Search

Search Results (401682 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-104380 2026-10-06 N/A
Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it. A cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx.
CVE-2026-105708 1 Imgproxy 1 Imgproxy 2026-10-06 4.3 Medium
A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-97300 2026-10-06 6.5 Medium
Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.
CVE-2026-41563 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions.
CVE-2026-41558 2026-10-06 7.5 High
Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.
CVE-2026-39789 2026-10-06 7.5 High
Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.
CVE-2026-39760 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.
CVE-2026-39723 2026-10-06 7.5 High
Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions.
CVE-2026-39599 2026-10-06 4.3 Medium
Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions.
CVE-2026-32582 2026-10-06 6.5 Medium
Contributor Broken Access Control in IATO MCP <= 1.11.0 versions.
CVE-2026-32576 2026-10-06 6.5 Medium
Customer Insecure Direct Object References (IDOR) in Faktur Pro for WooCommerce <= 3.2.1 versions.
CVE-2026-105072 2026-10-06 7.5 High
Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions.
CVE-2026-105707 1 Uptrace 1 Uptrace 2026-10-06 5.3 Medium
A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerability is the function Login of the file pkg/org/user_handler.go. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-51898 1 Sinaptik-ai 1 Pandas-ai 2026-10-06 9.8 Critical
sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute.
CVE-2026-51906 1 Taskingai 1 Taskingai 2026-10-06 9.1 Critical
In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers to write downloaded images to arbitrary locations on the server filesystem by manipulating the project_id parameter.
CVE-2026-51915 2026-10-06 9.8 Critical
TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the tool controller. In affected source snapshots, get_tool and update_tool in superagi/controllers/tool.py accept a caller-supplied tool_id and fail to verify organization ownership through the associated toolkit. A remote authenticated attacker from one organization can read or modify another organization's tool metadata through /tools/get/{tool_id} and /tools/update/{tool_id}.
CVE-2026-105706 1 Sourcecodester 1 Drug Recommendation System 2026-10-06 4.3 Medium
A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
CVE-2026-51881 1 Hkuds 1 Deeptutor 2026-10-06 9.8 Critical
deeptutor 1.4.0 contains code injection in ExecTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to execute reviewer-chosen shell commands in the service environment.
CVE-2026-105705 1 Sourcecodester 1 Drug Recommendation System 2026-10-06 4.3 Medium
A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
CVE-2026-105704 1 Sourcecodester 1 Drug Recommendation System 2026-10-06 7.3 High
A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be executed remotely. The exploit is publicly available and might be used.