Export limit exceeded: 404306 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404306 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-81154 | 2026-10-11 | N/A | ||
| The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape image alt text before outputting it in one of its gallery layouts, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected gallery, including administrators. | ||||
| CVE-2026-14854 | 2026-10-11 | N/A | ||
| The WooCommerce Bookings WordPress plugin before 3.11.0 does not limit a user-supplied value before using it to allocate memory in one of its unauthenticated AJAX actions, allowing unauthenticated attackers to exhaust server memory and cause a Denial of Service with a single request. | ||||
| CVE-2026-107694 | 2026-10-11 | N/A | ||
| The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.2.0 does not verify that the vendor a commission calculation is requested for is the requesting vendor, allowing vendors to disclose the commission rate and fixed fee the marketplace administrator configured for other vendors. | ||||
| CVE-2026-107507 | 2026-10-11 | N/A | ||
| The Squadeno WordPress plugin before 1.12.0 does not enforce its restrictions on every way a sport can be saved, allowing users with the lowest-tier Trainer role to change the section, age group, author, password, comment settings and date of a sport they are assigned to. | ||||
| CVE-2026-106029 | 2026-10-11 | N/A | ||
| The WeddingCity Lite WordPress plugin through 1.0.4 does not perform any authorisation or validity checks before deleting posts, pages and media attachments, allowing unauthenticated attackers to permanently delete arbitrary content site-wide. | ||||
| CVE-2026-104684 | 2026-10-11 | N/A | ||
| The Envira Gallery WordPress plugin before 1.16.2 does not verify that a user is authorized to read a gallery before rendering it, allowing authors to embed and expose other users' non-public gallery metadata to unauthenticated visitors. | ||||
| CVE-2026-104681 | 2026-10-11 | N/A | ||
| The Envira Gallery WordPress plugin before 1.16.2 does not verify that an image identifier added to a gallery refers to a media attachment the caller is permitted to view, allowing any user able to create and edit a gallery (Author and above by default) to disclose the title and excerpt of other users' private, draft, pending and trashed posts that WordPress would otherwise withhold from them. | ||||
| CVE-2026-104680 | 2026-10-11 | N/A | ||
| The Envira Gallery WordPress plugin before 1.16.2 does not verify that a user holds the capability WordPress reserves for installing Envira Gallery WordPress plugin before 1.16.2 code before processing its setup-wizard Envira Gallery WordPress plugin before 1.16.2-installation request, and does not restrict the installation to its own curated list, allowing a Multisite subsite Administrator to install an arbitrary WordPress.org-published Envira Gallery WordPress plugin before 1.16.2 into the network-shared Envira Gallery WordPress plugin before 1.16.2 directory, a privilege Multisite reserves for the network Super Admin. | ||||
| CVE-2026-104028 | 2026-10-11 | N/A | ||
| The Anton Extensions WordPress plugin through 1.2.2 does not perform any capability check, nonce verification, or file-type validation before writing attacker-supplied content to an attacker-chosen path, allowing unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution. | ||||
| CVE-2026-103695 | 2026-10-11 | N/A | ||
| The Mobile builder WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-103694 | 2026-10-11 | N/A | ||
| The Mobile builder WordPress plugin through 1.4.2 does not properly restrict which user meta keys a logged-in user can update through one of its REST routes, allowing any user with a self-registered account, such as a customer, to grant themselves the administrator role. | ||||
| CVE-2026-103305 | 2026-10-11 | N/A | ||
| The Prenotazioni WordPress plugin through 1.7.5 does not have authorisation and CSRF checks when saving its settings, and does not escape some of them when outputting them, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators and site visitors. | ||||
| CVE-2026-94235 | 2026-10-11 | N/A | ||
| The MemberHero WordPress plugin through 6.9 does not perform any capability or nonce check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to make the site send arbitrary HTML emails to arbitrary recipients from its own mail system, which can be abused to relay phishing carrying the site's identity and domain reputation. | ||||
