Export limit exceeded: 403219 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403219 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-45161 | 1 Wger-project | 1 Wger | 2026-10-07 | 5.4 Medium |
| wger is a free, open-source workout and fitness manager. Prior to version 2.6, the `trainer_login` view in wger accepts GET requests and executes `django_login()` without any CSRF protection, because Django's `CsrfViewMiddleware` only enforces tokens on unsafe methods (POST/PUT/PATCH/DELETE). An attacker can embed a single `<img>` tag on a malicious page; when an authenticated trainer loads that page, their browser auto-issues the GET with the session cookie, forcibly rebinding the trainer's session to an arbitrary user account. Version 2.6 fixes the issue. | ||||
| CVE-2026-42710 | 2026-10-07 | 7.6 High | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Slider by 10Web slider-wd allows Blind SQL Injection.This issue affects Slider by 10Web: from n/a through 1.2.63. | ||||
| CVE-2026-107181 | 1 Telegram | 1 Telegram Desktop | 2026-10-07 | 8.1 High |
| Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover. | ||||
| CVE-2026-107174 | 1 Redhat | 4 Openshift, Serverless, Source To Image and 1 more | 2026-10-07 | 6.4 Medium |
| A flaw was found in source-to-image. When unpacking archive files, the application fails to properly sanitize symbolic links pointing to absolute file paths. An attacker who supplies a malicious builder image can exploit this vulnerability by embedding links pointing outside the extraction directory. This allows the attacker to bypass sandbox boundaries, potentially leading to unauthorized information disclosure or file modification on the host system. | ||||
| CVE-2026-107167 | 1 Redhat | 1 Enterprise Linux | 2026-10-07 | 6.2 Medium |
| A flaw was found in m17n-lib. A user providing specially crafted text input can trigger a heap use-after-free condition during input-method state transitions. Under specific conditions, the library frees an internal input context object but subsequently attempts to write to that freed memory. This issue can cause applications relying on the library to crash, leading to a Denial of Service (DoS), or potentially allow arbitrary code execution. | ||||
| CVE-2026-107121 | 1 Redhat | 2 Build Keycloak, Red Hat Single Sign On | 2026-10-07 | 6.5 Medium |
| A flaw was found in the SMTP email configuration handling of the keycloak-services component. When the STARTTLS option is enabled, Keycloak fails to strictly enforce an encrypted connection, allowing it to fall back to unencrypted communication if the encryption request is tampered with. An attacker who can intercept network traffic can exploit this to capture sensitive email credentials and message content in plain text. | ||||
| CVE-2026-106586 | 1 Openbsd | 1 Openssh | 2026-10-07 | 2.5 Low |
| In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a different vulnerability than CVE-2026-73283. | ||||
| CVE-2026-106584 | 1 Openbsd | 1 Openssh | 2026-10-07 | 2.5 Low |
| In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mishandling. There can be a slightly more severe effect on users in certain Antarctic locations. | ||||
| CVE-2026-106562 | 2026-10-07 | 4.3 Medium | ||
| Backstage is an open framework for building developer portals. Prior to 2.1.6 in @backstage/plugin-search-backend and 1.8.7 in @backstage/plugin-search-backend-module-elasticsearch, search engine permission filtering could return documents denied by policy. An authenticated Backstage user subject to a DENY policy for search document types could receive unauthorized results in deployments with permission.enabled set to true and an Elasticsearch or OpenSearch backend. This issue is fixed in @backstage/plugin-search-backend 2.1.6 and @backstage/plugin-search-backend-module-elasticsearch 1.8.7. | ||||
| CVE-2026-106561 | 2026-10-07 | 5 Medium | ||
| Backstage is an open framework for building developer portals. Prior to 0.21.9, the @backstage/plugin-kubernetes-backend package is affected by sensitive information disclosure in kubernetes resource queries. An authenticated user holding the standard Kubernetes resource read permission could retrieve sensitive values that the Kubernetes plugin is designed to mask, potentially exposing credentials and other confidential material held in the connected clusters. Exposure is limited to resources that the Backstage service account is permitted to read and that match the targeted catalog entity's namespace and label selector. Deployments whose cluster credentials do not grant read access to these resources are unaffected. This issue is fixed in version 0.21.9. | ||||
| CVE-2026-106556 | 2026-10-07 | 7.7 High | ||
| Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by configuration bypass in techdocs mkdocs.yml sanitization. Insufficient validation of MkDocs configuration during TechDocs generation could allow an authenticated user who can register or modify documentation sources to execute arbitrary commands in the build environment. Impact is limited to resources accessible to the TechDocs backend or build container. This issue is fixed in versions 1.14.6 and 1.15.4. | ||||
| CVE-2026-106513 | 1 Misp | 1 Misp \(malware Information Sharing Platform\) | 2026-10-07 | N/A |
