Export limit exceeded: 384564 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 384564 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 384564 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 384564 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 384564 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (384564 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-51619 1 Totolink 1 T6 2026-08-28 N/A
Incorrect access control in the getOnlineClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain online client information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51620 1 Totolink 1 T6 2026-08-28 N/A
Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain network topology and interface configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51621 1 Totolink 1 T6 2026-08-28 N/A
Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive device configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51622 1 Totolink 1 T6 2026-08-28 N/A
Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN configuration data via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51624 1 Totolink 1 T6 2026-08-28 N/A
Incorrect access control in the getStationMacByIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain a client MAC address via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-51626 1 Totolink 1 T6 2026-08-28 N/A
Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WPS configuration, including the current PIN, via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
CVE-2026-3686 1 Ibm 1 Cloud Pak For Data System 2026-08-28 6.2 Medium
IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 is vulnerable to a denial of service due to improper limitation of resources.
CVE-2026-19295 1 Ibm 1 Langflow Oss 2026-08-28 9.9 Critical
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control.
CVE-2026-19294 1 Ibm 1 Langflow Oss 2026-08-28 6.4 Medium
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user's private flow due to improper authorization.
CVE-2026-19286 1 Ibm 1 Langflow Oss 2026-08-28 9.8 Critical
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.
CVE-2026-18904 1 Ibm 1 Langflow Oss 2026-08-28 8.2 High
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.
CVE-2026-18899 1 Ibm 1 Langflow Oss 2026-08-28 7.5 High
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.
CVE-2026-18891 1 Ibm 1 Langflow Oss 2026-08-28 8.2 High
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.
CVE-2026-18729 1 Ibm 1 Langflow Oss 2026-08-28 8.8 High
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
CVE-2026-18545 1 Ibm 1 Langflow Oss 2026-08-28 4.3 Medium
IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
CVE-2026-18527 1 Ibm 1 Administration Runtime Expert For I 2026-08-28 9.9 Critical
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.
CVE-2026-71110 1 Oracle 1 Helidon 2026-08-28 8.1 High
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.18, 3.0.0-3.2.17 and 4.0.0-4.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
CVE-2026-50980 2026-08-28 N/A
Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via a crafted DNS TXT record
CVE-2026-51376 2026-08-28 N/A
An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause a denial of service via an unauthenticated MESSAGE packet into the mesh gossip cache
CVE-2026-51613 1 Totolink 1 T6 2026-08-28 N/A
Incorrect access control in the getDeviceInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain device identification details via sending a crafted POST request to /cgi-bin/cstecgi.cgi.