| CVE-2026-12980 | 2026-10-11 | N/A | ||
| The Post Snippets WordPress plugin through 4.2.4 does not properly escape variable values substituted into snippets before outputting them, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the content is viewed. | ||||
| CVE-2026-108630 | 1 Jeecg | 2 Jeecg-boot, Jeecg Boot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in SysDepartPermissionController that allows any authenticated user to modify department permission records by calling the edit endpoint. Low-privileged attackers can obtain row ids from the unguarded list endpoint and overwrite depart_id, permission_id and data_rule_ids to alter which menus and data rules departments may delegate. | ||||
| CVE-2026-108639 | 2 Jeecg, Jeecgboot | 3 Jeecg-boot, Jeecg Boot, Jeecgboot | 2026-10-11 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to permanently delete data dictionaries via the deletePhysic handler of SysDictController. Low-privileged attackers can send DELETE requests to /sys/dict/deletePhysic/{id} to irreversibly remove active dictionaries and all their items, bypassing the recycle bin. | ||||
| CVE-2026-108678 | 1 Jeecg | 2 Jeecg-boot, Jeecg Boot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryUserRoles handler of SystemApiController that lets authenticated users read any user's role codes. Low-privileged attackers can send GET requests to /sys/api/queryUserRoles with an arbitrary username to enumerate role assignments and identify administrator accounts. | ||||
| CVE-2026-98260 | 1 Linux | 1 Linux Kernel | 2026-10-11 | 7.8 High |
| In the Linux kernel, the following vulnerability has been resolved: exec: Cleanup POSIX timers right after de_thread() A per-thread CPU timer holds a reference to the PID of the thread it is attached to and, while it is armed, its node is queued in that thread's posix_cputimers. The task is looked up by that PID. When a non-leader thread exec()s, de_thread() changes which task owns that PID. pid_task(timer->it.cpu.pid, PIDTYPE_PID) then returns NULL, but the node is still queued on tsk, which is alive. timer_lock_sighand() takes a failed lookup to mean that the node is already dequeued, so it has nothing to undo. begin_new_exec() calls posix_cpu_timers_exit(me) right after exec_task_namespaces() and that removes the leftover node, so the state normally stays invisible. But bprm->point_of_no_return is set before de_thread(), so if unshare_files(), set_mm_exe_file(), exec_mmap() or exec_task_namespaces() fails, the task dies before it gets there. exit_itimers() then frees the k_itimer while its node is still queued, and reaping tsk later erases that freed node from the rbtree. In short: the non-leader thread B the parent timer_create(CLOCK_THREAD_CPUTIME_ID) timer_settime() arm_timer() // the node is queued on B execve() de_thread(B) exchange_tids(B, leader) // B's PID now belongs to the leader release_task(leader) __exit_signal(leader) posix_cpu_timers_exit(leader) // cleans leader's queue, not B's __unhash_process(leader) // that PID has no task anymore exec_mmap() mmap_read_lock_killable(old_mm) kill(B, SIGKILL) // -EINTR get_signal() do_exit() exit_itimers() posix_timer_delete() posix_cpu_timer_del() posix_timer_unhash_and_free() // freed while still queued wait4() release_task(B) posix_cpu_timers_exit(B) cleanup_timerqueue() timerqueue_del() // use-after-free Move the POSIX timer cleanup right after de_thread() before any of the later failure conditions brings the task into do_exit(). [ tglx: Move the cleanup right after de_thread() ] | ||||
| CVE-2026-108627 | 1 Jeecg | 2 Jeecg-boot, Jeecg Boot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the loadDatarule handler of SysRoleController that lets any authenticated user query role data rules. Low-privileged attackers can request GET /sys/role/datarule/{permissionId}/{roleId} to read rule names, columns, conditions, values and bound rule ids for any role. | ||||
| CVE-2026-98281 | 1 Linux | 1 Linux Kernel | 2026-10-11 | 7.8 High |
| In the Linux kernel, the following vulnerability has been resolved: futex: Also allocate private hash on vfork() As Jann demonstrated, it is entirely feasible to access the mm through vfork(). Therefore we need to allocate a private hash on vfork() as well as any other CLONE_VM user. Specifically, it must be avoided to have (private) futex waiters before allocating the private hash. | ||||