Export limit exceeded: 10035 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10035 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100264 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 2.7 Low |
| In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host | ||||
| CVE-2026-94620 | 1 Foundation50 | 1 Classroom50 | 2026-10-02 | N/A |
| Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to version 1.11.0, `gh teacher download` clones each student's assignment repository and then writes autograde artifacts (`result.json` and `results.json`) into the just-cloned working tree. The write followed symlinks, so a student who committed `result.json` or `results.json` as a **symlink** (materialized verbatim by `git clone`) could redirect the teacher's write to an arbitrary path — e.g. `~/.zshrc`, `~/.ssh/authorized_keys`, a cron file, or an in-clone `.git/hooks/*` file that git subsequently executes. The written bytes are attacker-controlled (the student's uploaded release asset for `result.json`; student-chosen submit-tag names for `results.json`). This is an arbitrary file write leading to code execution as the teacher, whose `gh` token carries `admin:org`, `repo`, and `workflow` across the entire classroom organization. Version 1.11.0 contains a patch. Some workarounds are available. Avoid running `gh teacher download` against untrusted student repositories, or run it inside a disposable sandbox / container with no access to sensitive host files or credentials. Inspect cloned trees for symlinked, hardlinked, or special (`result.json`/`results.json`) entries before allowing the artifact-refresh step to run. | ||||
| CVE-2026-93982 | 1 Openpanel | 1 Openpanel | 2026-10-02 | 3.3 Low |
| OpenPanel through 2.3.0 writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with access to application stdout or centralized logging systems can capture base64-encoded credentials to replay MCP requests and access project analytics. | ||||
| CVE-2026-88265 | 1 Redhat | 4 Enterprise Linux, Hardened Images, Hummingbird and 1 more | 2026-10-02 | 5.6 Medium |
| A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet. | ||||
| CVE-2026-87910 | 1 Python | 1 Cpython | 2026-10-02 | 5.7 Medium |
| When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None. | ||||
| CVE-2026-94390 | 2 Dotstore, Wordpress-extensions | 2 Hide Shipping Method For Woocommerce, Hide Shipping Method For Woocommerce | 2026-10-01 | 7.2 High |
| Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions. | ||||
| CVE-2026-103263 | 1 Tornadoweb | 1 Tornado | 2026-10-01 | 5.9 Medium |
| Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user. | ||||
| CVE-2022-30333 | 4 Debian, Linux, Opengroup and 1 more | 4 Debian Linux, Linux Kernel, Unix and 1 more | 2026-10-01 | 9.8 Critical |
| RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected. | ||||
| CVE-2026-97256 | 2 Greg–siteorigin, Wordpress-extensions | 2 Page Builder By Siteorigin, Page Builder By Siteorigin | 2026-10-01 | 7.2 High |
| Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions. | ||||
| CVE-2026-97291 | 2 Magazine3, Wordpress-extensions | 2 Schema & Structured Data For Wp & Amp, Schema & Structured Data For Wp & Amp | 2026-10-01 | 8.8 High |
| Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions. | ||||
| CVE-2026-100512 | 2 Hook & Filter, Wordpress-extensions | 2 Nested Pages, Nested Pages | 2026-10-01 | 9.8 Critical |
| Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions. | ||||
| CVE-2026-102377 | 2 10web, Wordpress-extensions | 2 Photo Gallery, Photo Gallery By 10web | 2026-10-01 | 8.8 High |
| Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions. | ||||
| CVE-2026-102392 | 2 Themehigh, Wordpress-extensions | 2 Extra Product Options For Woocommerce, Extra Product Options For Woocommerce | 2026-10-01 | 7.2 High |
| Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions. | ||||
| CVE-2026-103441 | 1 Wikimedia | 1 Mediawiki-wikibase Extension | 2026-10-01 | N/A |
| Deserialization of untrusted data vulnerability in The Wikimedia Foundation MediaWiki Wikibase extension allows Leverage Executable Code in Non-Executable Files. This issue affects MediaWiki Wikibase extension: 1.46, 1.45, and 1.43. | ||||
| CVE-2026-55083 | 1 Dhis2 | 1 Dhis2-core | 2026-10-01 | 9.1 Critical |
| DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) via unsafe Java deserialization. This issue has been patched in versions 2.42.5.1, 2.43.0.1, and 2.44. | ||||
| CVE-2026-43642 | 1 Softaculous | 1 Virtualizor | 2026-10-01 | 8.1 High |
| Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module handler that allows unauthenticated remote attackers to supply arbitrary serialized PHP objects for deserialization by setting the act parameter to login with the from_billing_module parameter present. Attackers can pass malicious serialized data through the billing_data POST field to the unserialize() function without allowed_classes restrictions, enabling exploitation of available POP chains to achieve remote code execution as root. | ||||
| CVE-2022-50788 | 1 Sound4 | 21 Big Voice2, Big Voice2 Firmware, Big Voice4 and 18 more | 2026-10-01 | 7.5 High |
| SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve system and sensitive information without authentication. | ||||
| CVE-2026-12256 | 2 Theme-fusion, Wordpress | 2 Avada, Wordpress | 2026-10-01 | 8.8 High |
| Deserialization of Untrusted Data vulnerability in ThemeFusion Fusion Builder fusion-builder allows Object Injection.This issue affects Fusion Builder: from n/a through 3.15.3. | ||||
| CVE-2026-58163 | 2 Apache, Apache Software Foundation | 2 Traffic Server, Apache Traffic Server | 2026-10-01 | 7.5 High |
| Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue. | ||||
| CVE-2026-97284 | 2026-10-01 | 8.8 High | ||
| Contributor PHP Object Injection in Icegram <= 3.1.31 versions. | ||||