Export limit exceeded: 398494 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (398494 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100379 | 1 Wikimedia Foundation | 1 Wikipedia Android App | 2026-09-26 | N/A |
| Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies. This issue affects Wikipedia Android App: main. | ||||
| CVE-2026-100378 | 2026-09-26 | N/A | ||
| Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - Translate Extension: from * before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2026-100377 | 1 Wikimedia | 1 Mediawiki-wikilambda Extension | 2026-09-26 | N/A |
| Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Excavation. This issue affects Mediawiki - WikiLambda Extension: 1.47.0-alpha. The issue has been remediated on the `master` branch. | ||||
| CVE-2026-100376 | 2026-09-26 | N/A | ||
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - TemplateSandbox Extension: from * before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2026-72668 | 1 Elastic | 1 Kibana | 2026-09-26 | 7.3 High |
| Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who subsequently interacts with that agent. Where the same user can also author workflows, this can extend to full administrative control of Kibana and of the Elasticsearch cluster. | ||||
| CVE-2026-94408 | 1 Elastic | 1 Elasticsearch | 2026-09-26 | 4.9 Medium |
| Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | ||||
| CVE-2026-97160 | 1 Lomart.fr | 1 Up Plugin For Joomla | 2026-09-26 | N/A |
| Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 | ||||
| CVE-2026-97162 | 1 Lomart.fr | 1 Up Plugin For Joomla | 2026-09-26 | N/A |
| Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 | ||||
| CVE-2026-97163 | 1 Lomart.fr | 1 Up Plugin For Joomla | 2026-09-26 | N/A |
| Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 | ||||
| CVE-2026-97161 | 1 Lomart.fr | 1 Up Plugin For Joomla | 2026-09-26 | N/A |
| Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 | ||||
| CVE-2026-78582 | 1 Elastic | 1 Kibana | 2026-09-26 | 6.5 Medium |
| Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into spaces they have no access to. Where a monitor is associated with a private location, the same operation also destroys the underlying Elastic Agent integration configuration without the authorization checks that Fleet would otherwise apply. | ||||
| CVE-2026-82294 | 1 Elastic | 1 Elasticsearch | 2026-09-26 | 6.5 Medium |
| Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). | ||||
| CVE-2026-94396 | 1 Elastic | 1 Elasticsearch | 2026-09-26 | 6.5 Medium |
| Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | ||||
| CVE-2026-94397 | 1 Elastic | 1 Elasticsearch | 2026-09-26 | 6.5 Medium |
| Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | ||||
| CVE-2026-37604 | 1 Ph7software | 1 Ph7builder | 2026-09-26 | 9.8 Critical |
| pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _protected/framework/Ip/Ip.class.php from the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verifying the request comes from a trusted proxy. Because the admin login attempt counter and lockout are keyed on this value, a remote unauthenticated attacker bypasses IP-based throttling by sending a different X-Forwarded-For value per request | ||||
| CVE-2026-93641 | 1 Zimbra | 1 Zimbra Collaboration Suite | 2026-09-26 | 9.3 Critical |
| An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim. | ||||
| CVE-2026-93642 | 1 Zimbra | 1 Zimbra Collaboration Suite | 2026-09-26 | 9.3 Critical |
| An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim. | ||||
| CVE-2026-93643 | 1 Zimbra | 1 Zimbra Collaboration Suite | 2026-09-26 | 9.8 Critical |
| When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra. | ||||
| CVE-2026-93647 | 1 Zimbra | 1 Zimbra Collaboration Suite | 2026-09-26 | 9.3 Critical |
| An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim. | ||||
| CVE-2026-63431 | 1 Horilla | 1 Horilla | 2026-09-26 | 6.5 Medium |
| Horilla is an HR and CRM software. In 1.5.0-85 and earlier, payroll/views/component_views.py does not consistently authorize access in allowances_deductions_tab, view_single_allowance, and view_single_deduction before loading records selected by emp_id, allowance_id, or deduction_id. An authenticated employee can substitute those identifiers to read another employee's salary structure, allowance and deduction amounts, personal loan disbursements, and repayment schedules without owning the record or holding payroll-view permissions. No complete fixed version is available as of this review. | ||||