Export limit exceeded: 401203 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 401203 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (401203 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-82045 | 1 Utmstack | 1 Utmstack | 2026-10-04 | 6.5 Medium |
| UTMStack before 11.2.16 contains a JPQL injection vulnerability that allows authenticated attackers to read arbitrary entity data by exploiting UtmNetworkScanService.searchPropertyValues(), which builds a JPQL query with String.format() and executes it via em.createQuery() without parameter binding. Attackers can inject malicious JPQL through the value parameter in the GET /api/utm-network-scans/searchPropertyValues endpoint to extract sensitive data including credential tables such as jhi_user. | ||||
| CVE-2026-104055 | 1 Canonical | 1 Postgresql-operator | 2026-10-04 | N/A |
| The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the monitoring user's password in cleartext to its logs. Any actor able to read those logs can recover the password, which grants read-only pg_monitor access to PostgreSQL. This is fixed in the dev track (14/edge) in revisions 1189 (arm64) and 1190 (amd64), and in the stable track (14/stable) in revisions 1216 (arm64) and 1217 (amd64). | ||||
| CVE-2026-93474 | 1 Monta | 1 Monta.app | 2026-10-04 | 6.5 Medium |
| Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | ||||
| CVE-2026-97212 | 1 Monta | 1 Monta.app | 2026-10-04 | 7.3 High |
| The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests. | ||||
| CVE-2026-97363 | 1 Monta | 1 Monta.app | 2026-10-04 | 7.5 High |
| The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access. | ||||
| CVE-2026-105043 | 1 Mathworks | 1 Simulink | 2026-10-04 | 3.6 Low |
| MathWorks Simulink before R2026b, when showing a crafted .slx file, can have blocks that are never visible in the Simulink Editor but will cause code execution. | ||||
| CVE-2026-95102 | 1 Monta | 1 Monta.app | 2026-10-04 | 9.4 Critical |
| WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system. | ||||
| CVE-2026-94594 | 1 Armatura | 2 Armatura One, Armatura One (usa) | 2026-10-04 | 4 Medium |
| Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential. | ||||
| CVE-2026-94593 | 1 Armatura | 2 Armatura One, Armatura One (usa) | 2026-10-04 | 7.8 High |
| Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available. | ||||
| CVE-2026-94592 | 1 Armatura | 2 Armatura One, Armatura One (usa) | 2026-10-04 | 8.4 High |
| Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed. | ||||
| CVE-2026-94591 | 1 Armatura | 2 Armatura One, Armatura One (usa) | 2026-10-04 | 8.4 High |
| Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, and can then decrypt the stored credentials of any specific installation to which the attacker separately obtains the encrypted configuration file. | ||||
| CVE-2026-105048 | 1 Zilliz | 1 Attu | 2026-10-04 | 4 Medium |
| The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses). | ||||
| CVE-2026-105049 | 1 Zilliz | 1 Attu | 2026-10-04 | 5.8 Medium |
| Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet. | ||||
| CVE-2026-105051 | 1 Irdeto | 1 Denuvo Anti-tamper | 2026-10-04 | 1.9 Low |
| Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel). | ||||
| CVE-2026-105029 | 1 Uvdesk | 2 Community-skeleton, Support-center-bundle | 2026-10-04 | 4.3 Medium |
| UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers. | ||||
| CVE-2026-105030 | 1 Rajnandan1 | 1 Kener | 2026-10-04 | 5.3 Medium |
| Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency. | ||||
| CVE-2026-79113 | 1 Aswf | 1 Openapv | 2026-10-04 | N/A |
| OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow. | ||||
| CVE-2026-100152 | 2 Smub, Wordpress-extensions | 2 All In One Seo, All In One Seo | 2026-10-04 | 6.5 Medium |
| The The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.2 This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. This requires the AIOSEO breadcrumb to be rendered on the search results page via the block, widget, shortcode, or template tag. | ||||
| CVE-2025-12828 | 2 Ultrapressorg, Wordpress-extensions | 2 Ultra Addons Lite For Elementor, Ultra Addons Lite For Elementor | 2026-10-04 | 6.4 Medium |
| The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Type Out widget in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-97337 | 2 Wordpress-extensions, Wpinsider-1 | 2 Simple Membership, Simple Membership | 2026-10-04 | 7.5 High |
| The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are dispatched from SwpmInitTimeTasks::check_and_do_email_activation() on frontend init with no authentication, nonce, capability, or ownership check, and the recipient address used by SwpmRegistration::send_reg_email() is taken from an attacker-controlled $_POST['email'] parameter (overriding the member's registered address). This makes it possible for unauthenticated attackers to redirect an arbitrary pending member's activation email — and the follow-up 'registration complete' email containing the member's username and plaintext password — to an attacker-chosen address, and to then activate that member's account without their consent. | ||||