CVE-2026-96820
Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions.
Busca em todas as edições
Agregado automaticamente, sem curadoria humana, a partir de fontes públicas: CISA KEV, NVD, EQSTLab e VEXDay. Cada alerta leva à sua fonte oficial.
1496 alertas em todas as edições, exibindo 421–450.
CVE-2026-96820
Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions.
CVE-2026-96819
Subscriber Cross Site Scripting (XSS) in oik <= 4.15.4 versions.
CVE-2026-96816
Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions.
CVE-2026-96814
Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions.
CVE-2026-96352
Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions.
CVE-2026-96351
Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions.
CVE-2026-94499
Subscriber Broken Access Control in FormGent <= 1.12.2 versions.
CVE-2026-94081
Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.
CVE-2026-94078
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions.
CVE-2026-93770
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions.
CVE-2026-93514
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions.
CVE-2026-93512
Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.
CVE-2026-27371
Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.
CVE-2026-102398
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions.
CVE-2026-102396
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions.
CVE-2026-102395
Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions.
CVE-2026-102385
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
CVE-2026-100507
Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions.
CVE-2026-103242
A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content — of attacker-chosen length — past the...
CVE-2026-92869
An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.
CVE-2026-91832
The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every...
CVE-2026-88797
The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any hosted on the WordPress.org repository.
CVE-2026-93495
Improper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a specially crafted device.
CVE-2026-102127
An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including...
CVE-2026-47598
NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module event delivery path where an unprivileged local user could cause a use-after-free through a race between asynchronous event delivery and file close. A successful exploit of this vulnerability might lead to code execution,...
CVE-2026-47596
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can write to read-only memory because the memory's permissions are not preserved. A successful exploit of this vulnerability might lead to code execution and escalation of privileges.
CVE-2026-47582
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
CVE-2026-86950
Apple · Multiple Products
Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
CVE-2026-71379
The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.
CVE-2026-96587
The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.