Export limit exceeded: 377734 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (377734 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-84766 | 2026-09-03 | 5.9 Medium | ||
| Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions. | ||||
| CVE-2026-81295 | 2026-09-03 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions. | ||||
| CVE-2026-84238 | 2026-09-03 | 9.8 Critical | ||
| Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions. | ||||
| CVE-2026-81773 | 2026-09-03 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | ||||
| CVE-2026-84144 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-09-03 | 7.5 High |
| Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | ||||
| CVE-2026-84848 | 2026-09-03 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions. | ||||
| CVE-2026-84847 | 2026-09-03 | 7.5 High | ||
| Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions. | ||||
| CVE-2026-84812 | 2026-09-03 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions. | ||||
| CVE-2026-84778 | 2026-09-03 | 7.5 High | ||
| Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration & Cloning <= 6.65 versions. | ||||
| CVE-2026-84776 | 2026-09-03 | 7.5 High | ||
| Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions. | ||||
| CVE-2026-84769 | 2026-09-03 | 6.5 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions. | ||||
| CVE-2026-84767 | 2026-09-03 | 5.3 Medium | ||
| Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions. | ||||
| CVE-2026-84758 | 2026-09-03 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions. | ||||
| CVE-2026-84754 | 2026-09-03 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions. | ||||
| CVE-2026-84753 | 2026-09-03 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. | ||||
| CVE-2026-81776 | 2026-09-03 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions. | ||||
| CVE-2026-81282 | 2026-09-03 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions. | ||||
| CVE-2026-81281 | 2026-09-03 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions. | ||||
| CVE-2026-51689 | 1 Totolink | 1 T6 | 2026-09-03 | 9.1 Critical |
| Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmware-upgrade workflow changes via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||||
| CVE-2026-84963 | 1 Mongodb | 1 C Driver | 2026-09-03 | 5.3 Medium |
| An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing operation still reports success and returns no error. An unauthenticated party who can supply the input processed by an application that uses this component may cause that application to hold data that does not match what was submitted, which may result in unintended alteration of data. | ||||