Export limit exceeded: 402043 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402043 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-48005 | 2 Apache, Redhat | 3 Apache Http Server, Http Server, Hummingbird | 2026-10-02 | 7.5 High |
| Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck . Users are recommended to upgrade to version 2.4.69, which fixes this issue. | ||||
| CVE-2026-90454 | 1 Cisagov | 1 Malcolm | 2026-10-02 | 4.3 Medium |
| A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, and the proxy configuration otherwise permits the request method those routes use. This allows an authenticated user on a deployment intended to be read-only to add or remove tags on stored session records. | ||||
| CVE-2026-56153 | 2 Apache, Redhat | 2 Http Server, Hummingbird | 2026-10-02 | 7.5 High |
| Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | ||||
| CVE-2026-90455 | 1 Cisagov | 1 Malcolm | 2026-10-02 | 3.7 Low |
| A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a single fixed, trusted vendor URL at initialization and does not process attacker-controlled input through the library, limiting practical exploitability of the reintroduced version in this context. | ||||
| CVE-2026-100255 | 1 Jetbrains | 1 Teamcity | 2026-10-02 | 8.1 High |
| In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset | ||||
| CVE-2026-90456 | 1 Cisagov | 1 Malcolm | 2026-10-02 | 8.1 High |
| An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value. | ||||
| CVE-2026-100256 | 1 Jetbrains | 1 Intellij Idea | 2026-10-02 | 7.8 High |
| In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects | ||||
| CVE-2026-98162 | 1 Linux | 1 Linux Kernel | 2026-10-02 | 5.5 Medium |
| In the Linux kernel, the following vulnerability has been resolved: smb/server: fix tree connection leak in smb2_tree_connect() See the procedure below: smb2_tree_connect ksmbd_tree_conn_connect xa_store(&sess->tree_conns, tree_conn->id, tree_conn) ksmbd_counter_inc(KSMBD_COUNTER_TREE_CONNS) ksmbd_share_tree_conn_inc(sc) ksmbd_iov_pin_rsp // fail status.ret = KSMBD_TREE_CONN_STATUS_NOMEM // do not disconnect tree_conn Disconnect the new tree connection if ksmbd_iov_pin_rsp() fails. | ||||
| CVE-2026-90457 | 1 Cisagov | 1 Malcolm | 2026-10-02 | 6.2 Medium |
| The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissions allowing it to be read by any local user. This is inconsistent with a separate, stronger hashing algorithm used for the same password on another authentication path. A party able to read this file, including a local user or a party with access to a configuration backup, could feasibly recover the underlying password through offline computation, compromising the administrative credential across every path that accepts it. | ||||
| CVE-2026-100257 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export | ||||
| CVE-2026-100258 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings | ||||
| CVE-2026-100259 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access | ||||
| CVE-2026-100260 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 5.3 Medium |
| In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset | ||||
| CVE-2026-63177 | 1 Cisagov | 1 Malcolm | 2026-10-02 | 7.1 High |
| Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while Nginx itself routes requests using the normalized path. An authenticated low-privilege user can prepend a traversal segment (for example `/x/../upload/...`) so that Nginx routes the request to a restricted backend while the Lua role check fails to match any rule and falls open, granting access it should deny. Version 26.07.0 fixes the issue. | ||||
| CVE-2026-100261 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 5.4 Medium |
| In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission | ||||
| CVE-2026-100262 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 7.6 High |
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates | ||||
| CVE-2026-63134 | 1 Cisagov | 1 Malcolm | 2026-10-02 | 5.4 Medium |
| Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags, but creates directory entries with a raw `os.makedirs(os.path.join(dest, entry.pathname))` that has no traversal protection. An uploaded malicious archive containing a directory entry with a `../` sequence or an absolute path causes the filebeat processing container to create directories outside the intended extraction directory. Version 26.07.0 fixes the issue. | ||||
| CVE-2026-100263 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 4.7 Medium |
| In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible | ||||
| CVE-2026-55676 | 1 Cisagov | 1 Malcolm | 2026-10-02 | 8.8 High |
| Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array by default (`file-upload/php/config.php:16`), so the type check is a no-op and every extension is accepted. The filename sanitizer keeps the `.php` extension intact. Committed files land in `/var/www/upload/server/php/files` (`file-upload/php/config.php:7`), and the component's nginx routes any URL ending in `.php` to php-fpm. An authenticated `GET /server/php/files/<name>.php` then executes the uploaded code as `www-data`. Prior to version 26.06.1, in RBAC mode, the upload endpoint is reachable by the granular `ROLE_UPLOAD` role (`nginx/lua/nginx_auth_helpers.lua:71`), a role intended only for submitting capture files. As a result, a user holding the upload-only role runs arbitrary PHP as `www-data` inside the file-upload container. Version 26.06.1 fixes the issue. | ||||
| CVE-2026-92899 | 1 Apache | 1 Wss4j | 2026-10-02 | 4.8 Medium |
| Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. | ||||