Export limit exceeded: 399514 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399514 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-101143 | 1 Eleveo | 1 Quality Management | 2026-09-29 | 4.3 Medium |
| A vulnerability was found in Eleveo Quality Management 9.7.0. Affected by this issue is some unknown functionality of the file /qm/cz.zoom.scorecard.webui.Scorecard/cz.zoom.scorecard.webui.Scorecard/QMBODownload. The manipulation results in information disclosure. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-101093 | 1 Cotonti | 2 Cotonti Siena, Siena | 2026-09-29 | 5.4 Medium |
| Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to delete user groups without token verification. Attackers can craft malicious links or pages that trick authenticated administrators into deleting custom groups and their associated permissions by riding the administrator's session. | ||||
| CVE-2026-100371 | 1 Invoiceplane | 1 Invoiceplane | 2026-09-29 | N/A |
| InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, an authorization guard to Users::change_password(), was added to address a previous authorization flaw that allowed a secondary administrator (user_type=1, user_id != 1) to directly change the password of the primary administrator (user_id=1) through users/change_password/{id}. That remediation, however, protects only the direct password-change operation. It does not protect the identity attribute that password recovery actually trusts: user_email. Users::form() applies no equivalent object-level authorization check when editing the primary administrator's account, and user_email is not included in PROTECTED_FIELDS. A secondary administrator can therefore rewrite the primary administrator's email address, then drive the public password-recovery flow — which resolves the account by user_email — to receive the reset token and take over user_id=1. The result is an alternate attack path that achieves the same impact PR #1638 was intended to prevent: cross-administrator full account takeover of the primary administrator. This issue has been patched via commit 8616fa4. | ||||
| CVE-2026-69806 | 2 Linux, Microsoft | 4 Linux Kernel, .net, Visual Studio 2022 and 1 more | 2026-09-29 | 7 High |
| Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-102371 | 2026-09-29 | N/A | ||
| In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument (pro attach <token>). On systems where /proc is mounted without process-hiding mitigations (such as hidepid), which is the default in WSL, an unprivileged local user or process in the same WSL instance can read the token from /proc/<pid>/cmdline while the attach process is running. The leaked token could then be used to attach other machines to the victim's Ubuntu Pro subscription and gain unauthorized access to Ubuntu Pro services. | ||||
| CVE-2026-65102 | 2026-09-29 | 7.8 High | ||
| NVIDIA DeepStream contains a vulnerability where an attacker could cause an integer overflow by supplying crafted tensor dimensions in a YAML configuration file. A successful exploit of this vulnerability might lead to denial of service, information disclosure, data tampering. | ||||
| CVE-2026-93355 | 1 Berriai | 1 Litellm | 2026-09-29 | 8.1 High |
| LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-based fallback lookup in the JWT authentication flow without verifying the email_verified claim. Attackers can present a token with an unverified email address matching a victim's account to inherit the victim's role, including proxy_admin privileges, and permanently overwrite the victim's stored identity binding to retain persistent unauthorized access to administrative endpoints exposing API keys and user management. | ||||
| CVE-2026-6928 | 2 Ibm, Linux | 2 Concert, Linux Kernel | 2026-09-29 | 9.8 Critical |
| IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code. | ||||
| CVE-2026-69439 | 1 Microsoft | 6 .net, Microsoft Visual Studio 2022, Microsoft Visual Studio 2026 and 3 more | 2026-09-29 | 8.8 High |
| Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-77258 | 2 Mcp-atlassian, Sooperset | 2 Mcp Atlassian, Mcp-atlassian | 2026-09-29 | 7.7 High |
| MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment in src/mcp_atlassian/confluence/attachments.py accepts a caller-controlled file_path and opens the selected server-local file without restricting it to the workspace. A permitted Confluence MCP caller can upload the file as an attachment and disclose data readable by the server process. This issue is fixed in version 0.22.0. | ||||
| CVE-2026-6935 | 2 Ibm, Linux | 2 Concert, Linux Kernel | 2026-09-29 | 7.8 High |
| IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code. | ||||
| CVE-2026-18104 | 1 Ibm | 1 Db2 Mirror For I | 2026-09-29 | 3.3 Low |
| IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption. | ||||
| CVE-2026-69485 | 1 Microsoft | 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more | 2026-09-29 | 8.8 High |
| Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-77260 | 2 Mcp-atlassian, Sooperset | 2 Mcp Atlassian, Mcp-atlassian | 2026-09-29 | 7.5 High |
| MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Confluence and Jira upload_attachment implementations accept an unconstrained file_path and open the referenced server-local file. A permitted MCP caller can upload sensitive host files to an Atlassian destination and then retrieve their contents. The advisory traces the vulnerable input and processing flow through upload_attachment, file_path, and CVE-2026-27825, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0. | ||||
| CVE-2026-69516 | 1 Microsoft | 18 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 15 more | 2026-09-29 | 7 High |
| Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69530 | 1 Microsoft | 6 Windows 10 1809, Windows Server 2019, Windows Server 2019 (server Core Installation) and 3 more | 2026-09-29 | 8.1 High |
| Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-86450 | 2026-09-29 | 7.5 High | ||
| Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects DetaWix Mobile Web Portal: before v1.0.19. | ||||
| CVE-2026-77255 | 2 Mcp-atlassian, Sooperset | 2 Mcp Atlassian, Mcp-atlassian | 2026-09-29 | 8.6 High |
| MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira update_issue attachments argument is converted into local paths and routed to the attachment upload implementation without workspace validation. A caller can make the MCP server read arbitrary local files and attach them to a Jira issue, using the server as a confused deputy to exfiltrate the contents. The advisory traces the vulnerable input and processing flow through jira update_issue, attachments, upload_attachment, and file_path, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0. | ||||
| CVE-2026-69384 | 1 Microsoft | 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more | 2026-09-29 | 7.1 High |
| Null pointer dereference in Virtual Hard Disk (VHD) Miniport Driver allows an unauthorized attacker to deny service locally. | ||||
| CVE-2026-77825 | 1 Ibm | 3 Contextforge, Contextforge-mcp-gateway, Contextforge Mcp Gateway | 2026-09-29 | 4.9 Medium |
| IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files outside the configured `LOG_FOLDER` by supplying a filename that resolves into a sibling directory whose absolute path shares the log directory's string prefix. | ||||