Export limit exceeded: 399730 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (399730 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-96652 1 Plex 1 Media Server 2026-09-29 4.3 Medium
Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL in the 'protocol' parameter and force the Plex server to POST to the attacker's chosen destination.
CVE-2026-96654 1 Plex 1 Media Server 2026-09-29 6.5 Medium
Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions and supply their own parameters.
CVE-2026-65114 2 Linux, Nvidia 3 Linux Kernel, Infra Controller, Infrastructure Controller 2026-09-29 8.3 High
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.
CVE-2026-65115 2 Linux, Nvidia 3 Linux Kernel, Infra Controller, Infrastructure Controller 2026-09-29 6.5 Medium
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource consumption. A successful exploit of this vulnerability may lead to denial of service.
CVE-2026-96655 1 Plex 1 Media Server 2026-09-29 4.3 Medium
Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses via the '/video/:/transcode/universal' path parameter.
CVE-2026-96656 1 Plex 1 Media Server 2026-09-29 7.2 High
Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The preference TranscoderH264Options is appended verbatim to x264's option string on every transcode. At startup, all .so files are run without signature, execute bit, or symbol checks.
CVE-2026-65117 2 Linux, Nvidia 3 Linux Kernel, Infra Controller, Infrastructure Controller 2026-09-29 5 Medium
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.
CVE-2026-100766 1 Mozilla 1 Firefox 2026-09-29 4.3 Medium
Information disclosure in the Networking: JAR component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100769 1 Mozilla 1 Firefox 2026-09-29 8.8 High
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
CVE-2026-100240 1 Wikimedia 1 Mediawiki - Templatesandbox Extension 2026-09-29 N/A
Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - TemplateSandbox Extension: from * before 1.46.1, 1.45.5, 1.43.10.
CVE-2026-65118 2 Linux, Nvidia 3 Linux Kernel, Infra Controller, Infrastructure Controller 2026-09-29 7.5 High
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
CVE-2026-65121 2 Linux, Nvidia 3 Linux Kernel, Infra Controller, Infrastructure Controller 2026-09-29 8.2 High
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering.
CVE-2026-69365 1 Microsoft 15 Windows 10 21h2, Windows 10 21h2, Windows 10 22h2 and 12 more 2026-09-29 8 High
Out-of-bounds read in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges over a network.
CVE-2026-65124 2 Linux, Nvidia 3 Linux Kernel, Infra Controller, Infrastructure Controller 2026-09-29 5.9 Medium
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to data tampering and denial of service.
CVE-2026-65125 2 Linux, Nvidia 3 Linux Kernel, Infra Controller, Infrastructure Controller 2026-09-29 6.6 Medium
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service.
CVE-2026-65126 2 Linux, Nvidia 3 Linux Kernel, Infra Controller, Infrastructure Controller 2026-09-29 5 Medium
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.
CVE-2026-97897 1 Krayin 1 Laravel-crm 2026-09-29 3.5 Low
A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component TinyMCE Media Upload. The manipulation results in cross site scripting. The attack may be performed from remote. Upgrading to version 2.2.6 is capable of addressing this issue. The patch is identified as 734aa10ae6c2ffa4c96c8869a89aa66940e4d345. You should upgrade the affected component.
CVE-2026-71483 1 Horilla 1 Horilla 2026-09-29 N/A
Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html without HTML neutralization. An external attacker can craft and deliver a link that causes JavaScript to execute when an authenticated employee or administrator reaches the employee filter, allowing access to browser-visible session data and actions with the victim's application privileges. This issue is fixed in version 1.6.0.
CVE-2026-57443 1 Issdandavis 1 Scbe-aethermoore 2026-09-29 7.5 High
SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the `POST /api/ops/check-email` endpoint without any authentication. Any remote attacker can call this endpoint and trigger execution of the `email_reader.py` subprocess, which connects to configured ProtonMail or Gmail accounts via IMAP and returns email metadata (sender, subject, body snippet) in the JSON response. The server binds to `0.0.0.0:8100` by default with CORS set to `allow_origins=["*"]`, making it reachable from any network or browser origin. Version 4.2.1 patches the issue.
CVE-2026-55214 1 Glpi-project 1 Glpi 2026-09-29 N/A
GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who opens the affected item's suppliers list triggers the stored cross-site scripting payload. This issue is fixed in version 11.0.8.