Export limit exceeded: 387293 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 387293 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 387293 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 387293 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 387293 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 387293 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 387293 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (387293 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-78254 | 2026-09-07 | N/A | ||
| The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18. In order to exploit this vulnerability, the server would either have to be malicious or be subject to a machine-in-the-middle attack. Additionally in the case of scp or the ftp task using ftps the server must pass the server identity checks performed by the tasks. For ftp tasks not using ftps a malicious server could act as a machine-in-the-middle to provide malicious files. Starting with Ant 1.10.18 both tasks will prevent writing outside of the destination directory by default. An option is available to disable this behavior in the unlikely case that the old behavior is required by existing build files. Mitigations: Users of scp and ftp (when using ftps) in any version of Ant should not bypass server identity checks. Users of ftp not using ftps should switch to ftps where possible. All users are recommended to upgrade to Apache Ant 1.10.18, which fixes this issue. | ||||
| CVE-2026-86291 | 1 Itsourcecode | 1 Sales And Inventory System | 2026-09-07 | 6.3 Medium |
| A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/us_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. | ||||
| CVE-2026-86290 | 1 Sourcecodester | 1 Online Voting System | 2026-09-07 | 7.3 High |
| A weakness has been identified in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation of the argument Category causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. | ||||
| CVE-2026-86289 | 1 Ollama | 1 Ollama | 2026-09-07 | 4.3 Medium |
| A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a manipulation results in integer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 0.31.2-rc1 is capable of addressing this issue. The patch is named 67b6a1c2d45321e0cb3c04a18073f9818de7724b. It is recommended to upgrade the affected component. | ||||
| CVE-2026-84186 | 1 Prestashop | 1 Prestashop | 2026-09-07 | N/A |
| Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarded-For header when the application is running behind a reverse proxy, load balancer or CDN. The application incorrectly processes the IP address string and uses the address controlled by the visitor rather than the one provided by the trusted infrastructure, allowing an unauthenticated remote attacker to cause the application to interpret their connection as originating from an arbitrary IP address. This condition allows IP-based controls, such as the maintenance mode allowlist, to be bypassed, as well as enabling the forgery of security and audit logs and the evasion of third-party mechanisms that rely on the IP address, such as geolocation checks, fraud detection or request throttling. | ||||
| CVE-2026-86288 | 1 Modelcloud | 1 Gptqmodel | 2026-09-07 | 6.3 Medium |
| A vulnerability has been found in ModelCloud GPTQModel up to 7.2.0. This vulnerability affects unknown code of the file gptqmodel/nn_modules/qlinear/tritonv2.py of the component Triton dequantization kernel. Such manipulation of the argument g_idx leads to out-of-bounds read. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.3.0 is able to resolve this issue. The name of the patch is 877c732f7d7dccd56a729844c6a5bd20f3aa8bb1. Upgrading the affected component is recommended. | ||||
| CVE-2026-78221 | 1 Openvpn | 1 Openvpn | 2026-09-07 | N/A |
| An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs. | ||||
| CVE-2025-15489 | 2 Passster Project, Wordpress | 2 Passster, Wordpress | 2026-09-07 | 5.3 Medium |
| The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content | ||||
| CVE-2026-84849 | 2 Brightplugins, Wordpress | 2 Pre-orders For Woocommerce, Wordpress | 2026-09-07 | 6.5 Medium |
| Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions. | ||||
| CVE-2026-81773 | 2 Saturdaydrive, Wordpress | 2 Ninja Forms - File Uploads, Wordpress | 2026-09-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | ||||
| CVE-2026-84753 | 2 Getwpfunnels, Wordpress | 2 Mail Mint, Wordpress | 2026-09-07 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. | ||||
| CVE-2026-84754 | 2 Getwpfunnels, Wordpress | 2 Wpfunnels, Wordpress | 2026-09-07 | 6.5 Medium |
| Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions. | ||||
| CVE-2026-84755 | 2 Getwpfunnels, Wordpress | 2 Mail Mint, Wordpress | 2026-09-07 | 6.5 Medium |
| Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions. | ||||
| CVE-2026-84758 | 2 Strategy11team, Wordpress | 2 Business Directory Plugin, Wordpress | 2026-09-07 | 6.5 Medium |
| Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions. | ||||
| CVE-2026-84766 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluent Booking | 2026-09-07 | 5.9 Medium |
| Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions. | ||||
| CVE-2026-84812 | 2 Wordplus, Wordpress | 2 Better Messages, Wordpress | 2026-09-07 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions. | ||||
| CVE-2026-85303 | 2 Magepeople, Wordpress | 2 Booking & Rental Manager, Wordpress | 2026-09-07 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking and Rental Manager: from n/a through 2.7.7. | ||||
| CVE-2026-75160 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-07 | 9.1 Critical |
| An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi. | ||||
| CVE-2026-75161 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-07 | N/A |
| An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to inject arbitrary code into the dpcheck system utility executed as root. | ||||
| CVE-2026-75162 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-07 | N/A |
| An information disclosure vulnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows any remote authenticated user, including users with the low-privileged Standard role, to retrieve the configured OPC-UA authentication credentials in cleartext via the JSON API response. | ||||