Export limit exceeded: 397472 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 397472 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (397472 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-9622 2 Rockwell Automation, Rockwellautomation 2 Rslinx Classic , Rslinx Classic 2026-09-01 N/A
A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover.
CVE-2026-16675 2 Rockwell Automation, Rockwellautomation 2 Factorytalk Activation Manager, Factorytalk Activation Manager 2026-09-01 N/A
A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resources.
CVE-2026-81287 2 Syed Balkhi, Wordpress 2 Charitable, Wordpress 2026-09-01 8.5 High
Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.
CVE-2026-82228 2 Siteground, Wordpress 2 Siteground Security, Wordpress 2026-09-01 8.1 High
Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.
CVE-2026-81758 2 Ownerrez, Wordpress 2 Ownerrez Api, Wordpress 2026-09-01 6.3 Medium
Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.
CVE-2026-82551 1 Linux Foundation 1 Magma 2026-09-01 5.3 Medium
A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_handlers.c of the component NGSetup Handler. Executing a manipulation can lead to state issue. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2026-84109 1 Xinhu 1 Rainrock Rockoa 2026-09-01 6.3 Medium
A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. Affected by this issue is the function getOrder of the file webmain/webmainAction.php. Executing a manipulation of the argument highorder can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-82225 2 Metagauss, Wordpress 2 Registrationmagic, Wordpress 2026-09-01 7.4 High
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.
CVE-2026-81780 2 Hashthemes, Wordpress 2 Hash Form, Wordpress 2026-09-01 10 Critical
Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
CVE-2026-81280 2 Ukr Solution, Wordpress 2 Print Barcode Labels For Your Woocommerce Products/orders, Wordpress 2026-09-01 6.5 Medium
Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions.
CVE-2026-81278 2 Wordpress, Wpexperts 2 Wordpress, Post Smtp 2026-09-01 5.4 Medium
Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post SMTP: from 4.0.0 through beta.1.
CVE-2026-81293 2 Passionate Programmer Peter, Wordpress 2 Wp Data Access, Wordpress 2026-09-01 9.3 Critical
Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.
CVE-2026-81297 2 Wordpress, Wpmanageninja 2 Wordpress, Fluent Forms Pro Add On Pack 2026-09-01 7.5 High
Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
CVE-2026-81763 2 Wordpress, ウェブ屋のさとーさん 2 Wordpress, Throws Spam Away 2026-09-01 9.3 Critical
Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
CVE-2026-81768 2 Highwarden, Wordpress 2 Super Store Finder, Wordpress 2026-09-01 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
CVE-2026-19914 2 Uscnanbu, Wordpress 2 Welcart E-commerce, Wordpress 2026-09-01 7.2 High
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_order' parameter in all versions up to, and including, 2.12.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is delivered via the guest checkout form, requiring no authentication, and executes when an administrator views the affected order in the WordPress admin panel.
CVE-2026-17589 2 Levelfourstorefront, Wordpress 2 Shopping Cart \& Ecommerce Store, Wordpress 2026-09-01 4.9 Medium
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order' parameter in all versions up to, and including, 5.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order SQL injection: the payload is written to the ec_pageoption table via the ec_ajax_save_page_options handler — which applies no sanitization to raw $_POST values — and is later retrieved with stripslashes() (bypassing WordPress magic-quotes protection) before being concatenated directly into SQL on every store page render.
CVE-2026-16788 2 Livecomposer, Wordpress 2 Live Composer – Free Wordpress Website Builder, Wordpress 2026-09-01 6.4 Medium
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_projects_output Shortcode in all versions up to, and including, 2.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress's shortcode-aware kses handling preserves the serialized shortcode body as a placeholder before content filtering runs, allowing attacker-controlled values such as view_all_link, main_heading_link_title, main_filter_title_all, and button_text to reach render-time sinks entirely unescaped.
CVE-2026-16786 2 Livecomposer, Wordpress 2 Live Composer – Free Wordpress Website Builder, Wordpress 2026-09-01 6.4 Medium
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode in all versions up to, and including, 2.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload survives save-time wp_kses_post filtering because KSES treats shortcode delimiters as opaque, and the unescaped fields — including main_heading_title, view_all_link, main_heading_link_title, and main_filter_title_all — are only rendered when do_shortcode() executes at page-view time.
CVE-2026-15101 2 Wordpress, Wpbakery 2 Wordpress, Wpbakery Page Builder 2026-09-01 6.4 Medium
The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 8.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The wp_kses_post sanitization applied during save does not neutralize the payload because the malicious script content is base64-encoded as plain alphanumeric text with no HTML tags to strip; the vc_raw_html shortcode template then decodes and echoes this content unescaped at render time.