Total
396049 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-75651 | 1 Adobe | 1 Experience Manager | 2026-09-11 | N/A | 5.4 MEDIUM |
| Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | |||||
| CVE-2026-73017 | 1 Microsoft | 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more | 2026-09-11 | N/A | 7.5 HIGH |
| Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally. | |||||
| CVE-2026-71440 | 1 Adobe | 1 Experience Manager | 2026-09-11 | N/A | 5.4 MEDIUM |
| Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | |||||
| CVE-2026-6642 | 2026-09-11 | N/A | 6.4 MEDIUM | ||
| The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset field values when they are rendered in HTML attribute contexts in the mla_generate_bulk_edit_form_fieldsets() function and mla-bulk-edit-fieldsets.tpl template. While wp_kses() filtering is applied during preset export for users without unfiltered_html capability, this does not prevent attribute injection attacks since the malicious payload consists of quotes and HTML attributes rather than HTML tags. When preset values are retrieved and rendered, they are directly assigned to template variables without esc_attr() escaping and then inserted into input element value attributes via simple string replacement. This makes it possible for authenticated attackers, with Author-level access and above (upload_files capability), to inject arbitrary web scripts that execute when an administrator imports the poisoned preset and the targeted input field receives focus. | |||||
| CVE-2026-69854 | 2026-09-11 | N/A | 9.0 CRITICAL | ||
| Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network. | |||||
| CVE-2026-62140 | 2026-09-11 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions. | |||||
| CVE-2026-62137 | 2026-09-11 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions. | |||||
| CVE-2026-62136 | 2026-09-11 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 versions. | |||||
| CVE-2026-62135 | 2026-09-11 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions. | |||||
| CVE-2026-62132 | 2026-09-11 | N/A | 5.3 MEDIUM | ||
| Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions. | |||||
| CVE-2026-62114 | 2026-09-11 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Passster <= 4.3.13 versions. | |||||
| CVE-2026-63076 | 1 Openssl | 1 Openssl | 2026-09-11 | N/A | 7.5 HIGH |
| Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer. Impact summary: A remote, unauthenticated attacker can crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service. CWE: CWE-476: NULL Pointer Dereference Description: When verifying the password-based MAC protection of a CMP message, OpenSSL library reads the protectionAlg algorithm parameter with X509_ALGOR_get0(), which returns both the parameter type and its value pointer. The value is then cast to an ASN1_STRING and treated as the expected PBMParameter after only checking that pointer is not NULL. The parameter type returned by X509_ALGOR_get0() was never consulted. This happens during protection verification, before any MAC is computed, so no knowledge of the PBM shared secret is required; the only precondition is that PBM verification is reachable. On the server side this is reached from OSSL_CMP_SRV_process_request() for any application that stands up a CMP server accepting PBM-protected messages, and on the client side from CMP response validation against a malicious or on-path (MITM) server. The reliable consequence is a denial of service; there is no memory disclosure, no controlled memory write, and no path to code execution. CMP is a specialized feature that an application must explicitly enable. FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. | |||||
| CVE-2026-62113 | 2026-09-11 | N/A | 4.3 MEDIUM | ||
| Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4.10.0 versions. | |||||
| CVE-2026-62110 | 2026-09-11 | N/A | 6.5 MEDIUM | ||
| Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions. | |||||
| CVE-2026-62109 | 2026-09-11 | N/A | 7.6 HIGH | ||
| Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions. | |||||
| CVE-2026-62107 | 2026-09-11 | N/A | 8.8 HIGH | ||
| Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions. | |||||
| CVE-2026-62103 | 2026-09-11 | N/A | 9.8 CRITICAL | ||
| Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions. | |||||
| CVE-2026-62102 | 2026-09-11 | N/A | 8.8 HIGH | ||
| Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions. | |||||
| CVE-2026-62089 | 2026-09-11 | N/A | 7.1 HIGH | ||
| Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2. | |||||
| CVE-2026-62088 | 2026-09-11 | N/A | 5.3 MEDIUM | ||
| Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data. This issue affects ElasticPress: from n/a through 5.3.4. | |||||