| MISP exposes critical infrastructure settings—specifically the Redis host addresses used by the core application, the ZeroMQ plugin, and the SimpleBackgroundJobs plugin—through its web UI and API to site-admin users. The background job workers trust raw Redis job payloads without additional validation. An attacker who obtains a hijacked site-admin session (for example, through a stored cross-site scripting vulnerability) can modify the Redis host settings to point at an attacker-controlled Redis server and then restart the workers. Once the workers connect to the attacker's Redis instance, the attacker can inject malicious job payloads that the workers execute, achieving arbitrary command execution as the worker account. Additionally, the download_attachments_on_load setting, which controls inline attachment rendering, was modifiable through the same interface, allowing a hijacked session to re-enable a feature that could facilitate further client-side attacks. The vulnerability requires site-admin privileges and a prior session-compromise mechanism; it does not require unauthenticated access. The impact is remote code execution in the context of the MISP worker process and potential data exfiltration through the attacker-controlled Redis connection. | ||||
| CVE-2026-106512 | 1 Misp | 1 Sachertortephp \(cakephp-based Misp Application\) | 2026-10-07 | N/A |
| The CakeResponse::download() method in lib/Cake/Network/CakeResponse.php constructs a Content-Disposition header by directly interpolating a caller-supplied filename into a quoted-string value without sanitization. Two distinct injection vectors exist in the unpatched code. First, if the filename contains C0 control characters (CR or LF), PHP refuses to emit the entire Content-Disposition header, silently dropping the attachment disposition. The response body is then served with its own Content-Type (for example text/html for an .html attachment) and renders inline in the browser on the application origin, creating a stored cross-site scripting condition. The commit message notes this is reachable even when the download_attachments_on_load setting is enabled, meaning a victim merely needs to view a page that triggers the download. Second, a double-quote character in the filename terminates the quoted-string value early, permitting injection of additional Content-Disposition parameters. The affected code path covers all callers of CakeResponse::download(), including attribute downloads, proposal downloads, and restSearch exports. An authenticated user who can create or upload an attachment with a crafted filename (for example through MISP attribute naming or proposal attachment naming) can store the malicious filename. When any other authenticated user views the affected page, the unsanitized filename is reflected into the HTTP response header, resulting in header manipulation and potential execution of arbitrary HTML or JavaScript in the context of the application origin. The security impact is equivalent to a stored cross-site scripting vulnerability, allowing session hijacking, data exfiltration, and unauthorized actions on behalf of the victim. | ||||
| CVE-2026-106506 | 1 Backstage | 2 Backstage, Plugin-scaffolder-backend | 2026-10-07 | 5.3 Medium |
| Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list ordering. An authenticated Backstage user with permission to create and read relevant scaffolder tasks may be able to infer confidential task data under specific conditions. Successful exploitation requires retained task secrets, visibility of a target task, knowledge of the secret structure, and repeated requests. This issue is fixed in version 4.1.0. | ||||
| CVE-2026-106504 | 1 Backstage | 2 Backstage, Plugin-scaffolder-backend | 2026-10-07 | 6.5 Medium |
| Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder task logs. An authenticated user who can create and read scaffolder tasks may be able to observe sensitive values in task logs in deployments with restrictive action permissions and affected templates. Exploitation requires a denied action whose input contains such a value. This issue is fixed in version 4.1.0. | ||||
| CVE-2026-106501 | 1 Backstage | 2 Backstage, Plugin-scaffolder-backend | 2026-10-07 | 9.6 Critical |
| Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder. An authenticated Backstage user who can read another user's Scaffolder task may receive internal execution data. In deployments where that data contains credentials for an external service, this may permit disclosure and unauthorized changes in that external service. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0. | ||||
| CVE-2026-106497 | 2026-10-07 | 4.3 Medium | ||
| Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent catalog property permission evaluation. In deployments that use affected value-based catalog permission conditions as a confidentiality boundary, an authenticated user could receive catalog entity data that policy authors intended to restrict. This issue is fixed in version 3.9.1. | ||||
| CVE-2026-106496 | 2026-10-07 | 3.1 Low | ||
| Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host. This issue is fixed in version 3.9.1. | ||||
| CVE-2026-106490 | 2026-10-07 | 6.5 Medium | ||
| Backstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-techdocs-backend package is affected by improper input validation in techdocs static content requests. When using the Azure Blob Storage provider, an authenticated Backstage user may be able to read restricted TechDocs content when entity-level permissions are enabled. Deployments that intentionally disable the default backend authentication policy may have broader exposure. This issue is fixed in version 2.2.4. | ||||
| CVE-2026-106486 | 2026-10-07 | 8.5 High | ||
| Backstage is an open framework for building developer portals. Prior to 0.3.10 in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud and 0.2.25 in @backstage/plugin-scaffolder-backend-module-bitbucket-server, the Bitbucket pull-request Scaffolder actions did not sufficiently validate filesystem paths. An authenticated user who can execute an eligible template and influence an allowed Bitbucket repository could affect paths outside the expected working area, potentially compromising backend confidentiality, integrity, or availability. This issue is fixed in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud 0.3.10 and @backstage/plugin-scaffolder-backend-module-bitbucket-server 0.2.25. | ||||