Export limit exceeded: 401188 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (401188 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100265 1 Jetbrains 1 Rider 2026-10-02 4.8 Medium
In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation
CVE-2026-51904 2026-10-02 N/A
SuperAGI up to v0.0.14 contains an improper access control vulnerability in the agent execution controller. In affected source snapshots, create_agent_execution and create_agent_run in superagi/controllers/agent_execution.py accept a caller-supplied agent_id and fail to verify that the referenced agent belongs to the authenticated user's organization. A remote authenticated attacker from one organization can create or start execution records for agents owned by another organization through /agentexecutions/add or /agentexecutions/add_run.
CVE-2026-12544 2 Redhat, Theforeman 4 Satellite, Satellite Capsule, Satellite Utils and 1 more 2026-10-02 7.7 High
A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection (SSTI) and insecure deserialization. This vulnerability can lead to remote code execution, total infrastructure compromise and supply chain risk.
CVE-2026-100266 1 Jetbrains 1 Hub 2026-10-02 7.7 High
In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address
CVE-2026-94645 1 Apache 1 Thrift 2026-10-02 N/A
Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-94644 1 Apache 1 Thrift 2026-10-02 N/A
Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-61373 1 Apache 1 Thrift 2026-10-02 N/A
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java TSaslNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-100270 1 Jetbrains 1 Youtrack 2026-10-02 3.3 Low
In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations
CVE-2026-100271 1 Jetbrains 1 Youtrack 2026-10-02 2.7 Low
In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects
CVE-2026-100272 1 Jetbrains 1 Youtrack 2026-10-02 4.9 Medium
In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues
CVE-2026-100273 1 Jetbrains 1 Youtrack 2026-10-02 8.2 High
In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution
CVE-2026-51898 1 Sinaptik-ai 1 Pandas-ai 2026-10-02 N/A
sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute.
CVE-2026-51901 1 Transformeroptimus 1 Superagi 2026-10-02 N/A
SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated users from one organization to schedule existing agents belonging to a different organization without proper authorization checks. The endpoint accepts an agent_id parameter but does not verify that the agent belongs to the authenticated user's organization.
CVE-2026-94646 2 Apache, Redhat 2 Thrift, Hummingbird 2026-10-02 7.5 High
Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
CVE-2026-100274 1 Jetbrains 1 Youtrack 2026-10-02 6.5 Medium
In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template
CVE-2026-39717 2026-10-02 4.3 Medium
Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through 4.4.9.1.
CVE-2026-39439 2026-10-02 6.5 Medium
Missing Authorization vulnerability in Kiera Howe WebSamurai websamurai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebSamurai: from n/a through 1.0.7.
CVE-2026-104613 1 Codeastro 1 Simple Pharmacy Management System 2026-10-02 6.3 Medium
A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /SimplePharmacy-PHP/product/view.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-104467 1 Yeswiki 1 Yeswiki 2026-10-02 8.1 High
YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. Attackers can send requests to endpoints like api/ci/update_config and api/archives to overwrite configuration and list, download, or delete backup archives.
CVE-2026-104442 1 Yeswiki 1 Yeswiki 2026-10-02 5.8 Medium
YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary URLs by supplying a syndication action through the render handler's content parameter. Attackers can target internal hosts and ports, read back fetched feed content in the rendered page, and cause feed enclosures to be downloaded into the files directory.