Export limit exceeded: 400204 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400204 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-92994 | 2026-09-30 | 8.8 High | ||
| The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it. | ||||
| CVE-2026-93580 | 2026-09-30 | 5.3 Medium | ||
| The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an IP check that is not enforced, allowing unauthenticated attackers who know a target order's parcel tracking number to forge its shipment status and prematurely mark the order completed. | ||||
| CVE-2026-47543 | 1 Nvidia | 5 Geforce, Nvs, Quadro and 2 more | 2026-09-30 | 6.7 Medium |
| VIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-47565 | 1 Nvidia | 6 Geforce, Guest Driver, Nvs and 3 more | 2026-09-30 | 6.4 Medium |
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a privileged user could trigger a race condition that leads to an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-47566 | 1 Nvidia | 6 Geforce, Guest Driver, Nvs and 3 more | 2026-09-30 | 5.5 Medium |
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a memory leak in error paths leading to kernel memory exhaustion. A successful exploit of this vulnerability might lead to denial of service. | ||||
| CVE-2026-47567 | 1 Nvidia | 7 Geforce, Guest Driver, Nvs and 4 more | 2026-09-30 | 5.5 Medium |
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a user could cause uncontrolled resource consumption by exhausting the DRM VMA offset address space. A successful exploit of this vulnerability might lead to denial of service. | ||||
| CVE-2026-47568 | 1 Nvidia | 7 Geforce, Guest Driver, Nvs and 4 more | 2026-09-30 | 5.5 Medium |
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause uncontrolled kernel log generation by repeatedly invoking an interface that emits unrate-limited error messages. A successful exploit of this vulnerability might lead to denial of service. | ||||
| CVE-2026-47574 | 1 Nvidia | 1 Virtual Gpu Manager | 2026-09-30 | 7.8 High |
| NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability where an attacker could cause incorrect resource transfer between spheres. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-0631 | 1 Tp-link | 2 Archer Be230, Archer Be230 Firmware | 2026-09-30 | 8.0 High |
| An OS Command Injection vulnerability exists in the Surfshark VPN login functionality in TP-Link Archer BE230 v1.2, BE3600v1 and AXE75 v1, allowing an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although similar in nature, each instance is tracked under a unique CVE ID. This issue affects Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420 and Archer AXE75 v1 < 1.5.6 Build 20260623. | ||||
| CVE-2026-101276 | 2026-09-30 | N/A | ||
| iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22. | ||||
| CVE-2026-102304 | 1 Google | 1 Chrome | 2026-09-30 | 9.6 Critical |
| Use after free in Passwords in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-102310 | 1 Google | 1 Chrome | 2026-09-30 | 6.5 Medium |
| Missing authorization in Payments in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-102312 | 1 Google | 2 Android, Chrome | 2026-09-30 | 4.3 Medium |
| UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-51872 | 2026-09-30 | N/A | ||
| Devika v1.0 is vulnerable to Code Injection via the Runner.run_code function in src/agents/runner/runner.py. | ||||
| CVE-2026-51871 | 2026-09-30 | N/A | ||
| Devika v1.0 is vulnerable to Code Injection in the Runner.execute function in src/agents/runner/runner.py which allows an attacker to achieve arbitrary code execution by exploiting the direct execution of LLM-generated content. | ||||
| CVE-2026-51870 | 2026-09-30 | N/A | ||
| DeepTutor v1.4.0 is vulnerable to command execution in /tutorbot/agent/tools/shell.py:ExecTool.execute. | ||||
| CVE-2026-51869 | 2026-09-30 | N/A | ||
| DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host. | ||||
| CVE-2026-51867 | 2026-09-30 | N/A | ||
| agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object. | ||||
| CVE-2026-94274 | 2026-09-30 | 5.3 Medium | ||
| The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content. | ||||
| CVE-2026-94297 | 2026-09-30 | 2.7 Low | ||
| The Media Library Organizer WordPress plugin before 2.1.4 does not verify that the requesting user holds the target taxonomy's management capability before creating a new term, allowing users with contributor-level access and above to create publicly visible terms in any taxonomy registered on the site. | ||||