Export limit exceeded: 393256 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 393256 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 393256 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 393256 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 393256 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (393256 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-7514 | 1 Gitlab | 1 Gitlab | 2026-09-16 | 4.3 Medium |
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that an authenticated user with developer-role permissions could substitute package file content and hide packages from their owners due to improper authorization checks in the Generic Package Registry. | ||||
| CVE-2026-8030 | 1 Gitlab | 1 Gitlab | 2026-09-16 | 4.3 Medium |
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to prevent another user from modifying their group settings due to improper validation of group URL slugs during namespace transfers. | ||||
| CVE-2026-16794 | 1 Gitlab | 1 Gitlab | 2026-09-16 | 4.3 Medium |
| GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user with the Security Manager role to execute arbitrary CI/CD jobs and access protected variables within group projects due to improper authorization controls on compliance framework management. | ||||
| CVE-2026-19619 | 1 Gitlab | 1 Gitlab | 2026-09-16 | 4.7 Medium |
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in the context of a targeted user's session due to improper sanitization of pasted HTML content in the Content Editor. | ||||
| CVE-2026-78252 | 1 Gitlab | 1 Gitlab | 2026-09-16 | 8.2 High |
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user could have induced a targeted user to perform unintended state-changing HTTP requests due to improper sanitization of user-controlled data in the Markdown JSON table renderer. | ||||
| CVE-2026-79708 | 1 Gitlab | 1 Gitlab | 2026-09-16 | 8.5 High |
| GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions could have allowed an authenticated user with developer permissions to execute a policy test pipeline on projects within their group and access protected CI/CD variables restricted to higher-privileged roles, due to insufficient scope validation. | ||||
| CVE-2026-86475 | 2026-09-16 | 5.3 Medium | ||
| The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, allowing unauthenticated visitors to take slots that are already fully booked. | ||||
| CVE-2026-86701 | 2026-09-16 | N/A | ||
| Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its components. A malicious application installed on the user's Android device may exploit the affected component via an Intent, potentially allowing the malicious application to obtain sensitive information from the affected application. | ||||
| CVE-2026-92036 | 1 Mozilla | 1 Firefox | 2026-09-16 | N/A |
| Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | ||||
| CVE-2026-84906 | 2026-09-16 | 5.3 Medium | ||
| The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or which order it belongs to, allowing unauthenticated visitors to mark unpaid orders of any value as paid by replaying the transaction of a single genuine low-value payment. | ||||
| CVE-2026-19857 | 2026-09-16 | 4.8 Medium | ||
| The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token into a form's custom HTML, allowing unauthenticated visitors to have arbitrary shortcodes, with attacker-chosen attributes, executed server-side on any page displaying an affected form. | ||||
| CVE-2026-13407 | 2026-09-16 | 6.1 Medium | ||
| The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notification emails, allowing unauthenticated attackers to inject arbitrary HTML into emails sent to the site administrator on form submission. | ||||
| CVE-2026-71269 | 1 Nodered | 1 Node-red | 2026-09-16 | N/A |
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||||
| CVE-2026-77853 | 2026-09-16 | N/A | ||
| Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands. | ||||
| CVE-2026-92042 | 1 Mozilla | 1 Firefox | 2026-09-16 | N/A |
| Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | ||||
| CVE-2026-73447 | 2026-09-16 | 9.1 Critical | ||
| A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products to escalate privileges and execute arbitrary OS commands via a crafted Certz Rotate request. The Bootz service is also affected. | ||||
| CVE-2026-89328 | 2026-09-16 | N/A | ||
| The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. This allows any member of a board to carry out manager-only actions on it, including adding or removing members and enabling public access to a private board. | ||||
| CVE-2026-89327 | 2026-09-16 | N/A | ||
| The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user the comment is attributed to, allowing any board member to post comments that appear to be authored by another user, including administrators. | ||||
| CVE-2026-88910 | 2026-09-16 | N/A | ||
| The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthenticated attackers to permanently delete its uploaded media files and their database records by iterating identifiers. | ||||
| CVE-2026-87959 | 2026-09-16 | N/A | ||
| The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI provider settings, allowing users with subscriber-level access to overwrite those settings, including the API key used for the WPBot WordPress plugin before 8.7.6's outgoing AI requests. | ||||