Export limit exceeded: 399884 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399884 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-96351 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions. | ||||
| CVE-2026-96350 | 2026-09-30 | 9.8 Critical | ||
| Subscriber Privilege Escalation in Estatik <= 4.3.5 versions. | ||||
| CVE-2026-96349 | 2026-09-30 | 10 Critical | ||
| Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions. | ||||
| CVE-2026-96348 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in Bookly <= 28.2 versions. | ||||
| CVE-2026-96347 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions. | ||||
| CVE-2026-96346 | 2026-09-30 | 7.6 High | ||
| Author SQL Injection in WP ERP <= 1.17.9 versions. | ||||
| CVE-2026-96345 | 2026-09-30 | 7.6 High | ||
| Administrator SQL Injection in Estatik <= 4.3.5 versions. | ||||
| CVE-2026-96344 | 2026-09-30 | 7.2 High | ||
| Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions. | ||||
| CVE-2026-96343 | 2026-09-30 | 7.2 High | ||
| Custom role PHP Object Injection in WP ERP <= 1.17.9 versions. | ||||
| CVE-2026-96338 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions. | ||||
| CVE-2026-95616 | 2026-09-30 | 7.5 High | ||
| An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. | ||||
| CVE-2026-95587 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions. | ||||
| CVE-2026-95531 | 2026-09-30 | 8.8 High | ||
| Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions. | ||||
| CVE-2026-94683 | 2026-09-30 | 8.8 High | ||
| Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions. | ||||
| CVE-2026-94681 | 2026-09-30 | 5.9 Medium | ||
| Unauthenticated Denial of Service Attack in WP Store Locator < 3.0.0 versions. | ||||
| CVE-2026-94678 | 2026-09-30 | 8.8 High | ||
| Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions. | ||||
| CVE-2026-94677 | 2026-09-30 | 7.2 High | ||
| Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions. | ||||
| CVE-2026-94674 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Pixel Manager for WooCommerce <= 1.69.0 versions. | ||||
| CVE-2026-94673 | 2026-09-30 | 5.3 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions. | ||||
| CVE-2026-94672 | 2026-09-30 | 4.3 Medium | ||
| Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions. | ||||