Export limit exceeded: 10124 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (10124 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-62120 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Law Office <= 3.20 versions.
CVE-2026-62090 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in WineShop <= 3.20 versions.
CVE-2026-62087 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Equadio <= 1.1.4 versions.
CVE-2026-62086 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Juno <= 2.25 versions.
CVE-2026-62077 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Avala <= 1.1.4 versions.
CVE-2026-62076 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Kalles <= 1.1.7.1 versions.
CVE-2026-62054 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Yacht Rental <= 2.6 versions.
CVE-2026-62053 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Wine House <= 3.20 versions.
CVE-2026-62052 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Tipsy <= 1.6 versions.
CVE-2026-62051 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Stargaze <= 1.10 versions.
CVE-2026-62050 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Splendour <= 1.23 versions.
CVE-2026-42723 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in CleanSkin <= 1.5.0 versions.
CVE-2026-42718 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Booster for WooCommerce <= 8.4.0 versions.
CVE-2026-42716 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Payever - WooCommerce Gateway <= 4.8.2 versions.
CVE-2026-20321 1 Cisco 1 Application Policy Infrastructure Controller (apic) 2026-10-11 6.5 Medium
A vulnerability in the web-based management API for Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to execute arbitrary commands as the root user. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient input validation of user-controlled command arguments. An attacker could exploit this vulnerability by authenticating using the API and sending crafted input. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system of an affected device with root-level privileges.
CVE-2026-76465 1 Cisco 1 Nx-os Software 2026-10-11 9.8 Critical
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with&nbsp;root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validation when an affected device is processing an MPLS echo-request packet. An attacker could exploit this vulnerability by sending a crafted MPLS echo-request to an IP address on an affected device. A successful exploit could allow the attacker to execute arbitrary code with&nbsp;root privileges and could cause process crashes, which could result in a device reload and a DoS condition.
CVE-2026-82049 1 Python 1 Cpython 2026-10-11 7.1 High
In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.
CVE-2026-108592 2026-10-10 5.3 Medium
mini-swe-agent 1.10.0 through 2.4.6 contains an information exposure vulnerability in BubblewrapEnvironment because bwrap omits --clearenv, so sandboxed commands inherit the host environment. Attackers using prompt injection in processed task content can make the agent read API keys from the environment and exfiltrate them over the shared network.
CVE-2026-78401 1 Ibm 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more 2026-10-10 9.8 Critical
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
CVE-2026-104006 2026-10-10 3.7 Low
The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the 'comment_author_*, comment_author_email_*' parameter. This makes it possible for unauthenticated attackers to extract the full name and email address of returning commenters pre-filled into comment form input fields and persisted as the site-wide cached page by any unauthenticated attacker requesting the same public URL. The read-side handler in advanced-cache.php correctly skips cached delivery for requests carrying comment_author_* cookies, but this check is absent on the write path, meaning the cache poisoning is invisible to the victim commenter yet fully exploitable by any unauthenticated attacker with no cookies.