Export limit exceeded: 10054 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 15081 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15081 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-94636 | 1 Apache | 1 Thrift | 2026-10-02 | N/A |
| Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity in input vulnerability in Apache Thrift py bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||
| CVE-2026-39444 | 2026-10-02 | 5.4 Medium | ||
| Authorization Bypass Through User-Controlled Key vulnerability in PublishPress PublishPress Series organize-series allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Series: from n/a through 3.1.3. | ||||
| CVE-2026-79654 | 1 Redhat | 3 Satellite, Satellite Capsule, Satellite Utils | 2026-10-02 | 4.3 Medium |
| A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history of a Content View belonging to another organization by supplying its identifier to the affected API endpoint. This can result in unauthorized disclosure of Content View lifecycle information, including publication and promotion events, associated users, and timestamps. | ||||
| CVE-2026-79684 | 1 Dell | 13 Powerstore 1000t, Powerstore 1200t, Powerstore 3000t and 10 more | 2026-10-02 | 8.8 High |
| Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges. | ||||
| CVE-2026-79686 | 1 Dell | 13 Powerstore 1000t, Powerstore 1200t, Powerstore 3000t and 10 more | 2026-10-02 | 8.8 High |
| Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges. | ||||
| CVE-2026-94650 | 2 Apache, Redhat | 2 Thrift, Hummingbird | 2026-10-02 | N/A |
| Uncontrolled Recursion vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||
| CVE-2026-85493 | 1 Apache | 1 Thrift | 2026-10-02 | N/A |
| Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||
| CVE-2026-103118 | 1 Graphicsmagick | 1 Graphicsmagick | 2026-10-02 | 4.3 Medium |
| A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. | ||||
| CVE-2026-100272 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 4.9 Medium |
| In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues | ||||
| CVE-2026-104434 | 2 Zcashfoundation, Zfnd | 2 Zebra, Zebra | 2026-10-02 | 6.5 Medium |
| ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort the zebrad process, repeatably keeping the node offline. | ||||
| CVE-2026-104430 | 2 Zcashfoundation, Zfnd | 2 Zebra, Zebra | 2026-10-02 | 7.5 High |
| Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra's inflated MAX_BLOCK_SIGOPS count, causing Zebra nodes to reject it and stall off the chain. | ||||
| CVE-2026-104468 | 1 Yeswiki | 1 Yeswiki | 2026-10-02 | 4.8 Medium |
| YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who obtain an unused reset URL from mailboxes, logs, backups, or browser history can submit a new password through checkEmailKey() and take over accounts. | ||||
| CVE-2026-28757 | 1 Intel | 2 Workload Services Framework Software, Workload Sevices Framework | 2026-10-02 | 6.7 Medium |
| Protection mechanism failure for some Intel(R) Workload Services Framework software within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. | ||||
| CVE-2026-55252 | 1 Openrundev | 1 Openrun | 2026-10-02 | N/A |
| OpenRun is an open-source, self-hosted GitOps platform for deploying web apps and internal tools to Docker or Kubernetes. Prior to version 0.17.7, the restrictions on redirect URLs in openrun can be bypassed by attackers, leading to open redirect attacks. This issue has been patched in version 0.17.7. | ||||
| CVE-2026-97318 | 2 Rafflepress, Wordpress-extensions | 2 Giveaways And Contests By Rafflepress, Giveaways And Contests By Rafflepress | 2026-10-02 | 6.1 Medium |
| The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary external site. | ||||
| CVE-2026-85615 | 1 Openpanel | 1 Openpanel | 2026-10-02 | 6.4 Medium |
| Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboardId to the authorized projectId. Authenticated attackers can supply an arbitrary victim dashboardId with their own projectId to read report layouts and configurations or delete dashboard grid arrangements across tenants. | ||||
| CVE-2026-85611 | 1 Openpanel | 1 Openpanel | 2026-10-02 | 6.4 Medium |
| OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to the caller's project. Authenticated attackers can supply their own projectId with a victim organization's guessable dashboardId to read confidential report definitions or permanently delete dashboard layouts across tenant boundaries. | ||||
| CVE-2026-102876 | 1 Surrealdb | 1 Surrealdb | 2026-10-02 | 8.1 High |
| SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS and Surreal-DB headers without validating access permissions. Attackers can authenticate as a user from one tenant while selecting another tenant's namespace and database to read, create, and modify records across tenant boundaries. | ||||
| CVE-2026-42010 | 2 Gnu, Redhat | 17 Gnutls, Ai Inference Server, Cert Manager and 14 more | 2026-10-02 | 7.1 High |
| A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process. | ||||
| CVE-2026-84062 | 1 D-zero | 1 Burgereditor | 2026-10-01 | N/A |
| BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key. If this vulnerability is exploited, the content of the page may be altered by an attacker who can log in to the product. | ||||