Export limit exceeded: 399590 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399590 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65126 | 2 Linux, Nvidia | 3 Linux Kernel, Infra Controller, Infrastructure Controller | 2026-09-29 | 5 Medium |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-97897 | 1 Krayin | 1 Laravel-crm | 2026-09-29 | 3.5 Low |
| A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component TinyMCE Media Upload. The manipulation results in cross site scripting. The attack may be performed from remote. Upgrading to version 2.2.6 is capable of addressing this issue. The patch is identified as 734aa10ae6c2ffa4c96c8869a89aa66940e4d345. You should upgrade the affected component. | ||||
| CVE-2026-71483 | 1 Horilla | 1 Horilla | 2026-09-29 | N/A |
| Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html without HTML neutralization. An external attacker can craft and deliver a link that causes JavaScript to execute when an authenticated employee or administrator reaches the employee filter, allowing access to browser-visible session data and actions with the victim's application privileges. This issue is fixed in version 1.6.0. | ||||
| CVE-2026-57443 | 1 Issdandavis | 1 Scbe-aethermoore | 2026-09-29 | 7.5 High |
| SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the `POST /api/ops/check-email` endpoint without any authentication. Any remote attacker can call this endpoint and trigger execution of the `email_reader.py` subprocess, which connects to configured ProtonMail or Gmail accounts via IMAP and returns email metadata (sender, subject, body snippet) in the JSON response. The server binds to `0.0.0.0:8100` by default with CORS set to `allow_origins=["*"]`, making it reachable from any network or browser origin. Version 4.2.1 patches the issue. | ||||
| CVE-2026-55214 | 1 Glpi-project | 1 Glpi | 2026-09-29 | N/A |
| GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who opens the affected item's suppliers list triggers the stored cross-site scripting payload. This issue is fixed in version 11.0.8. | ||||
| CVE-2026-53610 | 1 Glpi-project | 1 Glpi | 2026-09-29 | N/A |
| GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker-controlled markup without sufficient output encoding. A user who opens the crafted URL triggers reflected cross-site scripting in the dashboard. This issue is fixed in version 11.0.8. | ||||
| CVE-2026-49469 | 1 Glpi-project | 1 Glpi | 2026-09-29 | N/A |
| GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP filter. This allows access to LDAP objects that the default filter was intended to exclude. This issue is fixed in versions 11.0.8 and 10.0.26. | ||||
| CVE-2026-102811 | 2026-09-29 | 7.5 High | ||
| Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in handle_create_content and handle_clone_content to write files outside the project directory via directory traversal. | ||||
| CVE-2026-102807 | 1 Openclaw | 1 Openclaw | 2026-09-29 | 5.3 Medium |
| OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped operators to execute MCP App tools requiring operator.write scope. Attackers with operator.read tokens can obtain a standalone ticket from mcp.app.view and redeem it at the MCP app view endpoint to invoke state-changing tools without proper authorization checks. | ||||
| CVE-2026-102697 | 1 Ollama | 1 Ollama | 2026-09-29 | 7.8 High |
| Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell syntax. Attackers who can influence model output through prompt injection can execute additional shell commands by appending control operators like semicolons or logical operators to approved commands, bypassing the session approval requirement. | ||||
| CVE-2026-102634 | 1 Lmsys | 1 Sglang | 2026-09-29 | 7.5 High |
| SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send concurrent requests with identical bootstrap_room values to crash scheduler processes or hang other users' requests until transfer timeout. | ||||
| CVE-2026-102568 | 2026-09-29 | 5.5 Medium | ||
| Pardus Parental Control before 0.7.0 contains an incorrect authorization vulnerability in the polkit policy that allows unprivileged local users to disable parental controls as root. Attackers can invoke PPCActivator.py with the --disable argument via pkexec to remove all restrictions including DNS filtering and application limits without authentication. | ||||
| CVE-2026-102556 | 1 Redhat | 1 Enterprise Linux | 2026-09-29 | 8.6 High |
| A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handler that follows the documented GBytes API can trigger heap corruption or a crash upon receiving a crafted Pong. | ||||
| CVE-2026-102372 | 1 Gestsup | 1 Gestsup | 2026-09-29 | 6.1 Medium |
| GestSup versions before 3.2.62 fail to properly sanitize HTML email bodies in the IMAP LOGIN connector, allowing unauthenticated attackers to store arbitrary JavaScript in ticket descriptions and replies. Attackers can send emails to the monitored mailbox containing script tags and event handlers that execute in technician browsers, enabling ticket data theft and unauthorized actions. | ||||
| CVE-2026-102367 | 1 Gz-yami | 1 Mall4j | 2026-09-29 | 5.4 Medium |
| mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to validate the enabled flag when issuing new sessions. Disabled user accounts can indefinitely renew their sessions through the POST /token/refresh endpoint, retaining access that account disabling was intended to remove. | ||||
| CVE-2026-102364 | 1 Gz-yami | 1 Mall4j | 2026-09-29 | 5.4 Medium |
| mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office users by reusing their session tokens. Attackers can register on the public storefront and use their customer session token to access admin endpoints lacking @PreAuthorize permission checks, including menu listings, file uploads, and configuration endpoints. | ||||
| CVE-2026-102363 | 1 Gz-yami | 1 Mall4j | 2026-09-29 | 3.7 Low |
| mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an order number parameter. Attackers can access carrier names, waybill numbers, and complete logistics trails for any order without authentication or ownership verification. | ||||
| CVE-2026-102297 | 1 Zoneminder | 1 Zoneminder | 2026-09-29 | 4.3 Medium |
| ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API to list frame records from monitors they are denied access to, disclosing event and frame metadata across monitor boundaries. | ||||
| CVE-2026-102244 | 1 Modsetter | 1 Surfsense | 2026-09-29 | 4.3 Medium |
| A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown function of the file surfsense_backend/app/routes/editor_routes.py of the component Document Export Feature. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.0.36.3 is recommended to address this issue. The patch is named 2faff7b3823322a9cb6797973e6caf089386c354. The affected component should be upgraded. | ||||
| CVE-2026-102240 | 1 Netcore | 1 Nap930 | 2026-09-29 | 10 Critical |
| A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||