Export limit exceeded: 10229 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403616 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403616 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-106550 | 1 Mozilla | 1 Convict | 2026-10-09 | 7.5 High |
| Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete prototype‑pollution protections in config.set(). An attacker controlling the configuration key can write arbitrary properties to constructor.<key>, which walk() resolves to the global Object function. This allows overwriting core JavaScript methods such as Object.assign, leading to persistent process-wide failures and requiring a restart. The issue bypasses existing filters that only block constructor.prototype.* and __proto__.*. Exploitation requires an endpoint that forwards attacker-controlled keys into config.set(). | ||||
| CVE-2026-106547 | 1 Hdfgroup | 1 Hdf5 | 2026-10-09 | N/A |
| A heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c in HDF5 before 2.2.0 lets a remote attacker cause an application crash and possibly execute arbitrary code with a crafted HDF5 file. When a dataset's unallocated chunks are read, H5D__fill_init() fills the fill-value buffer from datatype and dataspace metadata in the file. If that metadata is inconsistent with the buffer's allocated size, the write goes past the end of the buffer. The attacker can control the content written through the fill value stored in the file. | ||||
| CVE-2026-65142 | 1 Nvidia | 1 Nvidia Model Optimizer | 2026-10-09 | 7.8 High |
| NVIDIA Model-Optimizer contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-107121 | 1 Redhat | 4 Build Keycloak, Build Of Keycloak, Red Hat Single Sign On and 1 more | 2026-10-09 | 6.5 Medium |
| A flaw was found in the SMTP email configuration handling of the keycloak-services component. When the STARTTLS option is enabled, Keycloak fails to strictly enforce an encrypted connection, allowing it to fall back to unencrypted communication if the encryption request is tampered with. An attacker who can intercept network traffic can exploit this to capture sensitive email credentials and message content in plain text. | ||||
| CVE-2026-58068 | 1 Veeam | 1 Veeam Agent For Windows | 2026-10-09 | N/A |
| This vulnerability in Veeam Agent for Microsoft Windows allows any local user to terminate arbitrary processes on the system. | ||||
| CVE-2025-64391 | 1 Veeam | 1 Veeam Agent For Windows | 2026-10-09 | N/A |
| This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it. | ||||
| CVE-2026-103416 | 1 Eclipse | 1 Threadx Netx Duo | 2026-10-09 | N/A |
| Out-of-bounds write via the TLS 1.3 handshake message cache in NetX Duo in Eclipse ThreadX NetX Duo 6.5.1.202602 allows a handshake message larger than the cache writes past it and on into the rest of the session control block, which holds pointers. A malicious or compromised server can make a TLS 1.3 client produce such a message before certificate authentication completes, so no server certificate is needed to reach it. | ||||
| CVE-2026-4264 | 1 Beetienda | 1 Ecommerce Platform | 2026-10-09 | N/A |
| Reflected Cross-Site Scripting (XSS) on the BeeTienda e-commerce platform, specifically in the latest demo version. The incident occurs due to a lack of proper sanitization of user input data in the 'search' parameter of the product list endpoint. When malicious payloads are transmitted via the 'search' parameter, they are displayed insecurely in the HTML response, allowing for the arbitrary execution of JavaScript code in the victim's browser. | ||||
| CVE-2025-14123 | 2026-10-09 | 6.8 Medium | ||
| The Redux Framework plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.5.11. This is due to the plugin saving arbitrary meta keys under a registered option name without sufficient capability checks or key allowlist / restrictions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set an arbitrary role (e.g., Administrator) when performing a profile update if a plugin or theme using this framework has added at least one user profile field that leverages Redux_Users::set_profile/set_section/set_field. | ||||
| CVE-2026-87110 | 1 Mongodb | 1 Ops Manager | 2026-10-09 | 5.3 Medium |
| An unauthenticated user with network access to the Ops Manager web port can repeatedly request monitoring endpoints that perform costly work without rate limiting. This can temporarily slow other traffic served by the same process while requests continue. | ||||
| CVE-2026-87109 | 1 Mongodb | 1 Ops Manager | 2026-10-09 | 5.3 Medium |
| An authenticated Ops Manager organization member can retrieve another member's pending authenticator enrollment seed through user-listing endpoints while that member's enrollment is unconfirmed. This results in disclosure of secret authentication material to another member of the same organization or project. | ||||
| CVE-2026-92989 | 2026-10-09 | N/A | ||
| The SendPress Newsletters WordPress plugin through 1.26.1.20 does not check the user's capability on several newsletter-management actions, allowing any authenticated subscriber-level user to synchronise all site users into a mailing list and to drive the newsletter send queue. | ||||
| CVE-2026-92990 | 2026-10-09 | N/A | ||
| The SendPress Newsletters WordPress plugin through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the same on every site rather than a per-site secret, allowing unauthenticated users to read newsletter sending logs, including recipient email addresses. | ||||
| CVE-2026-86850 | 2026-10-09 | N/A | ||
| The SKU Error Fixer for WooCommerce WordPress plugin through 1.0 does not perform any capability or nonce checks on two of its AJAX actions, which are also available to unauthenticated users, allowing them to permanently delete product variations it classifies as obsolete, and to disclose those variations' details, with no recoverable copy left behind. | ||||
| CVE-2026-88931 | 2026-10-09 | N/A | ||
| The Social Web Suite WordPress plugin through 4.1.12 does not restrict which of its settings may be written through an unauthenticated endpoint, allowing attackers to overwrite arbitrary Social Web Suite WordPress plugin through 4.1.12 options, including the shared secret that guards its own privileged endpoints. | ||||
| CVE-2026-106097 | 2026-10-09 | N/A | ||
| The Code Snippets WordPress plugin before 3.10.0 does not sanitise and escape a user-supplied parameter before using it in a SQL query in some of its snippet-migration import endpoints, which are accessible to any user holding site-administration capabilities; on a WordPress Multisite network those belong to subsite Administrators, allowing a subsite Administrator who is not a network Super Admin to perform UNION-based SQL injection against shared network tables and disclose network-wide data such as other users' password hashes. | ||||
| CVE-2026-25267 | 1 Qualcomm | 1 Snapdragon | 2026-10-09 | 7.8 High |
| Memory corruption when non-secure loader rewrites page tables before secure memory initialization. | ||||
| CVE-2026-107194 | 1 Sungrowpower | 1 Isolarcloud | 2026-10-09 | N/A |
| Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization. | ||||
| CVE-2026-62179 | 1 Mervinpraison | 1 Praisonai | 2026-10-09 | 6.5 Medium |
| PraisonAI is a multi-agent teams system. In `praisonai-platform` prior to version 0.1.9, issue dependency deletion can be authorized against the wrong side of a dependency edge. A workspace member cannot delete a dependency through the owner-created issue endpoint, but can delete the same dependency through a member-owned related issue endpoint because the route accepts either endpoint and checks delete permission only against the caller-selected URL issue. Version 0.1.9 patches the issue. | ||||
| CVE-2026-76458 | 1 Cisco | 3 Cisco Nx-os System Software In Aci Mode, Nx-os Software, Unified Computing System Manager | 2026-10-09 | 8.6 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76458 are related to improper handling of exceptional conditions issues that are grouped under the Common Weakness Enumeration (CWE) CWE-703. | ||||