Export limit exceeded: 402906 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402906 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-89430 | 1 Gitea | 1 Gitea | 2026-10-07 | N/A |
| Gitea validated a push mirror's remote address against the `[migrations]` allow and block lists only when the mirror was created. Each synchronization passed the stored address directly to `git push`, so a name that later resolved to a blocked or internal address was still reached. A user with administrator access to a repository, which includes repositories they create themselves, could aim push mirror synchronization at internal Git services and force-push the repository's contents to them. | ||||
| CVE-2026-94205 | 1 Gitea | 1 Gitea | 2026-10-07 | N/A |
| Gitea Actions decided whether a fork pull request run needed approval based on the user who triggered the event rather than the pull request author. For `pull_request` activity triggered by a maintainer during ordinary triage, such as adding a label, the run was created without requiring approval, while the workflow definition was still taken from the fork head. Where Actions is enabled and a matching runner is registered, fork-controlled workflow code could run on the base repository's runners without an explicit approval. | ||||
| CVE-2026-95112 | 1 Gitea | 1 Gitea | 2026-10-07 | N/A |
| When processing issue and comment bodies, Gitea scanned the entire preceding text for action keywords such as "closes" or "fixes" once per Markdown link, giving processing time quadratic in the input size. An authenticated user able to submit issue or comment content could send a crafted body of about 1 MB that keeps a CPU core busy for several minutes while holding a database transaction open. | ||||
| CVE-2026-96399 | 1 Gitea | 1 Gitea | 2026-10-07 | N/A |
| A repository's external issue tracker regular expression containing alternating capture groups could produce invalid slice indexes when Gitea rendered issue references, causing a runtime panic that terminated the Gitea process. A user who can edit a repository's external issue tracker settings could make any later rendering of matching content, such as viewing a README, crash the instance for all users. | ||||
| CVE-2026-106334 | 1 Google | 1 Chrome | 2026-10-07 | 8.8 High |
| Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106455 | 2026-10-07 | 7.7 High | ||
| Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs plugin configuration in techdocs. An authenticated attacker with control over a TechDocs source repository could cause a documentation build to retrieve and publish data from network locations reachable by the build environment. Exposure depends on deployment topology, build mode, and target endpoint protections. Modern cloud metadata services that require tokens or special headers are not directly accessible through the affected behavior. This issue is fixed in @backstage/plugin-techdocs-node versions 1.14.7 and 1.15.5. | ||||
| CVE-2026-106555 | 1 Openbsd | 1 Openssh | 2026-10-07 | 2.2 Low |
| In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication attempts. | ||||
| CVE-2026-106584 | 1 Openbsd | 1 Openssh | 2026-10-07 | 2.5 Low |
| In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mishandling. There can be a slightly more severe effect on users in certain Antarctic locations. | ||||
| CVE-2026-106494 | 2026-10-07 | 4.4 Medium | ||
| Backstage is an open framework for building developer portals. Prior to 0.17.8, the @backstage/backend-defaults package is affected by improper input validation in cloud storage url readers. An attacker with write access to a cloud storage bucket used by Backstage could craft object names that could collide with protected files in the output directory. In certain deployment configurations, this could lead to content injection. This issue is fixed in version 0.17.8. | ||||
| CVE-2026-106443 | 1 Kozea | 1 Weasyprint | 2026-10-07 | 8.8 High |
| WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to Pillow's generic image dispatcher without excluding EPS or PostScript formats. On hosts with Ghostscript installed, Pillow EpsImagePlugin invokes the interpreter for attacker-controlled PostScript, which can produce interpreter-permitted effects and can lead to remote code execution when the installed Ghostscript version has a usable sandbox bypass. Hosts without Ghostscript do not reach this rasterization path. This issue is fixed in version 70.0. | ||||
| CVE-2026-76750 | 1 Hewlett Packard Enterprise (hpe) | 1 Clearpass Policy Manager (cppm) | 2026-10-07 | 9.8 Critical |
| Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code on the affected system. | ||||
| CVE-2026-76751 | 1 Hewlett Packard Enterprise (hpe) | 1 Clearpass Policy Manager (cppm) | 2026-10-07 | 9.8 Critical |
| A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an unauthenticated, remote attacker to execute arbitrary code on the affected endpoint with the elevated privileges of the agent. | ||||
| CVE-2026-76752 | 1 Hewlett Packard Enterprise (hpe) | 1 Clearpass Policy Manager (cppm) | 2026-10-07 | 9.8 Critical |
| Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to circumvent existing authentication controls and gain administrative access to the affected system. | ||||
| CVE-2026-76753 | 1 Hewlett Packard Enterprise (hpe) | 1 Clearpass Policy Manager (cppm) | 2026-10-07 | 9.8 Critical |
| A format string vulnerability in an affected service interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to corrupt process memory. Successful exploitation could allow an attacker to execute arbitrary code. | ||||
| CVE-2026-106552 | 1 Openbsd | 1 Openssh | 2026-10-07 | 4.2 Medium |
| In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation. | ||||
| CVE-2026-106460 | 2026-10-07 | 6.8 Medium | ||
| Backstage is an open framework for building developer portals. From 0.3.0 until 0.6.15 and 0.7.5, the @backstage/plugin-auth-node package did not consistently honor explicit negative email verification during shared OAuth profile normalization. The affected paths include a selected profile email marked verified: false, a matching raw provider email marked email_verified: false, and an email obtained only from an ID token marked email_verified: false. Exploitation requires an admitted identity-provider user who can supply or change an unverified email and a deployment that uses the selected profile email to resolve catalog identities. The verification metadata must apply to the selected email; an absent email_verified claim alone is not affected. In an affected configuration, the user may assume another catalog identity and obtain its associated access and permissions. This issue is fixed in versions 0.6.15 and 0.7.5. | ||||
| CVE-2026-106492 | 2026-10-07 | 7.6 High | ||
| Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @backstage/backend-defaults package is affected by improper preservation of access restrictions during service credential delegation. An external service credential configured with access restrictions (e.g., read-only) could bypass those restrictions by routing requests through plugin delegation paths. This could allow a restricted service to perform operations beyond its intended scope, including write operations on plugins it was restricted to read-only access for. This issue is fixed in versions 0.16.1 and 0.17.8. | ||||
| CVE-2026-106585 | 1 Openbsd | 1 Openssh | 2026-10-07 | 6.5 Medium |
| In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed data. | ||||
| CVE-2026-106586 | 1 Openbsd | 1 Openssh | 2026-10-07 | 2.5 Low |
| In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a different vulnerability than CVE-2026-73283. | ||||
| CVE-2026-70357 | 1 Gitea | 1 Gitea | 2026-10-07 | N/A |
| Gitea validates a repository migration hostname against its network allow and block lists before invoking Git, but the Git subprocess independently resolves the hostname when connecting. An attacker who can start a migration and control the destination's DNS can change the address between validation and connection to reach a blocked internal address. The affected path is the Git clone operation; validation in the migration HTTP client's dialer does not protect the independently connecting Git subprocess. | ||||