Export limit exceeded: 403768 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (403768 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-107332 1 Aws 1 Aws-toolkit-vscode 2026-10-09 5.5 Medium
Insecure file permissions in the CodeCatalyst connection handler in AWS Toolkit for VS Code before 4.10.0 allowed local users to obtain CodeCatalyst bearer tokens via reading world-readable token cache files. To mitigate this issue, users should upgrade to version 4.10.0 or later.
CVE-2026-106581 1 Docker 1 Desktop 2026-10-09 N/A
Before 4.92.0, Docker Desktop for Windows did not verify the signature of a package supplied to Docker Desktop Installer.exe install -package. An attacker able to provide a crafted package and convince a user to approve the Docker-signed UAC prompt could execute attacker-controlled installer actions as LocalSystem.
CVE-2026-104629 2026-10-09 8.8 High
A component loading mechanism in openPDC and openHistorian will construct and run any specified type, which may be an invalid component to load. An attacker with an authenticated user account and the ability to place a file on the host filesystem can use this to run arbitrary constructor code, and this code runs with the privileges of the affected service account.
CVE-2026-104117 2 Illumos, Omnios 2 Illumos-gate, Omnios 2026-10-09 N/A
A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP multipathing (IPMP) configuration. The ipmgmtd door dispatch table in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c does not require the solaris.network.interface.config authorization for the IPMGMT_CMD_IPMP_UPDATE command, although its handler, ipmgmt_ipmp_update_handler(), writes to the persistent ipadm configuration when the IPMGMT_PERSIST flag is set. An unprivileged local user can therefore add interfaces to, or remove them from, existing IPMP groups in the stored configuration. The running configuration is not changed; the modification takes effect when the stored configuration is next applied, such as at boot, and may disrupt network connectivity. The flaw has existed since 2021 (illumos-gate commit a73be61a), and affects any illumos distribution prior to illumos-gate commit e8d3efa1.
CVE-2026-104116 2 Illumos, Omnios 2 Illumos-gate, Omnios 2026-10-09 N/A
A missing authorization check in the illumos zones statistics daemon (zonestatd) allows a local user in any zone to disrupt zonestat in other zones and to determine which zones are running. The zonestatd door server procedure, zsd_server() in usr/src/cmd/zonestat/zonestatd/zonestatd.c, handles the ZSD_CMD_NEW_ZONE command, which is intended to be sent by zoneadmd, without checking the caller's credentials. Because the zonestatd door is accessible to all users in every zone, an unprivileged user can send this command with an arbitrary zone ID, causing zonestatd to re-create its door file in that zone, so that new zonestat requests in that zone can fail while the file is replaced. The time taken to handle the command also reveals whether a given zone ID belongs to a running zone. The flaw has existed since 2010 (illumos-gate commit efd4c9b6), and affects any illumos distribution prior to illumos-gate commit 865b58d2.
CVE-2026-104114 2 Illumos, Omnios 2 Illumos-gate, Omnios 2026-10-09 N/A
A NULL pointer dereference in the illumos Network Auto-Magic daemon (nwamd) allows a local user to crash the daemon. nwamd_door_switch() in usr/src/cmd/cmd-inet/lib/nwamd/door_if.c writes to the caller's request structure before checking that a request was supplied, and before checking the caller's credentials. Because the nwamd door at /etc/svc/volatile/nwam/nwam_door is accessible to all local users, an unprivileged user can issue a door_call() with no argument data to crash nwamd; repeated calls place the svc:/network/physical:nwam service into maintenance, stopping automatic network configuration. nwamd runs only when svc:/network/physical:nwam is enabled, which is not the default. The flaw has existed since 2010 (illumos-gate commit 6ba597c5), and affects any illumos distribution prior to illumos-gate commit 0f1064d9.
CVE-2026-104113 1 Omnios 1 Omnios 2026-10-09 N/A
A double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS allows a local user to crash the daemon. When authorizing a door request that modifies interface configuration, ipmgmt_handler() in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c frees the caller's credential with ucred_free() immediately after reading the user ID, and frees it a second time on the error path if the authorization check fails. An unprivileged local user who does not hold the solaris.network.interface.config authorization can send such a request, for example IPMGMT_CMD_RESETIF, to the ipmgmtd door, causing ipmgmtd to abort; repeated requests place the svc:/network/ip-interface-management service into maintenance, preventing IP interface configuration. The early free was introduced in 2014 to support lx-branded zones (OmniOS commit 4c170900) and is not present in upstream illumos-gate. It affects OmniOS r151020 and later, and SmartOS, prior to the fix.
CVE-2026-104112 2 Illumos, Omnios 2 Illumos-gate, Omnios 2026-10-09 N/A
A missing release of resources in the illumos name service cache daemon (nscd) allows a local user to exhaust kernel memory. The nscd door server procedure, switcher() in usr/src/cmd/nscd/nscd_frontend.c, does not close file descriptors that are passed with a door call but not used by the request, and the main nscd door at /var/run/name_service_door accepts passed descriptors from any user in its zone. Because nscd also runs with an unlimited file descriptor limit, an unprivileged local user, including one in a non-global zone, can repeatedly pass a descriptor to its zone's nscd in a door_call() loop, causing the file descriptor table of nscd to grow without bound in kernel memory. This causes a denial of service of nscd and can render processes in all zones on the host unresponsive. The flaw has existed since 2006 (illumos-gate commit cb5caa98), and affects any illumos distribution prior to illumos-gate commit af810a72.
