Export limit exceeded: 399175 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (399175 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100690 2 Gohugo, Redhat 2 Hugo, Hummingbird 2026-09-28 7.5 High
Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission model validates only the lexical path and follows symbolic links that point outside the allowed set, Hugo did not detect symlinks escaping the sandbox. An attacker who can contribute content to a Hugo project (for example via a pull request) can commit a symlink such as assets/css/x.css -> /etc/passwd together with a PostCSS plugin that reads it, allowing any file readable by the Hugo build process to be disclosed and potentially embedded in the published site. This affects builds using the default security configuration; projects that do not invoke Node.js tools are unaffected. Fixed in v0.166.0, which scans allowed paths and fails the build when a symbolic link resolves outside them.
CVE-2026-100693 2 Gohugo, Redhat 2 Hugo, Hummingbird 2026-09-28 8.4 High
Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls to fetch from restricted IP addresses like localhost.
CVE-2026-100694 2 Gohugo, Redhat 2 Hugo, Hummingbird 2026-09-28 6.1 Medium
Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type are rendered without escaping raw HTML: Org export blocks and @@html:...@@ snippets pass HTML through unescaped, resulting in cross-site scripting (XSS) in the generated site. An attacker who can supply or influence a content file under /content or the output of a content adapter can inject scripts that execute in the browsers of visitors to the affected pages. Only pages whose source file or content-adapter output declares the text/org media type are affected, and sites that fully trust all content sources are not impacted. Version v0.166.0 fixes the issue by introducing a security.allowContent allowlist that denies text/org by default; sites that intentionally author Org Mode content can opt back in with [security] allowContent = ['.*'].
CVE-2026-94399 1 Elastic 1 Elasticsearch 2026-09-28 6.5 Medium
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
CVE-2026-94396 1 Elastic 1 Elasticsearch 2026-09-28 6.5 Medium
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
CVE-2026-82300 1 Elastic 1 Elasticsearch 2026-09-28 6.5 Medium
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).
CVE-2026-94397 1 Elastic 1 Elasticsearch 2026-09-28 6.5 Medium
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
CVE-2026-82294 1 Elastic 1 Elasticsearch 2026-09-28 6.5 Medium
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).
CVE-2026-82930 2 F&f Filipowski, F F Filipowski 2 Mh-developer, Mh-developer 2026-09-28 N/A
mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query these endpoints, access system information, and send raw control commands to manipulate building automation devices. This issue was fixed in version 3.0.30
CVE-2026-82933 2 F&f Filipowski, F F Filipowski 2 Mh-developer, Mh-developer 2026-09-28 N/A
mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions. This issue was fixed in version 3.0.30
CVE-2026-82929 2 F&f Filipowski, F F Filipowski 2 Mh-developer, Mh-developer 2026-09-28 N/A
mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception. This issue was fixed in version 3.0.30
CVE-2026-82932 2 F&f Filipowski, F F Filipowski 2 Mh-developer, Mh-developer 2026-09-28 N/A
mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service. This issue was fixed in version 3.0.30
CVE-2026-101082 1 Pmweb 1 Pmweb 2026-09-28 5.3 Medium
A weakness has been identified in PMWeb 7.x/8.x/2025.x. This issue affects some unknown processing of the file downloader.aspx. This manipulation of the argument FullFileName/FileName causes path traversal. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-88772 1 Citrix 3 Netscaler Adc, Netscaler Application Delivery Controller, Netscaler Gateway 2026-09-28 8.1 High
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
CVE-2026-58464 2026-09-28 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-58463 2026-09-28 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-69459 1 Microsoft 18 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 15 more 2026-09-28 7.8 High
Heap-based buffer overflow in Windows Power Dependency Coordinator allows an authorized attacker to elevate privileges locally.
CVE-2026-69460 1 Microsoft 18 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 15 more 2026-09-28 7.1 High
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges over a network.
CVE-2026-97165 1 Svenbluege.de 1 Event Gallery For Joomla 2026-09-28 N/A
Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” parameter is base64-decoded and written to the “Back” link without being validated.
CVE-2026-100749 1 Svenbluege.de 1 Event Gallery For Joomla 2026-09-28 N/A
Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned file entries and shopping carts that are older than 30 days will be deleted.