Export limit exceeded: 395531 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (395531 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-8325 | 1 Autodesk | 1 Revit | 2026-09-17 | 7.8 High |
| A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | ||||
| CVE-2026-1289 | 1 Autodesk | 3 Autocad, Autocad Lt, Revit | 2026-09-17 | 7.8 High |
| A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process. | ||||
| CVE-2026-91718 | 1 Google | 1 Chrome | 2026-09-17 | 9.6 Critical |
| Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-91716 | 1 Google | 1 Chrome | 2026-09-17 | 9.6 Critical |
| Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-91715 | 1 Google | 1 Chrome | 2026-09-17 | 8.8 High |
| Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-91711 | 1 Google | 1 Chrome | 2026-09-17 | 8.8 High |
| Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-91708 | 1 Google | 1 Chrome | 2026-09-17 | 3.1 Low |
| Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-77874 | 2026-09-17 | 7.1 High | ||
| A flaw was found in Hibernate ORM. This vulnerability allows an authenticated attacker to inject arbitrary SQL commands into the underlying database by manipulating the JSON path argument. The issue arises from improper handling of JSON path segments in the JsonPathHelper.appendInlinedJsonPathIncludingPassingClause() method, specifically when using Oracle, DB2, or HANA database dialects. Successful exploitation can lead to authorization bypass and significant data exfiltration, enabling the attacker to access sensitive information from the database. | ||||
| CVE-2026-66572 | 2026-09-17 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions. | ||||
| CVE-2026-66577 | 2026-09-17 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions. | ||||
| CVE-2026-66579 | 2026-09-17 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. | ||||
| CVE-2026-78528 | 2026-09-17 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions. | ||||
| CVE-2026-73999 | 2026-09-17 | 5.4 Medium | ||
| Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions. | ||||
| CVE-2026-66626 | 2026-09-17 | 7.6 High | ||
| Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions. | ||||
| CVE-2026-66619 | 2026-09-17 | 7.6 High | ||
| Administrator SQL Injection in Newsletters <= 4.18 versions. | ||||
| CVE-2026-91019 | 2026-09-17 | 4.9 Medium | ||
| The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys. | ||||
| CVE-2026-91017 | 2026-09-17 | 3.7 Low | ||
| The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature. | ||||
| CVE-2026-91015 | 2026-09-17 | 5.3 Medium | ||
| The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on a nonce that is publicly output to every visitor, allowing unauthenticated attackers to permanently disable any popup on the site. | ||||
| CVE-2026-91014 | 2026-09-17 | 7.1 High | ||
| The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run arbitrary web scripts in a visitor's browser if they can trick the visitor into following a crafted link (reflected XSS). | ||||
| CVE-2026-91011 | 2026-09-17 | 6.8 Medium | ||
| The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is stored in published content and executes in the browser of any user who later views the affected page. | ||||