Export limit exceeded: 403086 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403086 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403086 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403086 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-15816 | 1 Redhat | 12 Enterprise Linux, Enterprise Linux Eus, Hardened Images and 9 more | 2026-10-08 | 7.5 High |
| A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling. | ||||
| CVE-2026-6893 | 1 Redhat | 13 Dracut, Enterprise Linux, Enterprise Linux Eus and 10 more | 2026-10-08 | 7.5 High |
| A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior. | ||||
| CVE-2026-107570 | 2026-10-08 | 2.5 Low | ||
| heap OOB write in convert_file_from_to() via a crafted Content-Type header allows attacker to OOB write when email is used as a template. | ||||
| CVE-2026-19083 | 2026-10-08 | 8.8 High | ||
| Authorization bypass through User-Controlled key vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. OctoCloud allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects OctoCloud: from 1.12.06 before 1.12.07. | ||||
| CVE-2026-71895 | 1 Apache | 1 Dolphinscheduler | 2026-10-08 | N/A |
| An authorization vulnerability in Apache DolphinScheduler allows authenticated non-admin users to retrieve Kubernetes configuration data intended for administrator-managed cluster configuration. The exposed kubeconfig data contains credentials that may allow users to authenticate directly to the Kubernetes API outside DolphinScheduler. The impact depends on the permissions granted to the disclosed credentials. If the kubeconfig provides cluster-admin or broadly privileged service-account access, an attacker may read Kubernetes Secrets, create pods, and establish persistent access to the cluster. This issue affects Apache DolphinScheduler: from 3.2.0 before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue. | ||||
| CVE-2026-103517 | 2026-10-08 | 5.3 Medium | ||
| The Airwallex Online Payments Gateway WordPress plugin before 1.36.0 does not verify that an incoming payment notification genuinely comes from the payment provider when no webhook secret has been configured, allowing unauthenticated attackers to forge one and mark orders as paid without paying. | ||||
| CVE-2026-104671 | 2026-10-08 | 5.3 Medium | ||
| The TutorStarter WordPress theme before 4.0.4 does not respect the site's user registration setting in one of its AJAX registration handlers, allowing unauthenticated visitors to create WordPress user accounts even when user registration is disabled. | ||||
| CVE-2026-105190 | 2026-10-08 | 5.3 Medium | ||
| The Easy Digital Downloads WordPress plugin before 3.7.1 does not consult the site's user registration setting before creating a WordPress account, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled. The created account receives the site's default role. | ||||
| CVE-2026-94275 | 2026-10-08 | 5.3 Medium | ||
| The Track Orders for WooCommerce WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing unauthenticated attackers to obtain a customer's name, email address, phone number, postal address and order history by supplying that customer's email address. | ||||
| CVE-2026-94258 | 2026-10-08 | 2.7 Low | ||
| The SMS Alert WordPress plugin before 4.0.1 does not check that the acting administrator is allowed to manage the selected users before returning their stored billing phone numbers, allowing an administrator of one site on a multisite network to disclose the phone numbers of users who belong to other sites on that network. This affects multisite only, and requires the SMS Alert WordPress plugin before 4.0.1's gateway credentials to be stored on the acting administrator's own site. | ||||
| CVE-2026-94246 | 2026-10-08 | 6.3 Medium | ||
| The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the wallet account named in a withdrawal submission belongs to the user making it, allowing any authenticated user, such as a subscriber, to file a withdrawal request against another user's wallet for an amount and a payout destination of their choosing, and to indefinitely prevent that user from submitting withdrawals of their own. | ||||
| CVE-2026-94245 | 2026-10-08 | 6.5 Medium | ||
| The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the user submitting a wallet transfer owns the wallet being debited, allowing any authenticated user, including one with only the Subscriber role, to move an arbitrary user's wallet balance, including an administrator's, into an account they control. | ||||
| CVE-2026-94244 | 2026-10-08 | 4.3 Medium | ||
| The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not perform any capability check, and relies on a token any authenticated user can obtain from a front-end page, before generating a report containing every customer's wallet transaction history, allowing any authenticated user, such as a subscriber, to disclose all users' names, email addresses, roles, transaction amounts, payment methods and dates. | ||||
| CVE-2026-93509 | 2026-10-08 | 6.5 Medium | ||
| The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not validate that a wallet transfer amount is positive, and computes the sender's new balance from a stale snapshot taken before crediting the recipient, allowing an authenticated attacker with Subscriber-level access to mint wallet funds for themselves or drain a specific victim's balance into their own account. | ||||
| CVE-2026-86828 | 2026-10-08 | 6.6 Medium | ||
| The BackWPup WordPress plugin before 5.7.7 does not properly restrict the destination path of files extracted during a backup restore when its fallback archive library is used, allowing high-privileged users to write files outside the intended restore directory, potentially leading to remote code execution. | ||||
| CVE-2026-86827 | 2026-10-08 | 5.3 Medium | ||
| The BackWPup WordPress plugin before 5.7.7 does not verify that a request to its cron-triggered backup execution handler actually originates from WordPress's internal scheduled-event dispatch, allowing unauthenticated attackers to force any existing backup job to run immediately, independent of its configured trigger type or schedule. | ||||
| CVE-2026-86826 | 2026-10-08 | 5.9 Medium | ||
| The BackWPup WordPress plugin before 5.7.7 does not properly restrict web access to the working directory it uses during backup restores, allowing unauthenticated attackers, on webservers that do not honour .htaccess rules such as NGINX, to download the full backup archive (database dump and site files, including credentials and secret keys) left behind by an interrupted restore. | ||||
| CVE-2026-105260 | 2026-10-08 | 4.3 Medium | ||
| The Database Addon For WPForms ( wpforms entries ) WordPress plugin before 1.1.1 does not verify the CSRF nonce when the field is omitted and performs no capability check of its own, allowing attackers to delete arbitrary stored form entries by tricking a logged-in administrator into loading a crafted page. | ||||
| CVE-2026-105198 | 2026-10-08 | 5.3 Medium | ||
| The Appointment Booking Plugin WordPress plugin before 5.7.3 does not verify that the caller owns the order referenced by an order-item identifier before rendering that order's confirmation summary, letting an unauthenticated visitor retrieve any customer's name, contact details and order confirmation code by supplying a sequential order-item id. | ||||
| CVE-2026-105197 | 2026-10-08 | 2.7 Low | ||
| The Appointment Booking Plugin WordPress plugin before 5.6.5 does not verify that a backend staff user is authorized to act on the specific record targeted for deletion, allowing an authenticated user with a record-scoped staff role to irreversibly delete any order, customer, or transaction on the site, including records belonging to other staff and outside their assigned scope. | ||||