Export limit exceeded: 401267 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 401267 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (401267 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-104118 2 Razorpay, Wordpress-extensions 2 Razorpay For Woocommerce, Razorpay For Woocommerce 2026-10-04 N/A
The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.
CVE-2026-104119 1 Wordpress-extensions 1 Simple Shopping Cart 2026-10-04 N/A
The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape some of its settings field values before outputting them on an admin settings page, allowing high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks, which is notably impactful on multisite installations where administrators do not have the unfiltered_html capability.
CVE-2026-86817 1 Wordpress-extensions 1 Five Star Business Profile And Schema 2026-10-04 N/A
The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and arbitrary site option values, in public output readable by unauthenticated visitors.
CVE-2026-93549 1 Wordpress-extensions 1 Cocart 2026-10-04 N/A
The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request forgery attack that creates a new administrator account using a logged-in administrator's session.
CVE-2026-97332 1 Wordpress-extensions 1 User Private Files 2026-10-04 N/A
The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticated users to retrieve other users' private files directly.
CVE-2026-103354 2 Stellarwp, Wordpress-extensions 2 Gutenberg Blocks By Kadence Blocks, Gutenberg Blocks By Kadence Blocks 2026-10-04 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Stored XSS.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.7.11.1.
CVE-2026-97276 2 Veronalabs, Wordpress-extensions 2 Wp Statistics, Wp Statistics 2026-10-04 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics wp-statistics allows Reflected XSS.This issue affects WP Statistics: from n/a through 14.16.14.
CVE-2026-103062 2 Cozmoslabs, Wordpress-extensions 2 Translatepress, Translatepress 2026-10-04 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Stored XSS.This issue affects TranslatePress: from n/a through 3.3.6.
CVE-2026-103344 2 Unlimited-elements, Wordpress-extensions 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor 2026-10-04 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
CVE-2026-103355 2 Unlimited-elements, Wordpress-extensions 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor 2026-10-04 9.3 Critical
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
CVE-2026-97307 2 Stylemixthemes, Wordpress-extensions 2 Cost Calculator Builder, Cost Calculator Builder 2026-10-04 7.5 High
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.
CVE-2026-104402 2 Farvisun, Wordpress-extensions 2 Mindio Magic Mcp, Mindio Magic Mcp 2026-10-04 4.3 Medium
Insertion of Sensitive Information Into Sent Data vulnerability in farvisun Mindio Magic MCP mindio-magic-mcp allows Retrieve Embedded Sensitive Data.This issue affects Mindio Magic MCP: from n/a through 0.5.6.
CVE-2026-105216 2 Micro, Micro-ecc Project 2 Go-micro, Micro-ecc 2026-10-04 7.4 High
go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials.
CVE-2026-105218 1 Go-pay 1 Gopay 2026-10-04 7.4 High
gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.
CVE-2026-75762 1 Redhat 1 Multicluster Globalhub 2026-10-04 6.8 Medium
No description is available for this CVE.
CVE-2026-80220 1 Postgres-exporter 1 Postgres-exporter 2026-10-04 5.4 Medium
No description is available for this CVE.
CVE-2026-76594 1 Advisor-backend 1 Advisor-backend 2026-10-04 8.1 High
A flaw was found in advisor-backend. A network-adjacent unauthenticated attacker could exploit a vulnerability in the `/private/import_content/` endpoint, which lacks proper authentication and permission checks. This allows the attacker to overwrite the global Advisor rule, resolution, and playbook catalogue. When combined with another vulnerability involving unsafe YAML deserialization, this could lead to arbitrary code execution on affected systems.
CVE-2026-76595 1 Advisor-backend 1 Advisor-backend 2026-10-04 N/A
A flaw was found in advisor-backend. Multiple code paths within the application deserialize YAML (YAML Ain't Markup Language) with an unsafe full Loader, which can instantiate arbitrary Python objects via YAML tags. An unauthenticated remote attacker can exploit this by submitting specially crafted YAML input, leading to remote code execution (RCE) within the `advisor-backend` pod. This compromise could allow access to shared database credentials and impact all tenants.
CVE-2026-87052 1 Operator-foundry 1 Operator-foundry 2026-10-04 2.6 Low
A flaw was found in operator-foundry. The absence of automated dependency-update and vulnerability-scanning configurations in the repository increases the risk of undetected security vulnerabilities. This lack of automated security checks could potentially lead to the inclusion of known vulnerable components, which might then be exploited by an attacker if those underlying vulnerabilities are present and exploitable.
CVE-2026-87054 1 Operator-sdk-builder 1 Operator-sdk-builder 2026-10-04 4.2 Medium
A flaw was found in operator-sdk-builder. The containers-policy.json configuration file defaults to insecureAcceptAnything for container image registries that are not explicitly listed. This default setting causes signature verification to be entirely skipped for images pulled from these unlisted registries, which could allow for the use of untrusted or malicious container images.