Export limit exceeded: 402612 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402612 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-19395 | 2 Qt, Redhat | 2 Qt For Mcus, Hummingbird | 2026-10-05 | 7.5 High |
| In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty values. The check fails and reports an error, and the default error handler halts the device. | ||||
| CVE-2026-59797 | 1 Apache | 1 Http Server | 2026-10-05 | 9.8 Critical |
| Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | ||||
| CVE-2026-105289 | 1 Feelec-yishu | 1 Feelcrm-os | 2026-10-05 | 3.5 Low |
| A vulnerability was found in feelec-yishu feelcrm-os 1.0.0. Affected by this issue is the function htmlspecialchars_decode of the file App/Feelcrm/Common/Model/CrmDefineFormModel.class.php of the component Create Customer Endpoint. Performing a manipulation of the argument customer_form[remark] results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-105285 | 1 Totolink | 1 A3002mu | 2026-10-05 | 10 Critical |
| A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation of the argument addQos/comment/entry_name leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. | ||||
| CVE-2026-105069 | 2026-10-05 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikki Blight QR Redirector qr-redirector allows Stored XSS.This issue affects QR Redirector: from n/a through 2.0.5. | ||||
| CVE-2026-105068 | 2026-10-05 | 5.3 Medium | ||
| Insertion of Sensitive Information Into Sent Data vulnerability in Pixelite Events Manager events-manager allows Retrieve Embedded Sensitive Data.This issue affects Events Manager: from n/a through 7.4.5. | ||||
| CVE-2026-105055 | 2026-10-05 | 5.3 Medium | ||
| Missing Authorization vulnerability in WP Mailster WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through 1.9.0.0. | ||||
| CVE-2026-104810 | 2026-10-05 | N/A | ||
| This vulnerability allows remote attackers to delete sensitive files on vulnerable installations of Mitel MiVoice Office 400. Authentication is required to exploit this vulnerability. The specific flaw exists within the web portal listening on TCP port 443, under Maintenance → File Management → File Browser, which is affected by a directory traversal vulnerability. By exploiting this vulnerability, an authenticated attacker can access and delete files outside of the intended directory, including files belonging to the Mitel application and the underlying Linux system. Deleting critical system or application files can result in a denial-of-service condition affecting the underlying system. | ||||
| CVE-2026-104809 | 2026-10-05 | N/A | ||
| DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file’s origin or integrity. A malicious shared object using the expected name can therefore be loaded by a privileged process. The module code then executes within the context and privileges of that process. This results in arbitrary code execution and full compromise of the Mitel Linux virtual machine. | ||||
| CVE-2026-104675 | 2026-10-05 | 4.3 Medium | ||
| Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0. | ||||
| CVE-2026-104401 | 2026-10-05 | 4.3 Medium | ||
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Retrieve Embedded Sensitive Data.This issue affects Memberful - Membership Plugin: from n/a through 1.81.2. | ||||
| CVE-2026-104388 | 2026-10-05 | 5.3 Medium | ||
| Missing Authorization vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Retrieve Embedded Sensitive Data.This issue affects PowerPress Podcasting: from n/a through 11.17.9. | ||||
| CVE-2026-103351 | 2026-10-05 | 5.3 Medium | ||
| Improper Validation of Specified Quantity in Input vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Input Data Manipulation.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.1.1. | ||||
| CVE-2026-103335 | 2026-10-05 | N/A | ||
| Insertion of Sensitive Information Into Sent Data vulnerability in Deepen Bajracharya Video Conferencing with Zoom video-conferencing-with-zoom-api allows Retrieve Embedded Sensitive Data.This issue affects Video Conferencing with Zoom: from n/a through 4.6.10. | ||||
| CVE-2026-103084 | 2026-10-05 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LeapWorx Premium Addons for Elementor premium-addons-for-elementor allows Stored XSS.This issue affects Premium Addons for Elementor: from n/a through 4.11.109. | ||||
| CVE-2026-63045 | 2 Apache, Redhat | 3 Apache Http Server, Http Server, Hummingbird | 2026-10-05 | 7.5 High |
| Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response. Users are recommended to upgrade to version 2.4.69, which fixes this issue. | ||||
| CVE-2026-20526 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 7.5 High |
| In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01898195; Issue ID: MSV-8906. | ||||
| CVE-2026-20527 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 5.3 Medium |
| In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01864925 / MOLY01210562; Issue ID: MSV-8303. | ||||
| CVE-2026-20579 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9800. | ||||
| CVE-2026-20587 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 6.7 Medium |
| In mtee, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9608. | ||||