Search

Search Results (402802 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-106573 2026-10-07 5.3 Medium
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a missing limit check in the MVG decoder allows a crafted MVG image to trigger an excessively long-running operation. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.
CVE-2026-106572 2026-10-07 5.3 Medium
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a missing recursion-depth check in the CALS decoder allows a crafted CALS image to exhaust the call stack and terminate the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55.
CVE-2026-106571 2026-10-07 5.1 Medium
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 6.9.13-56 and 7.1.2-31, a crafted local call to the GetVirtualPixels API can trigger an integer calculation error and write beyond a heap buffer, crashing the server process. This issue is fixed in versions 6.9.13-56 and 7.1.2-31.
CVE-2026-106570 2026-10-07 4.3 Medium
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, an unauthenticated adjacent-network client can repeatedly connect to the distributed pixel cache server and exhaust its available connections, causing denial of service. This issue is fixed in version 7.1.2-32.
CVE-2026-106569 2026-10-07 5.3 Medium
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, missing validation and resource checks in the ASE decoder allow a crafted ASE image to cause a crash or a long-running operation. This issue is fixed in version 7.1.2-32.
CVE-2026-106233 1 Google 1 Chrome 2026-10-07 8.3 High
Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-106232 1 Google 1 Chrome 2026-10-07 5.4 Medium
UI misrepresentation in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106568 2026-10-07 5.3 Medium
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted XMP profile embedded in an image can cause the profile parser to enter an infinite loop, preventing image processing from completing. This issue is fixed in versions 7.1.2-32 and 6.9.13-57.
CVE-2026-106567 2026-10-07 5.9 Medium
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57.
CVE-2026-106566 2026-10-07 4 Medium
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, delegate symlink cleanup does not check the MAGICK_SHRED_PASSES environment variable, allowing a local privileged workflow to overwrite a file with random data. This issue is fixed in version 7.1.2-32.
CVE-2026-81164 2 Drupal, Entity Pdf Project 2 Entity Pdf, Entity Pdf 2026-10-07 5.4 Medium
Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5.
CVE-2026-96589 1 Gitea 1 Gitea 2026-10-07 4.3 Medium
When a private repository is transferred to a user who lacks access, Gitea grants that recipient temporary read access as a collaborator so they can review the repository. Rejecting or cancelling the transfer did not revoke this collaboration, so the named recipient kept persistent read access to the private repository, including its code, issues, pull requests and wiki, and could clone it. The repository owner was not notified. Transfer-granted access is now removed while collaborations that existed before the transfer are preserved.
CVE-2026-96404 1 Gitea 1 Gitea 2026-10-07 8.1 High
When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the account is an administrator, the session grants full administrative access, including changing the account's password. Databases with a single user also did not require the reinstall confirmation.
CVE-2026-93449 1 Ibm 1 Langflow Oss 2026-10-07 8.5 High
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
CVE-2026-92533 1 Bugtracker.net 1 Bugtracker.net 2026-10-07 N/A
Path traversal vulnerability in the BugTracker.NET file download component. The parameter used to specify the file name does not properly validate user-supplied paths. An authenticated remote attacker could enter a manipulated path to access files located outside the intended directory. Successful exploitation could allow the attacker to read system files accessible to the account used by the application.
CVE-2026-92531 1 Bugtracker.net 1 Bugtracker.net 2026-10-07 N/A
Operating system command injection vulnerability in the SVN integration component of BugTracker.NET. The application incorporates the value of the field corresponding to the repository into an svn.exe command without properly validating it. An authenticated user with administrator privileges could store manipulated arguments in the database and subsequently cause them to be processed by the revision comparison functionality. A successful exploit could allow the execution of arbitrary commands with the privileges of the account used by the application. To exploit this vulnerability, svn.exe must be installed and capable of being invoked by the service.
CVE-2026-89417 2026-10-07 7.2 High
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 's' Search Parameter via comments-atom Feed in all versions up to, and including, 6.3.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that the front-end server serves the retained .tmp file without a Content-Type or X-Content-Type-Options header, enabling MIME-sniffing browsers such as Chromium to execute the injected script — a condition present by default on many Apache and nginx/php-fpm deployments.
CVE-2026-88962 1 Ibm 1 Langflow Oss 2026-10-07 8.8 High
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
CVE-2026-79960 1 Gitea 1 Gitea 2026-10-07 7.1 High
When a push was authenticated with a deploy key, Gitea recorded the repository owner as the pusher, so permission checks in the push hook pipeline evaluated the owner instead of the deploy key. A holder of a writable deploy key could create protected tags without being on the tag allow list and change repository visibility through push options, for example making a private repository public. Pull requests created through the AGit flow with a deploy key were also attributed to the owner.
CVE-2026-79796 1 Hewlett Packard Enterprise (hpe) 1 Clearpass Policy Manager (cppm) 2026-10-07 9.8 Critical
Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain unauthorized access to the affected system.