Export limit exceeded: 91325 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (91325 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-97300 | 2 Arraytics, Wordpress-extensions | 2 Wp Event Solution, Wp Event Solution | 2026-10-09 | 6.5 Medium |
| Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions. | ||||
| CVE-2026-75962 | 2 Saadiqbal, Wordpress-extensions | 2 Post Smtp, Post Smtp | 2026-10-09 | 7.2 High |
| The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable without authentication on WordPress Multisite installations with public registration enabled, as WordPress accepts email addresses containing numeric HTML character references that Post SMTP's stricter validator rejects, persisting the attacker-controlled address verbatim to the email log via the failed-send exception message. | ||||
| CVE-2026-82924 | 1 Pusula Communication | 1 Expert Mail | 2026-10-09 | 5.3 Medium |
| Improper Control of Interaction Frequency vulnerability in Pusula Communication, IT, and Internet Industry and Trade Co. Ltd. Expert Mail allows Brute Force. This issue affects Expert Mail: through 2026-09-18. | ||||
| CVE-2026-105841 | 2 Lrzsz Project, Uwe Ohse | 2 Lrzsz, Lrzsz | 2026-10-09 | 7.5 High |
| lrzsz before 0.13.0 contains an OS command injection vulnerability in the lrz receive utility's pipe mode that allows remote senders to execute commands by supplying crafted filenames. When lrz runs under a suffixed name such as lrztar, procheader() in src/lrz.c passes the unescaped ZMODEM/YMODEM filename to popen(), so shell metacharacters execute as the receiving user. | ||||
| CVE-2026-91140 | 1 Progress Software | 1 Autonomous Rest Connector Genai Agents | 2026-10-09 | 9.6 Critical |
| An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator. | ||||
| CVE-2026-85523 | 1 Felisify Information Technologies Industry And Trade | 1 Sambabox | 2026-10-09 | 8.8 High |
| Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Felisify Information Technologies Industry and Trade Inc. SambaBox allows OS Command Injection. This issue affects SambaBox: before 5.4.1. | ||||
| CVE-2025-8352 | 1 Eset | 1 Eset Protect | 2026-10-09 | N/A |
| Allocation of resources without limits or throttling vulnerability in ESET PROTECT On-Prem increased resource consumption (CPU and RAM), leading to conditions for a Denial-of-Service attack. | ||||
| CVE-2026-105848 | 1 Payloadcms | 2 Payload, Plugin-stripe | 2026-10-09 | N/A |
| Payload is a free and open source headless content management system. In @payloadcms/plugin-stripe versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can reach the enabled optional Stripe REST proxy can perform unintended Stripe operations. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34. | ||||
| CVE-2026-106103 | 1 Quasarframework | 2 Icongenie, Quasar | 2026-10-09 | 7.1 High |
| Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/icongenie 6.1.1, the icongenie generate --profile command accepted folder and name values from a user-supplied profile without constraining the resolved destination to the Quasar project directory. icongenie/lib/utils/get-assets-files.js joined those values with appDir, while icongenie/lib/utils/validate-profile-object.js required only non-empty strings, allowing parent-directory traversal. A developer who runs a crafted profile can cause generated image content to be written or overwritten at any path writable by that user, potentially modifying shell startup files, build scripts, or other executable configuration. This issue is fixed in version 6.1.1. | ||||
| CVE-2026-106105 | 1 Quasarframework | 4 App-vite, Cli, Quasar and 1 more | 2026-10-09 | N/A |
| Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/ssl-certificate 2.1.0, @quasar/cli 5.0.4, and @quasar/app-vite 3.3.0, the @quasar/ssl-certificate utility cached a combined private key and certificate PEM without explicitly applying owner-only filesystem permissions. Another local user able to read the cache can copy the key and impersonate a development TLS endpoint in an environment that trusts the certificate. The generated certificate was also CA-capable, carried unnecessarily broad key usages, and encoded the IPv6 loopback address as a DNS subject alternative name. This issue is fixed in @quasar/ssl-certificate 2.1.0, @quasar/cli 5.0.4, and @quasar/app-vite 3.3.0. | ||||
| CVE-2026-106106 | 1 Quasarframework | 3 App-vite, Quasar, Render-ssr-error | 2026-10-09 | N/A |
| Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/render-ssr-error 2.2.4 and @quasar/app-vite 3.3.0, renderSSRError() in utils/render-ssr-error/src/index.js used diagnostic data from utils/render-ssr-error/src/env.js to serialize process.env, request headers, and cookies into the HTTP page returned by serve.devError(), while the development server listened on all interfaces by default. Any network-adjacent client that reaches an SSR or SSG render failure through this development-only error path can obtain shell environment secrets. The renderer escaped only one exact lowercase script closing-tag spelling, so case variants and valid closing-tag delimiter variants in reflected diagnostic data could terminate the script element and inject markup; executing the injected code in a developer browser additionally requires the payload to accompany that developer's request. This issue is fixed in @quasar/render-ssr-error 2.2.4 and @quasar/app-vite 3.3.0. | ||||
| CVE-2026-106107 | 1 Quasarframework | 2 App-vite, Quasar | 2026-10-09 | N/A |
| Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 3.3.0, several @quasar/app-vite SSR and SSG rendering paths interpolated ssrContext.nonce directly into quoted HTML attributes. An application that derives or overrides this value with attacker-controlled data can allow a quote to terminate the nonce attribute and inject additional attributes or markup into generated HTML across development and production SSR or SSG output. Cryptographically generated base64 or base64url nonces are not affected because they lack HTML attribute delimiters. This issue is fixed in version 3.3.0. | ||||
| CVE-2026-106109 | 1 Quasarframework | 2 App-vite, Quasar | 2026-10-09 | N/A |
| Quasar Framework is a framework for building high-performance Vue.js user interfaces. From 1.0.0 until 3.3.0, @quasar/app-vite recursively removed the resolved build.distDir before building without rejecting the project root, user home directory, filesystem roots, or symlink-resolved external directories. An unsafe trusted configuration can delete data writable by the build user before compilation begins. No attacker-controlled input reaches build.distDir by default, so exploitation requires compromised or less-trusted automation to influence build configuration, or a developer to run a mistaken configuration. This issue is fixed in version 3.3.0. | ||||
| CVE-2026-101207 | 1 Dell | 1 Openmanage Integration | 2026-10-09 | 8.8 High |
| Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | ||||
| CVE-2026-102158 | 1 Arista | 1 Cloudvision Cue | 2026-10-09 | 6.5 Medium |
| Improper validation of selected CloudVision CUE application programming interface (API) request parameters may allow an authenticated network user to perform SQL injection against the backend impacting its availability. | ||||
| CVE-2026-102160 | 1 Arista | 1 Cloudvision Cue | 2026-10-09 | 7.2 High |
| An operating system (OS) command injection vulnerability in CloudVision CUE backup management may allow an authenticated Super User to submit a crafted backup request and execute arbitrary commands with the privileges of the affected service. | ||||
| CVE-2026-102161 | 1 Arista | 1 Cloudvision Cue | 2026-10-09 | 8.8 High |
| An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges on the CV-CUE backend. | ||||
| CVE-2026-102156 | 1 Arista | 1 Cloudvision Cue | 2026-10-09 | 6.8 Medium |
| Improper neutralization of Lightweight Directory Access Protocol (LDAP) authentication input may allow an unauthenticated network attacker, under high-complexity conditions, to inject queries against the configured directory service. | ||||
| CVE-2026-101156 | 1 Arista | 1 Cloudvision Cue | 2026-10-09 | 8.4 High |
| A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege administrator to store malicious content in a configuration. The content may execute in another authenticated user's browser when that user views or compares the affected configuration. Successful exploitation may allow the attacker to act through the victim's authenticated browser session to access sensitive data, modify configurations, or disrupt managed wireless services. | ||||
| CVE-2026-101157 | 1 Arista | 1 Cloudvision Cue | 2026-10-09 | 8.7 High |
| A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that executes when an authenticated user views affected content. Successful exploitation may allow the attacker to compromise the victim's authenticated browser session, access sensitive data, modify system state, or disrupt affected services. | ||||