Export limit exceeded: 403768 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (403768 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-94510 1 Microsoft 1 Bookings 2026-10-09 9.9 Critical
Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-92990 2026-10-09 5.3 Medium
The SendPress Newsletters WordPress plugin through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the same on every site rather than a per-site secret, allowing unauthenticated users to read newsletter sending logs, including recipient email addresses.
CVE-2026-92989 2026-10-09 4.3 Medium
The SendPress Newsletters WordPress plugin through 1.26.1.20 does not check the user's capability on several newsletter-management actions, allowing any authenticated subscriber-level user to synchronise all site users into a mailing list and to drive the newsletter send queue.
CVE-2026-89235 2026-10-09 6.8 Medium
The Testimonials by BestWebSoft WordPress plugin through 1.0.8 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL to the query.
CVE-2026-88131 1 Microsoft 1 Dataverse 2026-10-09 9.8 Critical
Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network.
CVE-2026-86850 2026-10-09 6.5 Medium
The SKU Error Fixer for WooCommerce WordPress plugin through 1.0 does not perform any capability or nonce checks on two of its AJAX actions, which are also available to unauthenticated users, allowing them to permanently delete product variations it classifies as obsolete, and to disclose those variations' details, with no recoverable copy left behind.
CVE-2026-85348 2026-10-09 4.3 Medium
The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF protection when updating one of its settings, allowing attackers to change that setting via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2026-84224 2026-10-09 4.1 Medium
The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetching it, allowing users with editor-level access and above to make the site issue requests to internal services that are not otherwise reachable, and to tell which of those are live from the response.
CVE-2026-84032 1 Ibm 1 Guardium Data Protection 2026-10-09 5.6 Medium
IBM Guardium Data Protection 12.2.2 could allow a remote attacker to conduct a man-in-the-middle attack due to improper certificate validation.
CVE-2026-83947 1 Microsoft 1 Azure Event Grid System 2026-10-09 7.7 High
Missing authorization in Azure Event Grid allows an authorized attacker to perform spoofing over a network.
CVE-2026-83943 1 Microsoft 1 Azure Api Center 2026-10-09 8.7 High
Exposure of sensitive information to an unauthorized actor in Azure API Center allows an unauthorized attacker to disclose information over a network.
CVE-2026-78027 2026-10-09 5.8 Medium
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Server-side request forgery.
CVE-2026-78022 2026-10-09 6.8 Medium
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Not Failing Securely ('Failing Open') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
CVE-2026-78017 2026-10-09 3.8 Low
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Check for Unusual or Exceptional Conditions vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Protection mechanism bypass.
CVE-2026-77900 1 Microsoft 1 Azure App Service 2026-10-09 9.8 Critical
Missing authentication for critical function in Azure App Service allows an unauthorized attacker to execute code over a network.
CVE-2026-76769 2026-10-09 4.3 Medium
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
CVE-2026-75875 1 Ibm 1 Guardium Data Protection 2026-10-09 9.8 Critical
IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to path traversal.
CVE-2026-69435 1 Microsoft 1 Azure Sre Agent 2026-10-09 9.6 Critical
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
CVE-2026-49243 1 Webmin 1 Webmin 2026-10-09 9.6 Critical
Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.650, Webmin users who click on a malicious link to their server are vulnerable to this XSS vulnerability that could be used to execute attacker-controlled commands. This issue has been patched in version 2.650.
CVE-2026-108107 2026-10-09 9.8 Critical
PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to extract customer records and credentials via time-based blind SQL injection.