Total
396399 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-84819 | 2026-09-10 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions. | |||||
| CVE-2026-84282 | 2026-09-10 | N/A | 6.5 MEDIUM | ||
| A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server URL before initiating outbound connections. An authenticated administrator can manipulate the document server parameter to cause the ownCloud server to send arbitrary requests to attacker-controlled destinations, including localhost and internal network hosts. This allows internal network reconnaissance and TCP port scanning based on differences in server responses. | |||||
| CVE-2026-84063 | 2026-09-10 | N/A | 6.5 MEDIUM | ||
| BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If this vulnerability is exploited, an arbitrary file may be uploaded by an attacker who can log in to the product, potentially allowing arbitrary PHP code to be executed may be caused. | |||||
| CVE-2026-84062 | 2026-09-10 | N/A | 4.3 MEDIUM | ||
| BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key. If this vulnerability is exploited, the content of the page may be altered by an attacker who can log in to the product may be caused. | |||||
| CVE-2026-81801 | 2026-09-10 | N/A | 8.1 HIGH | ||
| Subscriber Settings Change in WP-Stateless <= 4.4.1 versions. | |||||
| CVE-2026-81794 | 2026-09-10 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions. | |||||
| CVE-2026-81787 | 2026-09-10 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions. | |||||
| CVE-2026-81782 | 2026-09-10 | N/A | 6.5 MEDIUM | ||
| Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions. | |||||
| CVE-2026-78552 | 2026-09-10 | N/A | 6.0 MEDIUM | ||
| The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of injected directives. | |||||
| CVE-2026-78550 | 2026-09-10 | N/A | 6.6 MEDIUM | ||
| The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator SSH session. As a result, the unsanitized input is executed directly, leading to code execution with the privileges of the management console. | |||||
| CVE-2026-69878 | 1 Microsoft | 7 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 4 more | 2026-09-10 | N/A | 6.4 MEDIUM |
| Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code locally. | |||||
| CVE-2026-69845 | 1 Microsoft | 7 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 4 more | 2026-09-10 | N/A | 9.8 CRITICAL |
| Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69824 | 2026-09-10 | N/A | 9.8 CRITICAL | ||
| Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69460 | 2026-09-10 | N/A | 7.1 HIGH | ||
| Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-69430 | 2026-09-10 | N/A | 7.0 HIGH | ||
| Use after free in Windows Embedded Mode Service allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-58013 | 2 Gnome, Redhat | 2 Glib, Enterprise Linux | 2026-09-10 | N/A | 6.5 MEDIUM |
| A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary. | |||||
| CVE-2026-58012 | 2 Gnome, Redhat | 2 Glib, Enterprise Linux | 2026-09-10 | N/A | 6.5 MEDIUM |
| A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary. | |||||
| CVE-2026-58011 | 2 Gnome, Redhat | 2 Glib, Enterprise Linux | 2026-09-10 | N/A | 6.5 MEDIUM |
| A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service. | |||||
| CVE-2026-58010 | 2 Gnome, Redhat | 2 Glib, Enterprise Linux | 2026-09-10 | N/A | 6.5 MEDIUM |
| A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary. | |||||
| CVE-2026-50165 | 2026-09-10 | N/A | N/A | ||
| alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. An Improper Access Control issue in versions prior to 2.0-M5-2605 allows an organization owner to read system-level configuration secrets through organization/event scoped "single configuration" endpoints. The affected endpoints require organization or event ownership, but they accept an arbitrary configuration key and then return the first matching value from a lookup that includes system-level configuration. As a result, an organization owner can retrieve secrets intended to be administrator-only, including the system API key when it is configured. Version 2.0-M5-2605 fixes the issue. | |||||
