Search

Search Results (403614 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-106065 2 Gimp, Redhat 2 Gimp, Enterprise Linux 2026-10-09 6.3 Medium
A heap-based buffer overflow was found in GIMP’s PCX export plug-in. For images with extremely large width and height, buffer allocation uses overflowing 32-bit width * height arithmetic while subsequent GEGL operations use the full extent, after integer overflow in size calculation
CVE-2026-94670 2 Wordpress-extensions, Wpeverest 2 Everest Forms, Everest Forms 2026-10-09 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Everest Forms allows Reflected XSS. This issue affects Everest Forms: from n/a through 3.6.1.
CVE-2026-95534 2 Unlimited-elements, Wordpress-extensions 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor 2026-10-09 8.8 High
Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Object Injection. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.19.
CVE-2026-95595 2 Fontsplugin, Wordpress-extensions 2 Disable And Remove Google Fonts Gdpr Dsgvo Friendly, Disable And Remove Google Fonts Gdpr Dsgvo Friendly 2026-10-09 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fontsplugin Disable and Remove Google Fonts | GDPR & DSGVO friendly disable-remove-google-fonts allows Reflected XSS. This issue affects Disable and Remove Google Fonts | GDPR & DSGVO friendly: from n/a through 2.0.2.
CVE-2026-95605 2 Passionate Programmer Peter, Wordpress-extensions 2 Wp Data Access, Wp Data Access 2026-10-09 9.3 Critical
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Passionate Programmer Peter WP Data Access allows Blind SQL Injection. This issue affects WP Data Access: from n/a through 5.5.82.
CVE-2026-95606 2 Stellarwp, Wordpress-extensions 2 The Events Calendar, The Events Calendar 2026-10-09 9.8 Critical
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection. This issue affects The Events Calendar: from n/a through 6.17.4.
CVE-2026-96335 2 Wordpress-extensions, Wpmudev 2 Forminator, Forminator Forms 2026-10-09 7.5 High
Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Forminator: from n/a through 1.57.2.
CVE-2026-106066 2 Gimp, Redhat 2 Gimp, Enterprise Linux 2026-10-09 6.3 Medium
A heap-based buffer overflow was found in GIMP’s raw data export plug-in. When exporting very large images, g_malloc() sizing based on overflowing width * height * bytes-per-pixel can allocate far less memory than GEGL reads or writes during export, following integer overflow
CVE-2026-106067 2 Gimp, Redhat 2 Gimp, Enterprise Linux 2026-10-09 6.3 Medium
A heap-based buffer overflow was found in GIMP’s Hot color filter plug-in. For very large images, a pixel buffer is allocated using overflowing 32-bit width * height (and related) arithmetic while the filter’s pixel access path uses the true image size, after integer overflow in the allocation size
CVE-2026-56851 1 Golang 1 Text 2026-10-09 7.5 High
The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer.
CVE-2026-103371 1 Apache 1 Geode 2026-10-09 7.5 High
Insertion of Sensitive Information into Log File in Apache Geode Web Management. This issue affects Apache Geode: from 2.0.0 before 2.0.3. Users are recommended to upgrade to version 2.0.3, which fixes the issue.
CVE-2026-107161 2 Cyrusimap, Redhat 6 Cyrus-sasl, Enterprise Linux, Hardened Images and 3 more 2026-10-09 7.5 High
A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application.
CVE-2026-107353 1 Ljharb 1 Traverse 2026-10-09 6.5 Medium
traverse (npm) versions 0.3.6 through 0.3.9, 0.4.0 through 0.4.6, 0.5.0 through 0.5.2, and 0.6.0 through 0.6.11 allow prototype pollution through set(). When the path passed to set() crosses a primitive value, the next path segment is resolved on that primitive's built-in prototype, so an application that passes an untrusted path to set() lets an attacker add or overwrite properties of String.prototype, Number.prototype, or Boolean.prototype using plain JSON data, for example traverse({ name: 'bob' }).set(['name', '__proto__', 'polluted'], 'yes'). Object.prototype was reachable only with a non-data path segment, such as an object whose toString returns a different value on each call, or through a Proxy that accepts an assignment without storing it. This is fixed in 0.3.10, 0.4.7, 0.5.3, and 0.6.12.
CVE-2026-34499 1 Johnsoncontrols 1 Advms 2026-10-09 N/A
Use of hard-coded cryptographic key vulnerability in Johnson Controls ADVMS allows Read Sensitive Constants Within an Executable. This issue affects ADVMS: before 3.10.
CVE-2026-76286 1 Splunk 1 Splunk Mcp Server 2026-10-09 5.3 Medium
In Splunk MCP Server versions below 1.2.1, Splunk MCP Server could send the Splunk platform authentication token of a user who runs a custom Application Programming Interface (API) tool to the URL configured for that tool. If another user controls that URL, they could capture the token and use it to access data and perform actions as the user who ran the tool. Successful exploitation requires a user who holds a role that contains the mcp_tool_execute capability to run a custom API tool configured by another user. For more information see Configure the Splunk MCP Server (https://help.splunk.com/en/splunk-enterprise/mcp-server-for-splunk-platform/1.2/configure-the-splunk-mcp-server) and Managing custom tools in Splunk MCP Server (https://help.splunk.com/en/splunk-enterprise/mcp-server-for-splunk-platform/1.2/managing-custom-tools-in-splunk-mcp-server) in the Splunk documentation.
CVE-2026-94154 2 R3098, Wordpress-extensions 2 Aurora Heatmap, Aurora Heatmap 2026-10-09 6.1 Medium
The Aurora Heatmap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an admin user clicks the injected heatmap link.
CVE-2026-17538 2 Latepoint, Wordpress-extensions 2 Latepoint, Latepoint 2026-10-09 5.4 Medium
The LatePoint - Appointment Booking & Reservation plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.6.9. This is due to the process_step_customer() function using is_user_logged_in() as the sole gate before merging POSTed customer data into an existing LatePoint customer, without any ownership checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the personal information (first name, last name, email, phone, notes) of arbitrary LatePoint customers, and, when the contact_merge setting is 'phone', to overwrite the victim's email address and take over the account via a password reset.
CVE-2026-88648 1 Gnu 1 Gnutls 2026-10-09 7.4 High
Incomplete X.509 implementation in GnuTLS v3.8.13 allows attackers controlling a subordinate Certificate Authority to bypass cross-domain PKI restrictions and issue unauthorized certificates.
CVE-2026-82627 2 Uncannyowl, Wordpress-extensions 2 Uncanny Automator, Uncanny Automator 2026-10-09 7.5 High
The Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.6.1.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object when a third-party integration plugin (such as PeepSo, MailPoet, WPForms, etc) is installed and a recipe is configured that stores attacker-controlled data as trigger meta. The additional presence of a POP chain within Uncanny Automator allows attackers to delete arbitrary files on the server.
CVE-2026-87726 1 Nxp 1 Nxpnfcrdlib 2026-10-09 3.9 Low
Insufficient API bounds checking in phalFelica in NXP NXPNfcRdLib RC663 through 07.14.00_Pub may allow an attacker with privileges or an untrusted third party to access unintended memory regions, potentially leading to limited loss of confidentiality, integrity, and availability. All software versions from 07.18.00 onwards have fixed this problem.