Search

Search Results (396907 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-96445 1 Redhat 2 Build Keycloak, Red Hat Single Sign On 2026-09-23 6.8 Medium
A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates specific HTTP headers to determine if a one-time password (OTP) should be skipped, but fails to verify if those headers came from a trusted source. This could allow an attacker who already has a user's password to bypass the second-factor authentication by providing a specially crafted header in their request.
CVE-2026-95845 1 Moquette-io 1 Moquette 2026-09-23 N/A
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message queues. When a fast publisher sends messages to a slow subscriber whose in-flight window is full, queued messages can accumulate without bound in memory or persistent storage. Remote clients can use this condition to exhaust broker resources and cause a denial of service. This issue is fixed in version 0.18.1.
CVE-2026-95603 2026-09-23 7.2 High
Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions.
CVE-2026-95600 2026-09-23 5.3 Medium
Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions.
CVE-2026-95592 2026-09-23 5.3 Medium
Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.
CVE-2026-95530 2026-09-23 6.5 Medium
Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions.
CVE-2026-95528 2026-09-23 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions.
CVE-2026-95524 2026-09-23 5.3 Medium
Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
CVE-2026-95522 2026-09-23 7.6 High
Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.
CVE-2026-95513 2026-09-23 7.5 High
Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions.
CVE-2026-94682 2026-09-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions.
CVE-2026-94671 2026-09-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.
CVE-2026-94498 2026-09-23 6.5 Medium
Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.
CVE-2026-94457 2026-09-23 4.8 Medium
Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions.
CVE-2026-94183 2026-09-23 7.4 High
Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about the origin of displayed content and increasing the risk of phishing.
CVE-2026-94181 2026-09-23 7.4 High
An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification.
CVE-2026-94179 2026-09-23 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions.
CVE-2026-94168 2 Leap13, Wordpress 2 Premium Addons For Elementor, Wordpress 2026-09-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.
CVE-2026-94118 2026-09-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions.
CVE-2026-93774 2026-09-23 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions.