Export limit exceeded: 10074 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 389262 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (389262 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-78738 | 2026-09-08 | N/A | ||
| Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature. | ||||
| CVE-2026-78510 | 1 Microsoft | 9 365 Apps, Microsoft 365, Office 2016 and 6 more | 2026-09-08 | 9.8 Critical |
| Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-9033 | 1 Tp-link | 55 Dr3150, Dr3150 Firmware, Dr3150 V1 and 52 more | 2026-09-08 | 4.3 Medium |
| An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access. Successful exploitation may allow termination of individual or all active captive portal sessions, causing temporary service disruption and requiring users to re-authenticate. | ||||
| CVE-2026-78507 | 1 Microsoft | 8 365 Apps, Microsoft 365, Office 2019 and 5 more | 2026-09-08 | 8.8 High |
| Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-78506 | 1 Microsoft | 10 365 Apps, Microsoft 365, Office 2019 and 7 more | 2026-09-08 | 5.5 Medium |
| Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-78504 | 1 Microsoft | 10 365 Apps, Microsoft 365, Office 2019 and 7 more | 2026-09-08 | 8.8 High |
| Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-78503 | 1 Microsoft | 10 365 Apps, Microsoft 365, Office 2019 and 7 more | 2026-09-08 | 6.5 Medium |
| Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-84937 | 2 Video Player For Youtube Project, Wordpress | 2 Video Player For Youtube, Wordpress | 2026-09-08 | 6.8 Medium |
| The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users with the Contributor role and above to perform SQL injection attacks and read arbitrary data from the database. | ||||
| CVE-2026-18406 | 2 Brainstormforce, Wordpress | 2 Sureforms, Wordpress | 2026-09-08 | 7.2 High |
| The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field Entity-Encoded Payload in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-85414 | 2 Fooplugins, Wordpress | 2 Gallery By Foogallery, Wordpress | 2026-09-08 | 6.4 Medium |
| The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-78502 | 1 Microsoft | 10 365 Apps, Microsoft 365, Office 2019 and 7 more | 2026-09-08 | 6.5 Medium |
| Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-10196 | 2 Getwpfunnels, Wordpress | 2 Mail Mint–email Marketing, Newsletter, Email Automation & Woocommerce Emails, Wordpress | 2026-09-08 | 9.8 Critical |
| The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form_submission' function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code on the server. The vulnerability was partially patched in version 1.23.1. | ||||
| CVE-2026-15550 | 2 Saturdaydrive, Wordpress | 2 Ninja Forms - Save Progress, Wordpress | 2026-09-08 | 4.3 Medium |
| The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability checks and nonce verification in the 'bulk_actions' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary database records from the 'wp_nf3_objects' table, such as saved submissions. | ||||
| CVE-2026-86191 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2026-09-08 | 4.3 Medium |
| SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying parent database visibility. Attackers can access the endpoint to retrieve complete key schemas including sensitive field names and relation definitions from hidden databases. | ||||
| CVE-2026-86192 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2026-09-08 | 6.5 Medium |
| SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization. | ||||
| CVE-2026-78971 | 2026-09-08 | N/A | ||
| In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions. | ||||
| CVE-2026-16310 | 2 Learndash, Wordpress | 2 Learndash, Wordpress | 2026-09-08 | 9.8 Critical |
| The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the password of any WordPress user, including administrators, by supplying an arbitrary user ID during registration, and take over their account without any notification sent to the victim. | ||||
| CVE-2026-86180 | 1 Code-projects | 2 Task Management System, Task Management System In Php | 2026-09-08 | 7.3 High |
| A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2026-19859 | 2 Formbuilder Project, Wordpress | 2 Formbuilder, Wordpress | 2026-09-08 | 6.5 Medium |
| The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registered on the site on any page displaying a form. Escaping is applied to that content before a later shortcode-expansion pass rather than after it, so the escaping can be bypassed. | ||||
| CVE-2026-19862 | 2 Formbuilder Project, Wordpress | 2 Formbuilder, Wordpress | 2026-09-08 | 4.8 Medium |
| The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender. Exploitation requires the site to be configured to take one of the message's addresses from a form field. | ||||