Export limit exceeded: 404132 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404132 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-42702 | 2026-10-10 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Tutor LMS <= 4.1.0 versions. | ||||
| CVE-2026-42699 | 2026-10-10 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in FV Player 8 <= 8.1.8 versions. | ||||
| CVE-2026-42697 | 2026-10-10 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Social Share Icons & Social Share Buttons <= 3.7.5 versions. | ||||
| CVE-2026-42696 | 2026-10-10 | 10 Critical | ||
| Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration & Cloning <= 1.5.19 versions. | ||||
| CVE-2026-42633 | 2026-10-10 | 8.5 High | ||
| Subscriber SQL Injection in Events Manager <= 7.4.6 versions. | ||||
| CVE-2026-42630 | 2026-10-10 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in Web Plura Backup & Restore Manager <= 0.2.25 versions. | ||||
| CVE-2026-42419 | 2026-10-10 | 5.9 Medium | ||
| Unauthenticated Sensitive Data Exposure in Swish Migrate and Backup <= 1.4.0 versions. | ||||
| CVE-2026-40808 | 2026-10-10 | 6.5 Medium | ||
| Subscriber Broken Access Control in Jetpack VideoPress <= 3.6 versions. | ||||
| CVE-2026-40803 | 2026-10-10 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Jotform – AI Chatbot <= 3.8.2 versions. | ||||
| CVE-2026-40802 | 2026-10-10 | 7.6 High | ||
| Subscriber Settings Change in Pubjet | پابجت <= 5.4.8 versions. | ||||
| CVE-2026-40801 | 2026-10-10 | 8.1 High | ||
| Subscriber Broken Access Control in Wordable <= 8.2.10 versions. | ||||
| CVE-2026-40800 | 2026-10-10 | 9.3 Critical | ||
| Subscriber SQL Injection in ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes <= 1.5.3 versions. | ||||
| CVE-2026-40777 | 2026-10-10 | 8.1 High | ||
| Subscriber Broken Access Control in WPSection <= 1.5.1 versions. | ||||
| CVE-2026-39802 | 2026-10-10 | 8.1 High | ||
| Unauthenticated Remote Code Execution (RCE) in Everest Backup <= 2.3.13 versions. | ||||
| CVE-2026-39801 | 2026-10-10 | 9.8 Critical | ||
| Subscriber Privilege Escalation in AIWU <= 1.5.9 versions. | ||||
| CVE-2026-39800 | 2026-10-10 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Additional Order Filters for WooCommerce <= 1.24 versions. | ||||
| CVE-2026-108593 | 1 Decolua | 1 9router | 2026-10-10 | 6.4 Medium |
| 9router 0.4.1 through 0.5.99 contains a configuration injection vulnerability in the POST /api/cli-tools/hermes-settings endpoint that allows authenticated dashboard users to inject arbitrary keys into the Hermes Agent config.yaml file. Attackers can submit a baseUrl containing double quotes and newlines to add hooks_auto_accept and a hooks.post_llm_call shell command, which Hermes Agent executes without approval after an LLM call. | ||||
| CVE-2026-108600 | 2026-10-10 | 4.7 Medium | ||
| open-multi-agent (@open-multi-agent/core) 1.5.0 through 1.21.2 contains a link following vulnerability in the file_write tool sandbox that allows attackers to create files outside the workspace root by using dangling symlinks. Attackers can plant a dangling symlink in the workspace and steer the agent via prompt injection to write attacker-influenced content anywhere the agent process can write. | ||||
| CVE-2026-108599 | 2026-10-10 | 4.7 Medium | ||
| phi 0.1.1 through 0.28.4 contains an improper link resolution vulnerability that allows malicious repositories to bypass workspace_only_writes by exploiting lexical-only path checks in the permission gate. Attackers can commit symlinks pointing outside the workspace and use prompt injection to make the write tool write attacker-influenced content to external files without approval. | ||||
| CVE-2026-108598 | 2026-10-10 | 9.8 Critical | ||
| Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM. | ||||