CVE-2026-103220 1 Canva 1 Affinity 2026-10-09 4.5 Medium
The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing raster image data in Affinity document files, leading to an out-of-bounds read and the dereference of an untrusted pointer. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could result in memory corruption or an application crash.
CVE-2026-102916 2 Illumos, Omnios 2 Illumos-gate, Omnios 2026-10-09 N/A
A reachable assertion in the illumos bhyve instruction emulator allows a guest to panic the host. When emulating a REP-prefixed MOVS or STOS instruction that accesses guest MMIO, vie_emulate_movs() and vie_emulate_stos() in usr/src/uts/intel/io/vmm/vmm_instruction_emul.c do not clear the VIES_REPEAT status flag on the final iteration. For MMIO regions emulated in the kernel (the local APIC, I/O APIC and HPET), the stale flag causes a VERIFY assertion in vie_advance_pc() to fail, and the host panics. A privileged user within a guest VM can issue a REP MOVS or REP STOS instruction against the local APIC page to cause a denial of service of the host and every other guest running on it. The flaw has existed since 2020 (illumos-gate commit e0c0d44e), and affects any illumos distribution prior to illumos-gate commit 696ecf8d.
CVE-2026-101130 1 Canva 1 Affinity 2026-10-09 3.6 Low
The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing arrays of strings in Affinity document files, leading to a heap buffer over-read. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could disclose the contents of adjacent heap memory in the document's text or result in an application crash.
CVE-2026-101094 1 Canva 1 Affinity 2026-10-09 3.6 Low
The Affinity by Canva application before 3.3.1 (October 2026 release) did not correctly handle incomplete UTF-8 character sequences when parsing text in Affinity document files, leading to a heap buffer over-read. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could disclose the contents of adjacent heap memory in the document's text or result in an application crash.
CVE-2026-101022 2026-10-09 4.3 Medium
A Modbus connection feature on openPDC accepts a caller-specified destination address and port with no restriction on which internal hosts may be targeted. An authenticated user can attempt connections to arbitrary internal network destinations, revealing which destinations are reachable. With repeated attempts, an attacker may be able to map the internal network.
CVE-2025-7872 1 Portabilis 1 I-diario 2026-10-09 3.5 Low
A weakness has been identified in Portabilis i-Diario 1.5.0. This affects an unknown function of the file /justificativas-de-falta. Executing a manipulation of the argument Justificativa can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. This patch is called 821342cd8d952e8bd214cb16145da785a92f5681. Applying a patch is advised to resolve this issue. The vendor confirms: "Audited values shown on that screen are now sanitized on output".
CVE-2025-7871 1 Portabilis 1 I-diario 2026-10-09 3.5 Low
A security flaw has been discovered in Portabilis i-Diario 1.5.0. The impacted element is an unknown function of the file /conteudos. Performing a manipulation of the argument filter[by_description] results in cross site scripting. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The patch is named d076c112b45e3b3e41cbe11de27949b491d922c2. It is recommended to apply a patch to fix this issue. The vendor confirms: "The searched term is now rendered escaped in the autocomplete widget, and the content tags are rendered through output-escaped templates, so an injected payload is displayed as inert text instead of being executed."
CVE-2025-7870 1 Portabilis 1 I-diario 2026-10-09 3.5 Low
A vulnerability was identified in Portabilis i-Diario 1.5.0. The affected element is an unknown function of the file app/uploaders/doc_uploader.rb of the component justificativas-de-falta Endpoint. Such manipulation of the argument Anexo leads to cross site scripting. The attack can be launched remotely. The exploit is publicly available and might be used. The name of the patch is 6c529bb2d96130aa29533f49e204e86518e11fdd. It is best practice to apply a patch to resolve this issue. The vendor confirms: "The attachment uploader now rejects files whose declared content type indicates executable or markup content".
CVE-2026-93548 2026-10-09 8.8 High
The FooSales WordPress plugin before 1.43.3 does not verify that an authenticated caller is entitled to act as the user a request names, allowing any authenticated user to have the FooSales WordPress plugin before 1.43.3 act as an arbitrary other user, including an administrator, resulting in that user's account details being exposed and their account being taken over.
CVE-2026-87846 2026-10-09 5.3 Medium
The Shipping for Nova Poshta WordPress plugin through 1.19.8 does not perform any authorisation, nonce or ownership checks on one of its AJAX actions available to unauthenticated users, allowing anyone to delete the shipment records of arbitrary orders and to make the store issue the carrier's waybill-deletion request for those orders using the store's own stored API credentials.
CVE-2026-107804 1 0xjacky 1 Nginx-ui 2026-10-09 5.3 Medium
Nginx UI is a web user interface for the Nginx web server. From 2.2.0 until 2.6.0, the bundled reverse proxy does not preserve the external client identity used by Gin because the backend has no trusted proxy configuration. Management requests can be attributed to loopback and pass the IP allowlist loopback exception, although valid credentials are still required. Failed logins from different external clients are also attributed to the same loopback address, allowing an unauthenticated attacker to trigger a shared temporary login ban for password or OTP authentication without invalidating existing sessions. This issue is fixed in version 2.6.0.
CVE-2026-20588 2 Mediatek, Mediatek, Inc. 51 Mt2718, Mt2718 Firmware, Mt6768 and 48 more 2026-10-09 6.7 Medium
In mtee, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9607.