Export limit exceeded: 401580 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (401580 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-71299 | 1 Redhat | 1 Multicluster Engine | 2026-10-05 | 6.5 Medium |
| A flaw was found in Maestro. Its REST API write endpoints were registered without proper authentication middleware. This allows a remote attacker to perform unauthorized write operations, such as creating, modifying, or deleting consumers and resource bundles. This could lead to data integrity issues or a denial of service (DoS). | ||||
| CVE-2026-71298 | 1 Redhat | 1 Multicluster Engine | 2026-10-05 | 6.4 Medium |
| A flaw was found in maestro. A remote attacker could exploit a SQL injection vulnerability in the `orderBy` query parameter of its REST API list endpoints. This flaw, which does not require authentication, allows for read-only blind extraction of data from the database. | ||||
| CVE-2026-105649 | 2026-10-05 | 7.3 High | ||
| Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG images uploaded with a non-SVG file extension were stored without sanitization. This allowed any staff user, including Contributors, to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.65.0. | ||||
| CVE-2026-78411 | 1 Rapid7 | 1 Velociraptor | 2026-10-05 | 6.5 Medium |
| Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS permission to update the server metadata. Server metadata is often used to store site wide configuration data that should only be updated by the server admin. | ||||
| CVE-2026-12171 | 2026-10-05 | 7.8 High | ||
| auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over attacker-controlled repository content (for example, in a CI workflow that checks out an untrusted pull request head, or locally on a forked or third-party repository) executes attacker-chosen code with the privileges of the invoking user or CI job, including access to workflow secrets, without the repository dependencies ever being installed. The plugins option similarly loads attacker-controlled modules from the repository. Under the same conditions, appendGitLog/appendGitTag allow git argument injection (e.g. --output= to write arbitrary files), output allows writing attacker-influenced content to arbitrary paths, and template causes an outbound request to an attacker-chosen URL. Version 2.6.1 treats in-repository configuration as untrusted and refuses to run when it sets these options, unless the new --unsafe-config flag is passed. | ||||
| CVE-2026-86671 | 2026-10-05 | N/A | ||
| In Eclipse Che versions 7.29.0 and later, the GET `/api/scm/resolve` and `POST /api/factory/resolver` endpoints pass an attacker-controlled URL to `URLFetcher.fetch()`, which calls `new URL(url).openConnection()` with no scheme or host allow-list and returns the response body to the caller. Any authenticated Che user can read arbitrary local files via the file:// scheme (including the pod's Kubernetes service-account token at `file:///var/run/secrets/kubernetes.io/serviceaccount/token`), reach internal HTTP services and cloud instance metadata endpoints (169.254.169.254), and have their stored SCM personal access token attached as an `Authorization` header to a host of their choosing. The same credential-forwarding behavior also fires when a victim opens a workspace from a malicious devfile whose `parent.uri` points to an attacker-controlled server, enabling exfiltration of the victim's SCM PAT without direct API access. No fix is available. | ||||
| CVE-2026-105648 | 2026-10-05 | 4 Medium | ||
| Ghost is a Node.js content management system. From 6.0.9 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network on some network configurations. A successful attack would not result in any response data being returned. This issue is fixed in version 6.65.0. | ||||
| CVE-2026-102779 | 2026-10-05 | N/A | ||
| Joomla Extension - joomlafry.com - Unauthenticated forced execution of published automation tasks in TF Content 2.9.0 - 2.9.4 - The extension exposes the site task `records.custom_action` without authentication, ACL, CSRF, task-trigger, content-binding, or cron-token enforcement. A Guest can supply the numeric ID of any published TF Content task and make the component dispatch its configured executor immediately. | ||||
| CVE-2026-102777 | 1 Svenbluege.de | 1 Event Gallery For Joomla | 2026-10-05 | N/A |
| Joomla Extension - svenbluege.de - Server-side request forgery in the Google Photos picker in Event Gallery extension < 6.6.0 - The Google Photos picker of the back-end upload page fetches the thumbnails of the picked images through the server, with the OAuth access token of the Google Photos account. The task took the address to fetch from the request without checking it and asked for no form token. A prepared page on another web site could therefore make the server send the access token of the account to any address, or fetch addresses inside the server's network, in the name of a logged in administrator; a back-end user with the permission "Manage" could do the same directly. The token is valid for about an hour and reaches what the picker session of the account reaches. | ||||
| CVE-2026-28659 | 1 Google | 1 Android Xr | 2026-10-05 | 7.8 High |
| In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-92078 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 6.5 Medium |
| Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-92079 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 9.1 Critical |
| Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-88397 | 2026-10-05 | N/A | ||
| ApiAdmin v.5.0 and before is vulnerable to SQL Injection in the user-list endpoint GET /admin/User/getUsers via the gid parameter. | ||||
| CVE-2026-102282 | 1 Cthackers | 1 Adm-zip | 2026-10-05 | 7.1 High |
| adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via `fs.chmodSync()` when `keepOriginalPermission=true` is passed to `extractAllTo()`/`extractEntryTo()` — and it never filters the setuid/setgid/sticky bits out of those bits. A zip crafted by an attacker can therefore produce an extracted binary with mode `04755`. When extraction runs as root (the default posture in Docker builds, CI runners, and privileged install steps — the exact environments where this flag is used), the resulting root-owned setuid file is executed later by a lesser-privileged user, turning the attacker's code into a root execution. Version 0.6.1 fixes the issue. | ||||
| CVE-2026-103066 | 2026-10-05 | 8.5 High | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0. | ||||
| CVE-2026-100506 | 2026-10-05 | 7.2 High | ||
| Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Check: from n/a through 12.1. | ||||
| CVE-2026-100511 | 2026-10-05 | 8.8 High | ||
| Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1. | ||||
| CVE-2026-97257 | 2026-10-05 | 8.8 High | ||
| Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7. | ||||
| CVE-2026-93617 | 2026-10-05 | 7.2 High | ||
| Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1. | ||||
| CVE-2026-103348 | 2026-10-05 | 7.2 High | ||
| Deserialization of Untrusted Data vulnerability in Smackcoders Inc. WP Ultimate Exporter wp-ultimate-exporter allows Object Injection.This issue affects WP Ultimate Exporter: from n/a through 3.0. | ||||