Export limit exceeded: 398959 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 398959 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (398959 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100622 | 1 Cap-go | 1 Cap-go | 2026-09-28 | 7.5 High |
| capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from the public file read endpoint. Unauthenticated attackers can download deleted bundles using cached URLs and trigger restoration of deleted objects into R2 storage on cache hits. | ||||
| CVE-2026-100618 | 1 Cap-go | 1 Cap-go | 2026-09-28 | 8.5 High |
| Capgo (capgo.app) is affected by an authorization flaw in the app icon update path. The PUT /app/:id endpoint accepts a user-controlled `icon` value, normalizes it, and stores it in public.apps.icon_url without verifying that the image path belongs to the target app's own image namespace (e.g. org/{owner_org}/{app_id}/...). Updating apps.icon_url fires the on_app_update trigger, whose worker reads record.icon_url and calls cleanStoredImageMetadata(), which runs with service-role credentials (supabaseAdmin()) and downloads and re-uploads the referenced storage object with upsert: true. As a result, an authenticated holder of an app-limited write API key can cause the privileged worker to rewrite an out-of-scope private image object (for example an organization logo) that the key cannot read or write directly under Supabase Storage RLS. All versions are affected; no patched version was available at the time of the advisory. | ||||
| CVE-2026-100614 | 1 Cap-go | 1 Cap-go | 2026-09-28 | 8.8 High |
| Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image object keys from mutable database rows without validating ownership. An authenticated attacker can place a victim tenant's image key in a row they control, causing the service-role worker to download and re-upload that object with sanitized metadata. Attackers can silently modify metadata in cross-tenant image objects by supplying known victim keys during authorized row updates, bypassing storage access controls through the confused-deputy metadata worker. | ||||
| CVE-2026-100610 | 1 Flowiseai | 1 Flowise | 2026-09-28 | 7.5 High |
| Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history without route-level permission checks, and the backing service performs no workspace or ownership validation. getAllUpsertHistory() returns UpsertHistory rows selected solely by an attacker-supplied chatflowid, and patchDeleteUpsertHistory() deletes rows by an attacker-supplied array of record UUIDs. As a result, any authenticated low-privilege user or valid API key can read or delete document-store upsert history belonging to other users and other workspaces whenever the target chatflowId (which is exposed publicly in /chatbot/<chatflowId> share links) or row ids are known. The retrievable flowData and result fields contain embedding, record-manager and vector-store node configuration, including per-node paramValues. No patched version is available. | ||||
| CVE-2026-100606 | 1 Flowiseai | 1 Flowise | 2026-09-28 | 7.7 High |
| Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login path. When an SSO callback arrives with an email matching a user whose status is INVITED, verifyAndLogin (SSOBase.ts:80-94) copies the user record from the database — including the server-stored single-use invitation tempToken — into the data passed to AccountService.register(). The register handler's token lookup, email match, and expiry checks therefore pass trivially against the server's own token instead of a caller-supplied one, and the account and its organization membership are flipped to ACTIVE. As a result, anyone able to authenticate at any configured SSO provider using a pending invitee's email address as the email claim can take over that invitation and obtain the invited user's access to the organization without ever possessing the emailed invitation token, for as long as the invitation is valid (24 hours by default). At the time of the advisory no patched version was available. | ||||
| CVE-2026-101141 | 1 Eleveo | 1 Call Recording Software | 2026-09-28 | 3.5 Low |
| A flaw has been found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/audio.jsp of the component Play Audio Page. Executing a manipulation of the argument viewRoleId/cfType can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-101898 | 1 Axios | 1 Axios | 2026-09-28 | N/A |
| Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 request setup does not consistently apply proxy settings and caller-supplied DNS lookup policy. An HTTPS request uses httpVersion: 2 with explicit config.proxy or environment-derived proxy settings, or relies on caller-supplied config.lookup DNS policy. The HTTP/2 path can connect without the configured proxy behavior or without applying the caller-supplied config.lookup policy before http2.connect(). Requests can bypass the intended proxy route or the caller-supplied DNS resolution policy. This issue is fixed in version 1.20.0. | ||||
| CVE-2026-55096 | 1 Leshchenko1979 | 1 Fast-mcp-telegram | 2026-09-28 | 7.1 High |
| fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to the outgoing Telegram message. Downloads are guarded by _validate_url_security, an SSRF denylist that checks the URL's literal hostname string but never resolves DNS. The fetch (httpx.AsyncClient.get) does its own resolution at request time. Consequently a hostname that resolves to a loopback / private / link-local address passes the guard and is fetched — even with the secure defaults block_private_ips=True and allow_http_urls=False. Because the fetched body is returned to the attacker as a Telegram file attachment, this is a full-read, exfiltrating SSRF, not blind. This issue has been patched in version 30.1. | ||||
| CVE-2026-101900 | 1 Axios | 1 Axios | 2026-09-28 | N/A |
| Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving FormData headers. A separate same-process prototype-pollution flaw supplies an array or non-plain class instance whose inherited properties make it appear FormData-like; plain objects are blocked. The inherited getHeaders function can return attacker-controlled headers that resolveConfig merges into a fetch adapter request. Attacker-controlled headers can alter authorization, cache, metadata-service, or application-specific request behavior. This issue is fixed in version 1.20.0. | ||||
| CVE-2026-101901 | 1 Axios | 1 Axios | 2026-09-28 | N/A |
| Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session initialization or reuse. A request uses httpVersion: 2 and the ClientHttp2Session emits an error during session initialization or reuse. The unhandled session error escapes normal Promise rejection handling. The uncaught error can terminate the Node.js process and cause denial of service. This issue is fixed in version 1.20.0. | ||||
| CVE-2026-54708 | 1 Freepbx | 1 Security-reporting | 2026-09-28 | N/A |
| FreePBX is an open source IP PBX. Prior to versions 16.0.72 and 17.0.7, a critical vulnerability exists in the FreePBX backup Module that allows authenticated attackers to execute arbitrary code on the server. Authentication with a known username that has sufficient access permissions and/or write access to backup files is required. This vulnerability is caused by improper path sanitization in the backup restore functionality, enabling attackers to upload malicious PHP files to the web root directory. This issue has been patched in versions 16.0.72 and 17.0.7. | ||||
| CVE-2026-54710 | 1 Freepbx | 1 Security-reporting | 2026-09-28 | N/A |
| FreePBX is an open source IP PBX. Prior to versions 16.0.40 and 17.0.7, a critical remote code execution (RCE) vulnerability exists in the superfecta module due to unsafe inclusion of arbitrary PHP files, allowing authenticated attackers to execute arbitrary PHP code on the server with the privileges of the web server user. Authentication with a known username is required. The vulnerability is rooted in the options and save_options cases in the Superfecta module's AJAX handler. The code dynamically includes PHP files from the sources/ directory based on user-supplied input. This allows an attacker to execute arbitrary code when combined with arbitrary directory creation (e.g., via the backup module) and file uploads that reveal full paths (e.g., via the soundlang module). This issue has been patched in versions 16.0.40 and 17.0.7. | ||||
| CVE-2026-69499 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-28 | 8.8 High |
| Integer overflow or wraparound in Windows Imaging Component allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69498 | 1 Microsoft | 18 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 15 more | 2026-09-28 | 7 High |
| Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-4398 | 1 Gitlab | 1 Gitlab | 2026-09-28 | 5.4 Medium |
| GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have assigned compliance frameworks from namespaces they were not authorized to access to their own project, due to missing namespace validation on self-managed instances. | ||||
| CVE-2026-87719 | 1 Gitlab | 1 Gitlab | 2026-09-28 | 9.9 Critical |
| GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup. | ||||
| CVE-2026-88765 | 1 Gitlab | 1 Gitlab | 2026-09-28 | 8.5 High |
| GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions could allow an authenticated user to achieve remote code execution by importing a specially crafted Git project export to overflow the Unicode conversion buffer used in Advanced Search indexing. | ||||
| CVE-2026-86341 | 1 Gitlab | 1 Gitlab | 2026-09-28 | 4.4 Medium |
| GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user with Owner or Maintainer permissions could have silently disabled protected environment deployment approval requirements, allowing unapproved deployments to reach production, due to improper access control checks performed after the protected resource was modified. | ||||
| CVE-2026-92470 | 1 Gitlab | 1 Gitlab | 2026-09-28 | 7.7 High |
| GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to access sensitive CI/CD variable values from debug-mode job traces through the Duo AI troubleshooting feature due to missing authorization checks. | ||||
| CVE-2026-88774 | 1 Citrix | 3 Netscaler Adc, Netscaler Application Delivery Controller, Netscaler Gateway | 2026-09-28 | 7.2 High |
| Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage. | ||||