Export limit exceeded: 403737 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (403737 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-70522 1 Fanvil 1 X7a 2026-10-09 8.8 High
The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.
CVE-2026-59346 1 Vmware 2 Vmware Fusion, Vmware Workstation 2026-10-09 9.3 Critical
VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)
CVE-2026-59347 1 Vmware 2 Vmware Fusion, Vmware Workstation 2026-10-09 8.1 High
VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)
CVE-2026-103323 1 Wordpress-extensions 1 Integration For Epos Now And Woocommerce 2026-10-09 5.9 Medium
The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2 does not perform an authorization check on one of its REST endpoints, allowing unauthenticated users to retrieve the site's scheduled background tasks and their arguments, which include order identifiers and, when WooCommerce's deferred emails feature is enabled, the plaintext passwords of newly registered customers.
CVE-2026-103378 1 Wordpress-extensions 1 Geliver Aklly Kargo Pazaryeri 2026-10-09 6.5 Medium
The Geliver Akıllı Kargo Pazaryeri WordPress plugin before 3.1.1 does not prevent unauthenticated access to a log file it stores within its own web-accessible directory, into which it writes the site's carrier integration key while processing requests from unauthenticated users, allowing attackers to retrieve the key and use it to modify WooCommerce order statuses. The same log file also exposes customer information from orders the shop has processed.
CVE-2026-103681 1 Wordpress-extensions 1 Frontend Dashboard 2026-10-09 4.3 Medium
The Frontend Dashboard WordPress plugin before 3.0.0 does not perform a capability check in one of its AJAX actions, allowing authenticated users with low privileges, such as subscribers, to delete the Frontend Dashboard WordPress plugin before 3.0.0's configured profile and post form fields.
CVE-2026-104049 1 Wordpress-extensions 1 Academy Lms 2026-10-09 4.3 Medium
The Academy LMS WordPress plugin before 4.0.0 does not verify course enrollment or object ownership when returning a lesson's content through one of its REST API routes, allowing users with a self-registerable student account to read the full content of arbitrary lessons, including lessons of paid or private courses they are not enrolled in.
CVE-2026-104050 1 Wordpress-extensions 1 Academy Lms 2026-10-09 4.3 Medium
The Academy LMS WordPress plugin before 4.0.0 does not verify that a quiz question belongs to the course the requesting user is authorized to access before returning that question's answer options, allowing any authenticated user with access to a single course, such as an enrolled student, to read the quiz answer options of questions belonging to other courses they are not enrolled in.
CVE-2026-104651 1 Wordpress-extensions 1 Yaad Sarig Payment Gateway For Wc 2026-10-09 4.3 Medium
The Yaad Sarig Payment Gateway For WC WordPress plugin before 2.2.13 does not verify authorization or that the requesting user owns the target order in several of its order payment-processing actions, allowing any authenticated user, including subscribers, to act on and alter orders belonging to other customers.
CVE-2026-104652 1 Wordpress-extensions 1 Envira Gallery 2026-10-09 6.8 Medium
The Envira Gallery WordPress plugin before 1.16.1 does not sanitise and escape a gallery item identifier before outputting it in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page embedding the gallery.
CVE-2026-104653 1 Wordpress-extensions 1 Envira Gallery 2026-10-09 6.8 Medium
The Envira Gallery WordPress plugin before 1.16.1 does not sanitise or escape user-supplied gallery display configuration values before storing them and outputting them in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page containing the affected gallery.
CVE-2026-104667 1 Wordpress-extensions 1 Animated Number Counters 2026-10-09 6.8 Medium
The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the counter, leading to second-order SQL injection that can read arbitrary data including password hashes.
CVE-2026-104677 1 Wordpress-extensions 1 Wp Coder 2026-10-09 7.2 High
The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site.
CVE-2026-104678 1 Wordpress-extensions 1 Cp Media Player 2026-10-09 2.7 Low
The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that should require administrator access.
CVE-2026-104953 1 Wordpress-extensions 1 Mpg 2026-10-09 6.8 Medium
The MPG WordPress plugin before 4.2.3 does not properly validate the structure of imported project data before using it in a database query, allowing users with the Editor role or higher to perform SQL injection attacks and read sensitive data such as password hashes.
CVE-2026-105316 1 Wordpress-extensions 1 Magee Shortcodes 2026-10-09 7.1 High
The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting.
CVE-2026-86816 1 Wordpress-extensions 1 Wpcafe 2026-10-09 5.3 Medium
The WPCafe WordPress plugin before 3.0.21 does not restrict access to some of its REST API endpoints, allowing unauthenticated attackers to read WooCommerce product data, including per-product sales counts, exact stock levels, and private product meta, that WooCommerce itself keeps behind authentication.
CVE-2026-87782 1 Wordpress-extensions 1 Koinonia Link 2026-10-09 8.8 High
The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.
CVE-2026-87971 1 Wordpress-extensions 1 If-so Dynamic Content 2026-10-09 7.1 High
The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link.
CVE-2026-96530 1 Wordpress-extensions 1 Optimole 2026-10-09 6.5 Medium
The Optimole WordPress plugin before 4.2.15 does not perform a capability check before exposing its stored image-optimization account data in a dashboard widget, allowing any authenticated user, including Subscribers, to read the site's third-party service credentials.