Search Results (91039 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-105135 1 Internlm 1 Mindsearch 2026-10-06 10 Critical
A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-105089 1 Wwbn 1 Avideo 2026-10-06 8.7 High
WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe src attributes to execute JavaScript in victims' browsers.
CVE-2026-103005 1 Elastic 1 Elasticsearch 2026-10-06 6.5 Medium
Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management privileges could cause the cluster to allocate an uncontrolled amount of memory when connector resources with an excessively large `description` field are created and subsequently accessed, exhausting available heap memory and crashing the affected node.
CVE-2026-105166 1 Kishor-23 2 Food-waste-management-system, Food Waste Management System 2026-10-06 7.3 High
A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of the file fooddonateform.php of the component Food Donation Form. Performing a manipulation of the argument image-choice results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-39758 2 Midtrans, Wordpress-extensions 2 Midtrans-woocommerce, Midtrans-woocommerce 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Midtrans-WooCommerce <= 2.32.3 versions.
CVE-2026-39766 2 Reputeinfosystems, Wordpress-extensions 2 Arforms, Arforms 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.
CVE-2026-39767 2 Baseapp, Wordpress-extensions 2 Wpbase Cache, Wpbase Cache 2026-10-06 6.5 Medium
Subscriber Denial of Service Attack in WPBase Cache <= 5.5.6 versions.
CVE-2026-39768 2 Cleantalk, Wordpress-extensions 2 Security & Malware Scan, Security & Malware Scan By Cleantalk 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Security & Malware scan by CleanTalk <= 2.189 versions.
CVE-2026-39778 2 Themeansar, Wordpress-extensions 2 Ansar Import – One Click Starter Sites – For Elementor & Themes, Ansar Import – One Click Starter Sites – For Elementor & Themes 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Ansar Import – One Click Starter Sites – for Elementor &amp; Themes <= 2.1.2 versions.
CVE-2026-39780 2 Wordpress-extensions, Youzify 2 Youzify, Youzify 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Youzify <= 1.3.7 versions.
CVE-2026-39781 2 Dan Rossiter, Wordpress-extensions 2 Document Gallery, Document Gallery 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Document Gallery <= 5.1.1 versions.
CVE-2026-39784 2 Nicdark, Wordpress-extensions 2 Hotel Booking, Hotel Booking 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Hotel Booking <= 3.8 versions.
CVE-2026-39788 2 Shamimsplugins, Wordpress-extensions 2 Front End Pm, Front End Pm 2026-10-06 6.5 Medium
Subscriber Cross Site Scripting (XSS) in Front End PM <= 11.4.6 versions.
CVE-2026-39790 2 E4jvikwp, Wordpress-extensions 2 Vikrentcar, Vikrentcar 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in VikRentCar <= 1.4.6 versions.
CVE-2026-40806 2 Plugin-devs, Wordpress-extensions 2 Blog, Posts And Category Filter For Elementor, Blog Posts And Category Filter For Elementor 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions.
CVE-2026-40807 2 Aman, Wordpress-extensions 2 Cf7 Views – Complete Entry Management For Contact Form 7, Cf7 Views 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in CF7 Views &#8211; Complete Entry Management for Contact Form 7 <= 3.2.6 versions.
CVE-2026-102163 2026-10-06 8.8 High
On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthenticated attacker within radio frequency (RF) proximity can send a crafted frame to crash the sensor service, disabling WIPS monitoring on the access point, or potentially achieve remote code execution. No wireless association or authentication is required.
CVE-2026-102161 2026-10-06 8.8 High
An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges on the CV-CUE backend.
CVE-2026-102160 2026-10-06 7.2 High
An operating system (OS) command injection vulnerability in CloudVision CUE backup management may allow an authenticated Super User to submit a crafted backup request and execute arbitrary commands with the privileges of the affected service.
CVE-2026-102158 2026-10-06 6.5 Medium
Improper validation of selected CloudVision CUE application programming interface (API) request parameters may allow an authenticated network user to perform SQL injection against the backend impacting its availability.