | 2026-09-07 | 9.8 Critical |
| PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code. | ||||