Search

Search Results (400182 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-102827 1 Steveukx 1 Git-js 2026-09-29 8.1 High
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares parsed option names with literal dangerous option spellings while Git accepts unambiguous long-option abbreviations. Attacker-influenced push arguments such as abbreviated --receive-pack or --exec forms can therefore bypass detectVulnerableFlags, reach git push against a local or file remote or an attacker-influenced receive-pack target, and cause Git to invoke an attacker-selected command in consumers that expose those arguments. The clone-side abbreviation handling does not protect the push path. This issue is fixed in 4.0.0.
CVE-2026-15278 2026-09-29 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-96878 1 Wikimedia 1 Mediawiki-cargo Extension 2026-09-29 N/A
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.
CVE-2026-96877 1 Wikimedia 1 Mediawiki-cargo Extension 2026-09-29 N/A
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.
CVE-2026-96874 1 Wikimedia 1 Mediawiki-cargo Extension 2026-09-29 N/A
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in the Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.
CVE-2026-95314 1 Google 1 Chrome 2026-09-29 N/A
Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-102304 1 Google 1 Chrome 2026-09-29 9.6 Critical
Use after free in Passwords in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-102301 1 Google 1 Chrome 2026-09-29 8.3 High
Out of bounds write in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-76227 1 Renovatebot 1 Renovate 2026-09-29 5.5 Medium
Renovate versions from 42.68.1 before 42.96.3 and from 43.0.0 before 43.4.4, including the renovate/renovate Docker images, and Mend Renovate CE/EE images (renovate-ce, renovate-ee-server, renovate-ee-worker) from 13.3.0 before 13.6.0, fail to restrict environment variables to an allowlist when spawning child processes. As a result, child processes (e.g. npm install, postUpgradeTasks, postUpdateOptions) gain full access to all environment variables of the Renovate process, allowing insider or outside attackers to exfiltrate secrets accessible to the Renovate deployment.
CVE-2026-76226 1 Renovatebot 1 Renovate 2026-09-29 6.3 Medium
Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance. Attackers can execute arbitrary code by providing malicious dependencies that are referenced in bazel mod deps calls, such as within ctx.execute statements.
CVE-2024-58376 1 Renovatebot 1 Renovate 2026-09-29 6.7 Medium
Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands. Attackers can manipulate registryAliases keys with unquoted shell metacharacters to inject commands executed during helm repo add operations, gaining full access to Renovate's execution environment.
CVE-2026-102719 2026-09-29 N/A
Predictable DTLS HelloVerifyRequest Cookie in NetX Secure
CVE-2026-102721 2026-09-29 N/A
A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229, 1521, 1984). When the opcode is NX_TFTP_CODE_ERROR the message string is copied with a loop whose only limits are the destination buffer and a NUL byte: ```c /* addons/tftp/nxd_tftp_client.c:1769 */ for (i = 0; (i < (sizeof(tftp_client_ptr -> nx_tftp_client_error_string) - 1)) && (*buffer_ptr); i++) ``` Nothing compares `buffer_ptr` against `nx_packet_append_ptr`. An ERROR packet that carries no terminating NUL, which a server controls completely, walks the loop off the end of the packet until it happens to meet a zero byte or fills the 64 byte destination. ``` ERROR: AddressSanitizer: heap-buffer-overflow READ of size 1 at 0x60d0000000c8 thread T4 #0 _nxd_tftp_client_file_read addons/tftp/nxd_tftp_client.c:1769 0x60d0000000c8 is 0 bytes to the right of 136-byte region ``` The open path has the same loop at :1327 and reports the same way. What is read lands in `nx_tftp_client_error_string`, which the application is expected to display or log, so adjacent packet pool memory ends up in whatever the device does with the error text. Add `(buffer_ptr < packet_ptr -> nx_packet_append_ptr)` to the loop condition in all three paths.
CVE-2026-102722 2026-09-29 N/A
In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and the non-zero values, thus a malicious server can name any address and direct the Client there.
CVE-2026-102724 2026-09-29 N/A
NULL Pointer Dereference When Evicting the Sole MSRP Attribute
CVE-2026-102725 2026-09-29 N/A
Out-of-bounds Read from Unvalidated MSRP Attribute List Length
CVE-2026-102729 2026-09-29 N/A
`gx_binres_theme_load()` sizes its theme buffer for the theme it was asked for, and allocates it even when the resource holds no theme with that id. A theme id at or past the theme count declared by the resource gets a buffer of zero bytes. The load pass then walks past the end of the theme table, takes whatever follows as a theme header, and writes a `GX_THEME` and its tables into that zero-byte buffer.
CVE-2026-102730 2026-09-29 N/A
Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, giving a demonstrated control-flow hijack — RIP set to a full 8-byte attacker-chosen value (register-verified). Two accompanying OOB reads. All reproduced verbatim under ASan at HEAD `9f1cfdc`. (The affected metadata-parser header states "Some portions generated by Copilot (Sonnet 4.6)" — an AI-generated parser with an unchecked on-flash count.)
CVE-2026-76721 2026-09-29 9.8 Critical
Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.
CVE-2026-76722 2026-09-29 9.8 Critical
Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution.