Search

Search Results (396937 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-93307 1 O-ran-sc 1 Smo Oam 2026-09-23 4.3 Medium
A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector. Such manipulation of the argument additionalFields.padding leads to uncontrolled memory allocation. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through a bug report but has not responded yet.
CVE-2026-91775 1 Limesurvey 1 Limesurvey 2026-09-23 N/A
LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface.
CVE-2026-88832 1 Redhat 1 Hummingbird 2026-09-23 7.3 High
BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.
CVE-2026-19267 1 Ibm 1 Financial Transaction Manager Ftmfor Redhat Openshift 2026-09-23 6.2 Medium
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions.
CVE-2026-78579 1 Okta 1 Access Gateway 2026-09-23 6.8 Medium
The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP datastore configuration. The raw values are substituted directly into the filter string and passed to the LDAP search operation, resulting in modification of the intended query logic.
CVE-2026-18505 1 Ibm 1 Financial Transaction Manager Ftmfor Redhat Openshift 2026-09-23 5.4 Medium
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated `Host` header to redirect authenticated operators to attacker-controlled sites, enabling credential phishing.
CVE-2026-18180 1 Ibm 1 Financial Transaction Manager Ftmfor Redhat Openshift 2026-09-23 6.5 Medium
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to SQL injection.
CVE-2026-93618 2026-09-23 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetTricks allows Stored XSS. This issue affects JetTricks: from n/a through 2.0.1.
CVE-2026-96656 1 Plex 1 Media Server 2026-09-23 7.2 High
Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The preference TranscoderH264Options is appended verbatim to x264's option string on every transcode. At startup, all .so files are run without signature, execute bit, or symbol checks.
CVE-2026-95593 2026-09-23 7.6 High
Editor SQL Injection in Ultimeter <= 3.0.8 versions.
CVE-2026-95525 2026-09-23 6.5 Medium
Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.
CVE-2026-95514 2026-09-23 5.3 Medium
Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions.
CVE-2026-94684 2026-09-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 versions.
CVE-2026-94680 2026-09-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.
CVE-2026-94679 2026-09-23 5.4 Medium
Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.
CVE-2026-94500 2026-09-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions.
CVE-2026-94487 2026-09-23 8.1 High
Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Capabilities <= 2.50.1 versions.
CVE-2026-94461 2026-09-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions.
CVE-2026-94391 2026-09-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions.
CVE-2026-94176 2026-09-23 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions.