Export limit exceeded: 403420 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403420 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403420 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103646 | 2026-10-08 | 9.8 Critical | ||
| The Ultimate Multisite WordPress plugin before 2.17.0 does not require authentication before a logged-out checkout is linked to, and logged in as, an existing WordPress account matching the submitted email address, and its duplicate-account check normalizes that address differently from the lookup used to create the customer, so an unauthenticated attacker can log in as any existing user, including a Network Super Admin, whose email address they know. This bypass is not addressed by the 2.15.1 fix for CVE-2026-75957 and remains exploitable in all versions up to and including 2.16.1, the releases that fix was expected to cover. Exploitation requires a checkout form configured without a password field (auto-generated password) and a target account that has no existing customer record in the Ultimate Multisite WordPress plugin before 2.17.0. | ||||
| CVE-2026-103309 | 2026-10-08 | 7.5 High | ||
| The GPTranslate WordPress plugin before 2.34.14 does not properly restrict who can store translations, and does not escape them when outputting them in translated pages, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks when server-side translations are enabled. | ||||
| CVE-2026-15830 | 1 Djangoproject | 1 Django | 2026-10-08 | 5.3 Medium |
| An issue was discovered in Django 6.0 before 6.0.9 and 5.2 before 5.2.18. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Andrew MacPherson and kimchunbok_ for reporting this issue. | ||||
| CVE-2024-7885 | 1 Redhat | 21 Apache Camel Hawtio, Apache Camel Spring Boot, Build Keycloak and 18 more | 2026-10-08 | 7.5 High |
| A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder instance, potentially leading to information leakage between requests or responses. In some cases, a value from a previous request or response may be erroneously reused, which could lead to unintended data exposure. This issue primarily results in errors and connection termination but creates a risk of data leakage in multi-request environments. | ||||
| CVE-2025-21042 | 1 Samsung | 2 Android, Mobile Devices | 2026-10-08 | 8.8 High |
| Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. | ||||
| CVE-2023-35311 | 1 Microsoft | 6 365 Apps, Office, Office 2019 and 3 more | 2026-10-08 | 8.8 High |
| Microsoft Outlook Security Feature Bypass Vulnerability | ||||
| CVE-2026-85234 | 1 Redhat | 2 Enterprise Linux, Hummingbird | 2026-10-08 | 7.5 High |
| A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom error message, it can pass invalid match offsets to the `genmatchstring()` function. This leads to out-of-bounds read/write operations. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted request, causing the daemon to crash and resulting in a denial of service. | ||||
| CVE-2026-17615 | 1 Redhat | 18 Apicurio Registry, Build Keycloak, Build Of Apache Camel For Quarkus and 15 more | 2026-10-08 | 7.5 High |
| A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability. | ||||
| CVE-2026-12260 | 1 Netboard Crm | 1 Netboard Crm Demo Platform | 2026-10-08 | N/A |
| SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in the ‘/module/auth/recovery.php’ endpoint. The parameter is vulnerable to blind attacks based on Boolean, error, time-based and UNION techniques. Exploitation allows attackers to extract confidential information (such as the version and type of backend used), alter data or further compromise the CRM environment. | ||||
| CVE-2026-106063 | 1 Redhat | 1 Enterprise Linux | 2026-10-08 | 6.3 Medium |
| A heap-based buffer overflow was found in GIMP’s DICOM export plug-in. When exporting an image with extremely large width and height, the export path allocates a buffer using a 32-bit width * height (and bytes-per-pixel) product that can overflow. GEGL then writes the full uncompressed extent into the undersized buffer, after integer overflow in the allocation size | ||||
| CVE-2026-106061 | 1 Redhat | 1 Enterprise Linux | 2026-10-08 | 5.5 Medium |
| A flaw was found in GIMP’s X cursor (XMC) thumbnail loader. When GIMP generates a thumbnail for a crafted XMC file, it allocates a pixel buffer using a width * height size computed in 32-bit signed arithmetic. If that product overflows, the allocation is smaller than the true image extent. A subsequent GEGL buffer read uses the unwrapped dimensions and performs an out-of-bounds read on the heap, after integer overflow in the size calculation. This can crash GIMP or corrupt process memory. | ||||
| CVE-2026-106062 | 1 Redhat | 1 Enterprise Linux | 2026-10-08 | 7.8 High |
| A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height, and pitch can be computed using 32-bit arithmetic that overflows. The allocated buffer is too small for the amount of pixel data written through GEGL, following integer overflow in size calculations. This may allow heap corruption and, in the worst case, arbitrary code execution in the context of the GIMP process. | ||||
| CVE-2025-71383 | 2026-10-08 | 9.8 Critical | ||
| Dbit WIFI4 N300 1.0.0 devices allow the management interface to be crashed via a request (from the local Wi-Fi network) that lacks a /api/login username or password field. This occurs because of an error in a JSON parser. | ||||
| CVE-2026-32582 | 2026-10-08 | 6.5 Medium | ||
| Missing Authorization vulnerability in iatoai IATO MCP iato-mcp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IATO MCP: from n/a through 1.12.0. | ||||
| CVE-2026-25263 | 1 Qualcomm | 1 Snapdragon | 2026-10-08 | 6.6 Medium |
| Memory corruption while processing IOCTL command called from user space to the kernel with invalid parameters. | ||||
| CVE-2026-107448 | 2026-10-08 | 3.4 Low | ||
| Magic: The Gathering Arena (Windows/Steam client; 2026.59.30.12801.127931.6 and certain later 2026.60.x builds) passes a server-supplied URL from a home-screen carousel GoToExternalUrl action directly to the Windows shell via Application.OpenURL/ShellExecuteW without validating the URI scheme or domain. A hypothetical attacker able to control the carousel content delivered to clients can cause arbitrary registered URI-scheme handlers to be invoked on client hosts with no user interaction. For example, one might expect that the carousel content only has https: URIs, not ms-calculator: URIs. | ||||
| CVE-2026-94114 | 1 Apache | 1 Commons Bcel | 2026-10-08 | 5.9 Medium |
| Symbolic name not mapping to correct class. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class. This issue affects Apache Commons BCEL: before 6.13.0. Users are recommended to upgrade to version 6.13.0, which fixes the issue. | ||||
| CVE-2026-25274 | 1 Qualcomm | 1 Snapdragon | 2026-10-08 | 6.7 Medium |
| Memory Corruption when processing concurrent DMA buffer allocation and deallocation commands without proper synchronization. | ||||
| CVE-2026-87688 | 1 Brocade | 1 Fabric Os | 2026-10-08 | N/A |
| An input validation vulnerability exists in the security certificate management component of the Brocade Fabric OS administrative management API. When processing certificate management operations, user-supplied certificate identifiers are handled without adequate sanitization prior to execution in external system routines. An authenticated attacker with privileges to perform certificate deletion requests can leverage this flaw to execute arbitrary system commands with the privileges of the underlying management daemon. This vulnerability affects Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. | ||||
| CVE-2026-94580 | 1 Brocade | 1 Fabric Os | 2026-10-08 | N/A |
| An arbitrary file and directory deletion vulnerability exists in the REST API management interface handling USB storage operations on Brocade Fabric OS versions before 10.0.1. An authenticated user possessing USB management privileges can manipulate requested target paths to delete arbitrary files or directories on the switch's local root filesystem, bypassing intended USB mount point boundaries. | ||||