Export limit exceeded: 23326 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (23326 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-106571 | 1 Imagemagick | 1 Imagemagick | 2026-10-07 | 5.1 Medium |
| ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 6.9.13-56 and 7.1.2-31, a crafted local call to the GetVirtualPixels API can trigger an integer calculation error and write beyond a heap buffer, crashing the server process. This issue is fixed in versions 6.9.13-56 and 7.1.2-31. | ||||
| CVE-2026-106564 | 1 Imagemagick | 1 Imagemagick | 2026-10-07 | 5.3 Medium |
| ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, a crafted EXR image can cause the EXR decoder to write beyond a heap buffer, causing the process to crash. This issue is fixed in version 7.1.2-32. | ||||
| CVE-2026-76459 | 2026-10-07 | 8.8 High | ||
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76459 are related to out-of-bounds write issues that are grouped under the Common Weakness Enumeration (CWE) CWE-787. | ||||
| CVE-2026-106453 | 1 Yawkat | 1 Lz4-java | 2026-10-07 | 5.3 Medium |
| yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to approximately 2 GiB and exhaust the JVM heap. Convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor allocate the untrusted size, while overloads that write to a caller-provided destination buffer are not affected because the caller controls the destination size. This issue is fixed in version 1.11.2. | ||||
| CVE-2026-106113 | 1 Sixlabors | 1 Imagesharp | 2026-10-07 | 7.5 High |
| ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumerics.GetBT709Luminance. GrayscaleLevelsRowOperation.Invoke uses the resulting value as an unchecked histogram offset, causing an unsafe out-of-range access and process termination. Adaptive Histogram Equalization and AutoLevel are not affected by this report. This issue is fixed in version 4.1.2. | ||||
| CVE-2026-106056 | 1 Rundeck | 1 Rundeck | 2026-10-07 | 7.5 High |
| Rundeck before 6.2.0 contains an OS command injection vulnerability that allows authenticated users with job run permission to execute commands on Windows nodes by supplying crafted option values. Attackers can inject cmd.exe metacharacters such as && or | into free-text options, which CLIUtils.quoteWindowsCMDArg wraps in ineffective single quotes, running commands with node executor credential privileges. | ||||
| CVE-2026-101258 | 1 Redhat | 1 Enterprise Linux | 2026-10-07 | 7.8 High |
| A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at runtime. An attacker can deliver the document directly or through formats that delegate rendering to Ghostscript (for example EPS import or print conversion workflows). Successful exploitation can compromise confidentiality, integrity, and availability of data accessible to the process running Ghostscript. | ||||
| CVE-2026-102256 | 1 Sonicwall | 1 Sma1000 | 2026-10-07 | 7.8 High |
| Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 appliance which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. | ||||
| CVE-2026-18095 | 2 Ibm, Redhat | 3 Financial Transaction Manager, Financial Transaction Manager Ftmfor Redhat Openshift, Openshift | 2026-10-07 | 8.5 High |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow. | ||||
| CVE-2026-96260 | 1 Mattermost | 2 Mattermost, Mattermost Server | 2026-10-07 | 6.5 Medium |
| Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation of plugin requests which allows an authenticated user to exhaust server memory and cause a denial of service via a large request body sent to a plugin endpoint.. Mattermost Advisory ID: MMSA-2026-00775 | ||||
| CVE-2026-92531 | 1 Bugtracker.net | 1 Bugtracker.net | 2026-10-07 | N/A |
| Operating system command injection vulnerability in the SVN integration component of BugTracker.NET. The application incorporates the value of the field corresponding to the repository into an svn.exe command without properly validating it. An authenticated user with administrator privileges could store manipulated arguments in the database and subsequently cause them to be processed by the revision comparison functionality. A successful exploit could allow the execution of arbitrary commands with the privileges of the account used by the application. To exploit this vulnerability, svn.exe must be installed and capable of being invoked by the service. | ||||
| CVE-2026-106057 | 1 Wummel | 1 Patool | 2026-10-07 | 7.8 High |
| patool before 4.0.6 contains an OS command injection vulnerability on Windows because shell_quote_nt fails to escape cmd.exe metacharacters or embedded double quotes in archive filenames. Attackers can supply crafted filenames like report&calc.gz for single-file formats run with shell=True to execute commands with patool process privileges. | ||||
| CVE-2026-101207 | 2026-10-07 | 8.8 High | ||
| Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | ||||
| CVE-2026-106556 | 2026-10-07 | 7.7 High | ||
| Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by configuration bypass in techdocs mkdocs.yml sanitization. Insufficient validation of MkDocs configuration during TechDocs generation could allow an authenticated user who can register or modify documentation sources to execute arbitrary commands in the build environment. Impact is limited to resources accessible to the TechDocs backend or build container. This issue is fixed in versions 1.14.6 and 1.15.4. | ||||
| CVE-2026-102120 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 8.8 High |
| A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment to run operating system commands with elevated privileges on another node of the same cluster. Insufficient input validation in an internal cluster management function let attacker-supplied values reach a privileged execution context; exploitation requires existing access to a node in the cluster, and the affected function is not reachable from outside the cluster. | ||||
| CVE-2026-102114 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.2 High |
| A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful exploitation requires an administrative account with elevated privileges. | ||||
| CVE-2026-102112 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.8 High |
| A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root and run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account. | ||||
| CVE-2026-25269 | 1 Qualcomm | 1 Snapdragon | 2026-10-07 | 6.7 Medium |
| Memory corruption when processing camera requests with excessive batch and IO buffer configurations exceeds allocated memory size. | ||||
| CVE-2026-106401 | 1 Google | 1 Chrome | 2026-10-07 | 9.6 Critical |
| Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106059 | 1 Gitahead | 1 Gitahead | 2026-10-07 | 8.8 High |
| GitAhead through 2.7.1 on macOS contains a command injection vulnerability that allows attackers to execute shell commands by crafting repository filenames interpolated unescaped into the Show in Finder AppleScript. Attackers can commit a file whose path contains a double quote followed by a do shell script payload, which runs as the victim user when Show in Finder is chosen. | ||||