Search Results (43678 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-96269 1 Gnu 1 Emacs 2026-09-24 7.8 High
GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no particular user settings are required to trigger it.
CVE-2026-75131 1 Nm-l2tp 1 Networkmanager-l2tp 2026-09-24 7.8 High
NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains a privilege escalation vulnerability that allows local users with permission to create VPN connections to execute arbitrary code as root by injecting pppd options through a crafted VPN username. Attackers can embed a double-quote character or whitespace in the username to break out of the pppd options file quoting context and include the pppd plugin directive, causing the privileged pppd process to load an attacker-controlled shared object.
CVE-2026-55632 1 Gocd 1 Gocd 2026-09-23 4.3 Medium
GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompletion while editing pipeline, template, environment, and user-preference configuration returns its users-and-roles mode to regular authenticated users without requiring an administrator role. A lower-privileged user can enumerate configured user names and available role names, which can facilitate attacks against those users. The response does not reveal which roles are assigned to each user, and the endpoint cannot modify data. This issue is fixed in version 26.1.0.
CVE-2026-93527 2 Bdthemes, Wordpress 2 Live Copy Paste For Elementor, Wordpress 2026-09-23 8.5 High
Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.
CVE-2026-94498 2 Appmysite, Wordpress 2 Appmysite, Wordpress 2026-09-23 6.5 Medium
Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.
CVE-2026-94679 2 Wordpress, Wpmanageninja 2 Wordpress, Fluent Support 2026-09-23 5.4 Medium
Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.
CVE-2026-95513 2 Vcita, Wordpress 2 Online Booking & Scheduling Calendar For Wordpress By Vcita, Wordpress 2026-09-23 7.5 High
Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions.
CVE-2026-94080 2 Webwizards, Wordpress 2 Marketking, Wordpress 2026-09-23 5.3 Medium
Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.
CVE-2026-95522 2 Syed Balkhi, Wordpress 2 Easy Digital Downloads, Wordpress 2026-09-23 7.6 High
Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.
CVE-2026-95527 2 Conekta Group, Wordpress 2 Conekta Payment Gateway, Wordpress 2026-09-23 6.5 Medium
Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.
CVE-2026-95590 2 Tainacan, Wordpress 2 Tainacan, Wordpress 2026-09-23 7.1 High
Subscriber SQL Injection in Tainacan <= 1.2.0 versions.
CVE-2026-95604 2 Tangible, Wordpress 2 Loops & Logic, Wordpress 2026-09-23 7.5 High
Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.
CVE-2026-75723 3 Adobe, Linux, Microsoft 4 Campaign, Campaign Classic, Linux Kernel and 1 more 2026-09-23 10 Critical
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-82010 3 Adobe, Linux, Microsoft 4 Campaign, Campaign Classic, Linux Kernel and 1 more 2026-09-23 9.9 Critical
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-96514 1 Neethuharii 1 Cafemanagement 2026-09-23 7.3 High
A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogin.php of the component Login Handler. This manipulation of the argument uname causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-92692 1 Sulu 1 Sulu 2026-09-23 N/A
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affected Sulu 2.6 and 3.0 release lines have a Smart Content QueryBuilder in src/Sulu/Component/Content/SmartContent/QueryBuilder.php that concatenates category identifiers from the public categories query parameter into a JCR-SQL2 WHERE clause without numeric validation. On a public page containing a category-filtered Smart Content block, an unauthenticated attacker can alter query conditions to infer or enumerate content-repository nodes, including unpublished content, or submit malformed and expensive query fragments that degrade availability; this path does not modify repository data. This issue is fixed in versions 2.6.25 and 3.0.8.
CVE-2026-76089 1 Verbb 1 Formie 2026-09-23 7.7 High
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks. Any authenticated user able to invoke the action can enumerate notification IDs and read recipient headers and complete HTML email bodies containing submitted form data, even without the sent-notification viewing permission. This issue is fixed in versions 2.2.23 and 3.1.31.
CVE-2026-63330 1 Warp-tech 1 Warpgate 2026-09-23 7.7 High
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects /@warpgate/admin/api/recordings/{uuid}/stream only with session authentication and omits require_admin_permission for AdminPermission::RecordingsView. Any authenticated regular user who identifies an active recording can subscribe to its WebSocket and receive real-time terminal input and output from proxied SSH, MySQL, or PostgreSQL sessions, including credentials, commands, and other sensitive data belonging to users and administrators. This issue is fixed in version 0.25.6.
CVE-2026-12751 1 Ibm 1 Cloud Pak For Business Automation 2026-09-23 5.4 Medium
IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
CVE-2026-94124 2 Levelfourdevelopment, Wordpress 2 Wp-easycart, Wordpress 2026-09-23 8.5 High
Contributor SQL Injection in WP EasyCart <= 5.9.4 versions.