Export limit exceeded: 395622 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 395622 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (395622 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-1030 | 1 Ibm | 1 Common Licensing | 2026-09-19 | 4.3 Medium |
| IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data. | ||||
| CVE-2026-1025 | 1 Ibm | 1 Common Licensing | 2026-09-19 | 6.1 Medium |
| IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | ||||
| CVE-2026-18442 | 2 Wclovers, Wordpress | 2 Wcfm Marketplace – Multivendor Marketplace For Woocommerce, Wordpress | 2026-09-19 | 7.5 High |
| The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'wcfmmp_user_location_lng' parameter in all versions up to, and including, 3.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-18441 | 2 Latepoint, Wordpress | 2 Appointment Booking Plugin – Latepoint | Calendar & Scheduling For Wordpress, Wordpress | 2026-09-19 | 4.3 Medium |
| The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.9 via the set_customer_object due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to enumerate arbitrary customer records and disclose personally identifiable information - including first name, last name, email address, and phone number - by iterating the customer[id] parameter. This issue is exploitable only when the site is configured with customer authentication disabled (guest checkout enabled). | ||||
| CVE-2026-17619 | 1 Ibm | 1 Spectrum Lsf Ibm Platform Rtm | 2026-09-19 | 8.6 High |
| IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | ||||
| CVE-2026-17262 | 1 Ibm | 1 I | 2026-09-19 | 5.4 Medium |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands. | ||||
| CVE-2026-15797 | 2 Danieliser, Wordpress | 2 Popup Maker – Boost Sales, Conversions, Optins, Subscribers With The Ultimate Wp Popup Builder, Wordpress | 2026-09-19 | 6.4 Medium |
| The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post_title in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacker to create a post with an HTML entity-encoded payload in the title, which bypasses sanitize_text_field on save and is later decoded and executed by the browser when rendered by the Select2 component. | ||||
| CVE-2026-15275 | 2026-09-19 | 7.5 High | ||
| The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The injection occurs in a numeric, unquoted SQL context, meaning WordPress's wp_magic_quotes() addslashes-based protection cannot neutralize the payload, and the AJAX handler is registered on wp_ajax_nopriv_make_search_request with no nonce or capability check, making it fully accessible without authentication. | ||||
| CVE-2026-15004 | 2026-09-19 | 5.4 Medium | ||
| The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions up to, and including, 6.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-12954 | 2 Mapster, Wordpress | 2 Mapster Wp Maps, Wordpress | 2026-09-19 | 8.8 High |
| The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function. This is due to the function performing no nonce verification, no capability check, and no allowlist validation on the meta key supplied via the `acf-photo-gallery-groups` POST parameter before passing both the meta key and its corresponding value directly to `update_user_meta()`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary user meta values, though privilege escalation is not possible. | ||||
| CVE-2026-12739 | 2 Saadiqbal, Wordpress | 2 Wp Easy Pay – Payment And Donation Form Builder For Square, Wordpress | 2026-09-19 | 4.3 Medium |
| The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to permanently delete arbitrary posts, pages, and custom post types (bypassing the trash via force deletion) or change any published post to draft status. | ||||
| CVE-2026-11727 | 1 Ibm | 1 Mq For Hpe Nonstop | 2026-09-19 | 8.1 High |
| IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data. | ||||
| CVE-2026-11726 | 1 Ibm | 1 Mq For Hpe Nonstop | 2026-09-19 | 8.1 High |
| IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values. | ||||
| CVE-2026-11722 | 1 Ibm | 1 Cics Tx Advanced | 2026-09-19 | 4.8 Medium |
| IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability. | ||||
| CVE-2026-11716 | 1 Ibm | 1 Mq For Hpe Nonstop | 2026-09-19 | 7.5 High |
| IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data. | ||||
| CVE-2026-11711 | 1 Ibm | 1 Websphere Application Server | 2026-09-19 | 6.5 Medium |
| IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component. | ||||
| CVE-2026-11710 | 1 Ibm | 1 Websphere Application Server | 2026-09-19 | 6.5 Medium |
| IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers. | ||||
| CVE-2026-11548 | 1 Ibm | 1 Cics Tx Advanced | 2026-09-19 | 4.8 Medium |
| IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability. | ||||
| CVE-2026-11545 | 1 Ibm | 1 Websphere Application Server | 2026-09-19 | 3.7 Low |
| IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks. | ||||
| CVE-2026-11540 | 1 Ibm | 1 Websphere Application Server | 2026-09-19 | 5.3 Medium |
| IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet. | ||||