Export limit exceeded: 400096 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400096 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103399 | 1 Redhat | 1 Enterprise Linux | 2026-09-30 | 5.3 Medium |
| A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the body is read, the server neither drains the declared body bytes nor closes the connection. On a keep-alive connection, those leftover bytes are interpreted as a subsequent HTTP request. A remote, unauthenticated attacker can place a complete HTTP request in the body and cause SoupServer to process that smuggled request, leading to unintended request handling. | ||||
| CVE-2026-97265 | 2026-09-30 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.8.15.3. | ||||
| CVE-2026-102392 | 2026-09-30 | 7.2 High | ||
| Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions. | ||||
| CVE-2026-102391 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions. | ||||
| CVE-2026-102377 | 2026-09-30 | 8.8 High | ||
| Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions. | ||||
| CVE-2026-102376 | 2026-09-30 | 7.1 High | ||
| Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions. | ||||
| CVE-2026-102375 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Broken Access Control in Optimole <= 4.2.14 versions. | ||||
| CVE-2026-100512 | 2026-09-30 | 9.8 Critical | ||
| Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions. | ||||
| CVE-2026-100510 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions. | ||||
| CVE-2026-97291 | 2026-09-30 | 8.8 High | ||
| Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions. | ||||
| CVE-2026-97290 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions. | ||||
| CVE-2026-97256 | 2026-09-30 | 7.2 High | ||
| Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions. | ||||
| CVE-2026-94171 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions. | ||||
| CVE-2026-102397 | 2026-09-30 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions. | ||||
| CVE-2026-103440 | 2026-09-30 | N/A | ||
| Exposure of sensitive information through data queries vulnerability in The Wikimedia Foundation MediaWiki PageTriage extension allows Information Elicitation. This issue affects MediaWiki PageTriage extension: 1.46, 1.45, and 1.43. | ||||
| CVE-2026-94419 | 1 Wolfssl | 1 Wolfssl | 2026-09-30 | 5.4 Medium |
| Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the form {row, index, hash(sessionID)} into the process-global SessionCache, and ClientSessionToSession() validates it against that hash alone. Because the TLS 1.2 session ID is chosen by the server and sent in clear, AddSessionToCache() matches any other server's session on the same ID and overwrites the client-side entry with that server's master secret, cipher suite and version, while the handle continues to resolve; nothing on the write path compares the peer, the application's server ID or the WOLFSSL_CTX. Resuming through the handle then produces an abbreviated handshake in which no Certificate message is sent, so neither chain verification nor wolfSSL_check_domain_name() runs, and the attacker is accepted as the original server for the whole of that connection. Affected builds are those leaving NO_SESSION_CACHE_REF, NO_SESSION_CACHE, NO_CLIENT_CACHE and TITAN_SESSION_CACHE all undefined, which includes a plain ./configure, --enable-opensslextra and --enable-opensslall; fifteen integration options define NO_SESSION_CACHE_REF and are therefore not affected, among them --enable-all, --enable-distro, --enable-curl, --enable-nginx, --enable-haproxy, --enable-stunnel, --enable-wpas and the rest of the OPENSSL_COMPATIBLE_DEFAULTS family, and --enable-leanpsk, --enable-leantls, --enable-lowresource and --enable-tinytls13 disable the cache outright. The application must use the legacy reference flow, wolfSSL_get_session() or SSL_get_session() followed by wolfSSL_set_session(); wolfSSL_get1_session() returns the session object itself and is not affected, nor are wolfSSL_SetServerID() lookups. Only TLS 1.2 and below and DTLS 1.2 and below are reachable, since TLS 1.3 and ticket resumption with an empty ServerHello session ID both use a client-chosen cache key. The poisoned entry lives in the process-global cache, so it crosses WOLFSSL_CTX boundaries and persists until the entry is evicted or the session times out, 500 seconds by default. Releases v5.3.0 through v5.9.2 are affected; the fix adds a per-write generation counter to the cache and raises WOLFSSL_CACHE_VERSION from 2 to 3, so a cache persisted by an older build is rejected by a fixed one. | ||||
| CVE-2017-20051 | 1 Jrsoftware | 1 Inno Setup | 2026-09-30 | 6.3 Medium |
| ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The sole source documents PE-format conformance defects in innosetup-5.5.9.exe with no exploit, attack path, or untrusted search path condition (CWE-426/427), and the author states Windows loads these files normally; the record's remote/exploited claims are unsupported, as is the product maintainer's contention. | ||||
| CVE-2026-103439 | 2026-09-30 | N/A | ||
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikbase extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki Wikbase extension: 1.46, 1.45, and 1.43. | ||||
| CVE-2026-103438 | 2026-09-30 | N/A | ||
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikistories extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki Wikistories extension: 1.46, 1.45, and 1.43. | ||||
| CVE-2026-100276 | 2026-09-30 | 5.9 Medium | ||
| In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action | ||||