Export limit exceeded: 30000 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (91215 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-70611 | 2 Electron, Electronjs | 2 Electron, Electron | 2026-10-08 | 6.9 Medium |
| Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in file manager action could launch the target file rather than reveal it. An attacker with a separate means of running script inside the DevTools frontend, such as a malicious DevTools extension, could use showItemInFolder handling to execute native code outside the sandbox when DevTools is opened for windows exposed to untrusted content or untrusted DevTools extensions. This issue is fixed in 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3. | ||||
| CVE-2026-91797 | 3 Foxit, Foxitsoftware, Microsoft | 5 Pdf Editor, Pdf Reader, Foxit Pdf Editor and 2 more | 2026-10-08 | 7.8 High |
| Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the PDF is opened. | ||||
| CVE-2026-17636 | 2 Ibm, Redhat | 4 Financial Transaction Manager, Financial Transaction Manager (ftm) for Redhat Openshift, Financial Transaction Manager Ftmfor Redhat Openshift and 1 more | 2026-10-08 | 8.8 High |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified quantity. | ||||
| CVE-2026-102133 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-08 | 6.6 Medium |
| An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service account running the connector, enabling code execution in that account's context; exploitation additionally requires network egress from the appliance to a system under the attacker's control. | ||||
| CVE-2026-17644 | 2 Ibm, Redhat | 4 Financial Transaction Manager, Financial Transaction Manager (ftm) for Redhat Openshift, Financial Transaction Manager Ftmfor Redhat Openshift and 1 more | 2026-10-08 | 8.8 High |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials. | ||||
| CVE-2026-27420 | 2026-10-08 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Katie Seaborn Zotpress zotpress allows Stored XSS.This issue affects Zotpress: from n/a through 7.4.4. | ||||
| CVE-2026-16163 | 1 Ibm | 4 Datapower Gateway 1050, Datapower Gateway 1060, Datapower Gateway 106cd and 1 more | 2026-10-08 | 8.6 High |
| IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause memory corruption due to an out-of-bounds write. | ||||
| CVE-2026-16178 | 1 Ibm | 4 Datapower Gateway 1050, Datapower Gateway 1060, Datapower Gateway 106cd and 1 more | 2026-10-08 | 7.5 High |
| IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to improper input validation. | ||||
| CVE-2026-89191 | 2026-10-08 | 6.8 Medium | ||
| Unsanitised input in the "template name" field of SQLView KRIS's Workflow Template feature is rendered in "onclick" attributes on the main dashboard without proper server-side sanitisation, allowing an attacker with administrative access to inject and store malicious scripts that execute in the browsers of affected users. | ||||
| CVE-2026-102504 | 1 Tonycoz | 1 Imager | 2026-10-08 | 7.5 High |
| Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3). Passing an untrusted raw_datachannels value to Imager->read() triggers an uncatchable exit. | ||||
| CVE-2026-92861 | 2026-10-08 | N/A | ||
| The Android application "Ticket Ryutsu Center" contains hard-coded credentials, which may allow an attacker to obtain an API key used by the application. | ||||
| CVE-2026-87726 | 2026-10-08 | 3.9 Low | ||
| Insufficient API bounds checking in phalFelica in NXP NXPNfcRdLib RC663 through 07.14.00_Pub may allow an attacker with privileges or an untrusted third party to access unintended memory regions, potentially leading to limited loss of confidentiality, integrity, and availability. All software versions from 07.18.00 onwards have fixed this problem. | ||||
| CVE-2026-87685 | 1 Brocade | 1 Fabric Os | 2026-10-08 | N/A |
| An arbitrary file manipulation vulnerability exists in the WebTools management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing configuration transfer requests, the application fails to properly validate and sanitize a user-supplied status file path parameter. An authenticated administrative user can exploit this issue by submitting a specially crafted status file parameter, causing the underlying process to move an arbitrary system file to a predictable, world-readable temporary directory. This can lead to persistent Denial of Service (DoS), critical system file destruction, host compromise, or sensitive data leakage. | ||||
| CVE-2026-87682 | 1 Brocade | 1 Fabric Os | 2026-10-08 | N/A |
| Multiple OS Command Injection vulnerabilities exist in the management interface and session processing routines of Brocade Fabric OS versions before 10.0.1. Input processing flaws during remote management connection validation and session verification for directory-based user accounts allow untrusted input containing shell metacharacters to reach internal system execution wrappers. An authenticated user or a compromised directory service account can exploit these vulnerabilities to execute arbitrary operating system commands with elevated privileges on the target device. | ||||
| CVE-2026-87675 | 1 Brocade | 1 Fabric Os | 2026-10-08 | N/A |
| An OS command injection vulnerability exists in the configuration management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When performing a configuration download operation, the management daemon will relay configuration parameters, user-supplied relay host strings, and filenames directly to an internal utility script without sufficient character set validation. Because the local utility fails to sanitize shell metacharacters before processing them in a system shell command, a malicious or compromised configuration file can cause arbitrary operating system commands to be executed on a remote local switch when an administrator initiates a configuration download. | ||||
| CVE-2026-87674 | 1 Brocade | 1 Fabric Os | 2026-10-08 | N/A |
| A local privilege escalation vulnerability exists in the system logging daemon of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Insufficient access controls on internal inter-process communication (IPC) channels allow an unprivileged local user to submit malformed logging configurations. Due to improper input sanitization during configuration file generation, an attacker can inject arbitrary directives that execute with elevated privileges when the logging service reloads, leading to local privilege escalation. | ||||
| CVE-2026-87673 | 1 Brocade | 1 Fabric Os | 2026-10-08 | N/A |
| An OS command injection vulnerability exists in maintenance command-line diagnostic utilities on Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. The binary fails to sanitize user-supplied input options when invoking underlying system commands through a shell interpreter. A privileged user with maintenance account access can exploit this issue by supplying crafted parameters, which results in arbitrary OS command execution with root privileges. | ||||
| CVE-2026-76453 | 2026-10-08 | 8.8 High | ||
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76453 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) CWE-707. | ||||
| CVE-2026-105079 | 2026-10-08 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StylemixThemes MasterStudy LMS masterstudy-lms-learning-management-system allows Stored XSS.This issue affects MasterStudy LMS: from n/a through 3.7.52. | ||||
| CVE-2026-12541 | 2 Redhat, Theforeman | 5 Enterprise Linux, Satellite, Satellite Capsule and 2 more | 2026-10-08 | 8.2 High |
| A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths. | ||||