Export limit exceeded: 401337 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (401337 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104401 | 2026-10-05 | 4.3 Medium | ||
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Retrieve Embedded Sensitive Data.This issue affects Memberful - Membership Plugin: from n/a through 1.81.2. | ||||
| CVE-2026-104806 | 2026-10-05 | N/A | ||
| DigitalCanion has discovered a path traversal vulnerability that allows an attacker to access files outside of the intended directory. The specific flaw exists within the Maintenance → System Logs functionality of the web management portal listening on TCP port 443. The application fails to properly validate user-supplied file paths, allowing an attacker to manipulate the requested path and traverse the underlying directory structure. By exploiting this vulnerability, an attacker can access and download files located outside the intended system logs directory, including potentially sensitive system and application files. | ||||
| CVE-2026-100103 | 2026-10-05 | N/A | ||
| Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to arbitrary code execution and compromise of the connected P4 Server. | ||||
| CVE-2026-104706 | 2026-10-05 | N/A | ||
| DigitalCanion has discovered a path traversal vulnerability that allows to view or download sensitive system files over the portal https://<ip>:8443 via menus Administration -> View Logs | ||||
| CVE-2026-105253 | 1 Itsourcecode | 1 Online Admission System Project | 2026-10-05 | 7.3 High |
| A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. | ||||
| CVE-2026-104400 | 2026-10-05 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a through 2.1.8. | ||||
| CVE-2026-104409 | 2026-10-05 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Stored XSS.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.13. | ||||
| CVE-2026-105251 | 1 Vgmstream | 1 Vgmstream | 2026-10-05 | 6.3 Medium |
| A vulnerability was detected in vgmstream up to r2117. Affected by this vulnerability is the function ps_find_padding of the file src/coding/psx_decoder.c of the component VAG File Handler. Performing a manipulation results in out-of-bounds read. The attack is possible to be carried out remotely. The patch is named 4b8316652a30d40f99ad43310bed273fd1f8a7a3. It is suggested to install a patch to address this issue. | ||||
| CVE-2026-105301 | 1 Redhat | 2 Build Keycloak, Red Hat Single Sign On | 2026-10-05 | 4 Medium |
| A flaw was found in the X.509 client-certificate authenticator of Keycloak, a solution for identity and access management. The issue occurs when the server is configured to check certificate revocation using CRL Distribution Points or OCSP. An attacker can provide a specially crafted certificate that points to a malicious server, causing Keycloak to make unauthorized outbound requests to internal or external endpoints before the certificate is fully validated. This can lead to a blind server-side request forgery (SSRF) attack. | ||||
| CVE-2026-105302 | 1 Redhat | 2 Build Keycloak, Red Hat Single Sign On | 2026-10-05 | 5.7 Medium |
| A flaw was found in the User Session Note mapper of the Keycloak identity and access management solution. The issue occurs because the mapper does not validate whether a requested session note contains sensitive internal credentials, such as federated access tokens from external identity providers. This allows a delegated client administrator to leak a user's upstream bearer tokens into the tokens issued to their managed application, potentially leading to unauthorized access to the user's data on external platforms. | ||||
| CVE-2026-105250 | 1 Vgmstream | 1 Vgmstream | 2026-10-05 | 4.3 Medium |
| A security vulnerability has been detected in vgmstream up to r2117. Affected is the function decode_ms_ima of the file src/coding/ima_decoder.c of the component Microsoft IMA Decoder. Such manipulation leads to divide by zero. The attack can be executed remotely. | ||||
| CVE-2026-105249 | 1 Vgmstream | 1 Vgmstream | 2026-10-05 | 4.8 Medium |
| A weakness has been identified in vgmstream up to r2117. This impacts the function make_group_random of the file src/meta/txtp_process.c of the component TXTP File Handler. This manipulation causes use after free. The attack needs to be launched locally. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is recommended to apply a patch to fix this issue. | ||||
| CVE-2026-105306 | 1 Redhat | 2 Build Keycloak, Red Hat Single Sign On | 2026-10-05 | 6.5 Medium |
| A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server. The issue occurs because the registration process fails to filter security-sensitive client attributes when a new client is created. An attacker with a valid Initial Access Token can register a client that bypasses audience checks during token introspection. This allows the attacker to view sensitive identity information, roles, and session details from access tokens belonging to other applications in the same realm. | ||||
| CVE-2026-105248 | 1 Vgmstream | 1 Vgmstream | 2026-10-05 | 6.3 Medium |
| A security flaw has been discovered in vgmstream up to r2117. This affects the function parse_params/txtp_parse of the file src/meta/txtp_parser.c of the component TXTP File Handler. The manipulation results in out-of-bounds write. The attack may be launched remotely. The patch is identified as 4669d37a6af94866f6f0628678f9f90d46954e8b. It is best practice to apply a patch to resolve this issue. | ||||
| CVE-2025-32220 | 1 Salonbookingsystem | 1 Salon Booking System | 2026-10-05 | 5.4 Medium |
| Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through 10.31.9. | ||||
| CVE-2026-81793 | 2 Dimitri Grassi, Wordpress | 2 Salon Booking System, Wordpress | 2026-10-05 | 6.5 Medium |
| Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through 10.31.9. | ||||
| CVE-2026-105247 | 1 Sourcecodester | 1 Online Reviewer Management System | 2026-10-05 | 7.3 High |
| A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/Subject/btn_functions.php?action=course. Executing a manipulation of the argument Subject can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. | ||||
| CVE-2026-19954 | 2026-10-05 | N/A | ||
| Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names. pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by "cole" encodes to "xn--cole-pka" rather than "xn--cole-9oa". The Net::Whois::Raw library modules are not affected. | ||||
| CVE-2026-105246 | 1 Sourcecodester | 1 Online Reviewer Management System | 2026-10-05 | 7.3 High |
| A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/Subject/btn_functions.php?action=update. Performing a manipulation of the argument Subject results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. | ||||
| CVE-2026-105245 | 1 Sgl-project | 1 Sglang | 2026-10-05 | 3.7 Low |
| A vulnerability has been found in sgl-project sglang up to 0.5.21. This issue affects the function server_info of the file python/sglang/srt/entrypoints/http_server.py of the component HTTP Endpoint. Such manipulation of the argument api_key leads to cleartext transmission of sensitive information. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. | ||||