Search

Search Results (404370 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-42696 2026-10-10 10 Critical
Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1.5.19 versions.
CVE-2026-42633 2026-10-10 8.5 High
Subscriber SQL Injection in Events Manager <= 7.4.6 versions.
CVE-2026-42630 2026-10-10 7.5 High
Unauthenticated Sensitive Data Exposure in Web Plura Backup &amp; Restore Manager <= 0.2.25 versions.
CVE-2026-42419 2026-10-10 5.9 Medium
Unauthenticated Sensitive Data Exposure in Swish Migrate and Backup <= 1.4.0 versions.
CVE-2026-40808 2026-10-10 6.5 Medium
Subscriber Broken Access Control in Jetpack VideoPress <= 3.6 versions.
CVE-2026-40803 2026-10-10 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Jotform &#8211; AI Chatbot <= 3.8.2 versions.
CVE-2026-40802 2026-10-10 7.6 High
Subscriber Settings Change in Pubjet | پاب‌جت <= 5.4.8 versions.
CVE-2026-40801 2026-10-10 8.1 High
Subscriber Broken Access Control in Wordable <= 8.2.10 versions.
CVE-2026-40800 2026-10-10 9.3 Critical
Subscriber SQL Injection in ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes <= 1.5.3 versions.
CVE-2026-40777 2026-10-10 8.1 High
Subscriber Broken Access Control in WPSection <= 1.5.1 versions.
CVE-2026-39802 2026-10-10 8.1 High
Unauthenticated Remote Code Execution (RCE) in Everest Backup <= 2.3.13 versions.
CVE-2026-39801 2026-10-10 9.8 Critical
Subscriber Privilege Escalation in AIWU <= 1.5.9 versions.
CVE-2026-39800 2026-10-10 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Additional Order Filters for WooCommerce <= 1.24 versions.
CVE-2026-108593 1 Decolua 1 9router 2026-10-10 6.4 Medium
9router 0.4.1 through 0.5.99 contains a configuration injection vulnerability in the POST /api/cli-tools/hermes-settings endpoint that allows authenticated dashboard users to inject arbitrary keys into the Hermes Agent config.yaml file. Attackers can submit a baseUrl containing double quotes and newlines to add hooks_auto_accept and a hooks.post_llm_call shell command, which Hermes Agent executes without approval after an LLM call.
CVE-2026-108596 1 Openlit 1 Openlit 2026-10-10 5.3 Medium
OpenLIT 2.1.0 contains an authorization bypass vulnerability that allows authenticated users to read other projects' telemetry by supplying a forged x-openlit-project-id header. Attackers who know a victim project id and database config id can query the trace read API to obtain traces including LLM prompts and completions.
CVE-2026-94590 2026-10-10 6.5 Medium
Improper Verification of Source of a Communication Channel vulnerability in CodePeople2 Sell Downloads sell-downloads allows Exploitation of Trusted Credentials.This issue affects Sell Downloads: from n/a through 1.2.3.
CVE-2026-108594 1 Mealie 1 Mealie 2026-10-10 3.5 Low
Mealie 3.26.0 through 3.28.0 contains a server-side request forgery vulnerability in the OpenID Connect avatar fetch that ignores ports when allowlisting the identity provider hostname. Authenticated OIDC users who control their picture URL can make the server send GET requests to arbitrary ports on the provider's internal address on each login.
CVE-2026-108592 2026-10-10 5.3 Medium
mini-swe-agent 1.10.0 through 2.4.6 contains an information exposure vulnerability in BubblewrapEnvironment because bwrap omits --clearenv, so sandboxed commands inherit the host environment. Attackers using prompt injection in processed task content can make the agent read API keys from the environment and exfiltrate them over the shared network.
CVE-2026-106610 2026-10-10 9.8 Critical
Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through 5.5.7.
CVE-2026-96341 2026-10-10 8.2 High
Incorrect Privilege Assignment vulnerability in WPMU DEV Forminator forminator allows Privilege Escalation.This issue affects Forminator: from n/a through 1.57.3.