Export limit exceeded: 401068 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (401068 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-105083 | 1 Imagemagick | 1 Imagemagick | 2026-10-03 | 3.9 Low |
| ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the rest of the file, so no policy rules are applied and restricted operations become allowed. | ||||
| CVE-2026-104433 | 1 Kvcache-ai | 1 Mooncake | 2026-10-03 | 7.5 High |
| Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference server. | ||||
| CVE-2026-12345 | 1 Python | 1 Cpython | 2026-10-03 | 6.3 Medium |
| The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms. | ||||
| CVE-2026-105051 | 2026-10-03 | 1.9 Low | ||
| Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel). | ||||
| CVE-2026-104475 | 1 Idurar | 1 Idurar Erp Crm | 2026-10-03 | 5.4 Medium |
| IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject scripts by uploading unsanitized SVG files. Attackers can upload JavaScript-laden SVGs via the profile update or settings upload endpoints, which execute in victims' browsers when served from the /public route. | ||||
| CVE-2026-105046 | 1 Kentico | 1 Xperience | 2026-10-03 | 4.3 Medium |
| Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints. | ||||
| CVE-2026-51858 | 2026-10-02 | 9.8 Critical | ||
| In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, TerminalToolkit.shell_exec allows prompt-driven shell command execution without an approval boundary. | ||||
| CVE-2026-51899 | 1 Transformeroptimus | 1 Superagi | 2026-10-02 | 4.3 Medium |
| In SuperAGI v0.0.14 and prior, controller endpoints (/api/agents/create, /api/agents/schedule, /api/agents/delete, /api/agents/edit_schedule, /api/agents/stop_schedule) allow authenticated users from one organization to create, schedule, edit, stop, and delete agents belonging to a different organization's project. The endpoints accept a project_id parameter but do not verify that the project belongs to the authenticated user's organization. | ||||
| CVE-2026-67989 | 2026-10-02 | 7.5 High | ||
| crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x | ||||
| CVE-2026-103625 | 1 Google | 1 Chrome | 2026-10-02 | 8.8 High |
| Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-105048 | 2026-10-02 | 4 Medium | ||
| The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses). | ||||
| CVE-2026-84411 | 1 Mikrotik | 1 Routeros | 2026-10-02 | 9.8 Critical |
| The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request. | ||||
| CVE-2026-105049 | 2026-10-02 | 5.8 Medium | ||
| Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet. | ||||
| CVE-2026-105050 | 1 Peazip | 1 Peazip | 2026-10-02 | N/A |
| PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled. | ||||
| CVE-2026-105030 | 2026-10-02 | 5.3 Medium | ||
| Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking visibility filters. Attackers can supply a known or guessed monitor tag to endpoints such as monitor-bar and monitor-latency-chart to obtain names, descriptions, status, uptime history and latency. | ||||
| CVE-2026-105029 | 1 Uvdesk | 1 Community-skeleton | 2026-10-02 | 4.3 Medium |
| UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' tickets. Attackers can supply arbitrary ticket IDs, which are loaded without an ownership check, to submit or change satisfaction ratings on tickets owned by other customers. | ||||
| CVE-2026-104479 | 2026-10-02 | 5.4 Medium | ||
| Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute in the site origin for any visitor viewing the listing. | ||||
| CVE-2026-104478 | 1 Formwork Project | 1 Formwork | 2026-10-02 | 7.1 High |
| Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access files outside the backup directory. | ||||
| CVE-2026-104477 | 1 Showdownjs | 1 Showdown | 2026-10-02 | 6.1 Medium |
| Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown links or images containing a double quote followed by onerror or onmouseover handlers to execute script when victims view rendered HTML. | ||||
| CVE-2026-104476 | 1 Backdropcms | 1 Backdrop | 2026-10-02 | 5.9 Medium |
| Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings. | ||||