Export limit exceeded: 402086 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402086 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104182 | 1 Uhop | 1 Stream-json | 2026-10-05 | 6.2 Medium |
| stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js and verifier at stream-json/jsonc/verifier.js restart comment-terminator scanning from the opening slash whenever a block or line comment spans an input chunk, while retaining the accumulated comment buffer. Delivering a large valid comment across many small chunks therefore causes quadratic CPU work and can stall the Node.js event loop. The maintainer characterizes the attack vector as local because the documented JSONC input is locally owned or user-controlled configuration, rather than input intended for the open internet. This JSONC-only scope does not include the plain JSON parser, which advances through and discards consumed string and number data. This issue is fixed in version 3.6.0. | ||||
| CVE-2025-56361 | 1 Csa-iot | 1 Matter | 2026-10-05 | 5.7 Medium |
| A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Level Control cluster's server tick logic (`emberAfLevelControlClusterServerTickCallback`). When a MoveToLevel command is executed and followed by a conflicting write to the OperationMode attribute (in the Pump Configuration and Control cluster), an invariant check (`minLevel < currentLevel`) fails and causes the device to abort. This leads to a denial of service condition. The issue is confirmed in SDK versions 1.3 and 1.4 (commit ab3d5ae), and is triggered remotely without authentication. | ||||
| CVE-2026-51894 | 1 Infiniflow | 1 Ragflow | 2026-10-05 | 6.5 Medium |
| infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_mindmap. A reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object. | ||||
| CVE-2026-51918 | 1 Ai4finance | 1 Finrobot | 2026-10-05 | 9.8 Critical |
| FinRobot 1.0.0 contains code injection in CodingUtils.create_file_with_code (). | ||||
| CVE-2026-88395 | 2026-10-05 | 9.8 Critical | ||
| GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter. | ||||
| CVE-2026-95166 | 2026-10-05 | N/A | ||
| In Bacularis v1.0.0 - 6.5.1 when adding a new pool, the LabelFormat field allows for a Cross Site Scripting (XSS) payload. | ||||
| CVE-2026-105712 | 1 Gnupg | 1 Gnupg | 2026-10-05 | 3.6 Low |
| gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk. | ||||
| CVE-2026-71298 | 1 Redhat | 1 Multicluster Engine | 2026-10-05 | 6.4 Medium |
| A flaw was found in maestro. A remote attacker could exploit a SQL injection vulnerability in the `orderBy` query parameter of its REST API list endpoints. This flaw, which does not require authentication, allows for read-only blind extraction of data from the database. | ||||
| CVE-2026-71299 | 1 Redhat | 1 Multicluster Engine | 2026-10-05 | 6.5 Medium |
| A flaw was found in Maestro. Its REST API write endpoints were registered without proper authentication middleware. This allows a remote attacker to perform unauthorized write operations, such as creating, modifying, or deleting consumers and resource bundles. This could lead to data integrity issues or a denial of service (DoS). | ||||
| CVE-2026-51879 | 1 Hkuds | 1 Deeptutor | 2026-10-05 | 9.1 Critical |
| deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TutorBotManager.write_bot_file. A remote caller can enumerate bot IDs and overwrite another bot's whitelisted control files through the HTTP tutorbot file route. | ||||
| CVE-2026-51893 | 2026-10-05 | 9.8 Critical | ||
| infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object. | ||||
| CVE-2026-88424 | 2026-10-05 | N/A | ||
| FineAdmin v1.0 was discovered to contain a SQL injection vulnerability via the field/order parameter at ButtonService.GetListByFilter(). This vulnerability allows attackers to access sensitive database information via crafted SQL statements. | ||||
| CVE-2026-93318 | 1 Moby | 1 Buildkit | 2026-10-05 | N/A |
| A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised DiffIDs to derive cache and snapshot identity without validating that they matched the actual layer contents. If a BuildKit daemon with shared or persistent cache first processes such a malicious image, a later build using the victim image may mount the attacker-controlled layer contents as the base image. This can allow code from the malicious image to run in the victim build, for example by replacing a commonly executed path such as /bin/sh. The attacker-controlled code may read build secrets mounted into the build, access other build resources, alter output artifacts, or hang the build. The issue affects both regular snapshotters and lazy-pulling snapshotters such as stargz. | ||||
| CVE-2026-93322 | 1 Moby | 1 Buildkit | 2026-10-05 | 6.2 Medium |
| A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon. | ||||
| CVE-2026-93320 | 1 Moby | 1 Buildkit | 2026-10-05 | 8.2 High |
| BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access. | ||||
| CVE-2026-105636 | 1 Makeplane | 1 Plane | 2026-10-05 | 9.9 Critical |
| Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, but the final URL reached after one or more redirects is not checked. A user who can create a workspace can register a webhook pointing to an attacker-controlled public endpoint that returns a 302 redirect to an internal address. The Plane worker then fetches internal resources, including cloud metadata, and stores the response body in webhook_logs, where the attacker can retrieve it through the workspace webhook-logs API. This issue is fixed in 1.4.0. | ||||
| CVE-2026-105741 | 2026-10-05 | 7.1 High | ||
| Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install) allowed authenticated remote attackers to bypass the "local-only" access restriction. By sending a spoofed X-Forwarded-For: 127.0.0.1 header, an attacker could make the server treat the request as originating from localhost, letting them write/overwrite an MCP client configuration file on the server's filesystem. This vulnerability is fixed in 1.10.3. | ||||
| CVE-2026-103100 | 1 Pexip | 2 Infinity, Pexip Infinity | 2026-10-05 | 7.5 High |
| Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting in a denial of service. | ||||
| CVE-2026-103101 | 1 Pexip | 2 Infinity, Pexip Infinity | 2026-10-05 | 8.6 High |
| Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible. | ||||
| CVE-2026-103102 | 1 Pexip | 2 Infinity, Pexip Infinity | 2026-10-05 | 8.6 High |
| Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client. | ||||