Export limit exceeded: 401632 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (401632 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103592 | 1 Pecee | 1 Simple-router | 2026-10-06 | 6.5 Medium |
| simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted addresses or evade blacklists, gaining access to IP-restricted routes. | ||||
| CVE-2026-103588 | 1 Webkul | 1 Qloapps | 2026-10-06 | 5.4 Medium |
| QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that executes in an authenticated administrator's session when the victim follows the link. | ||||
| CVE-2026-103001 | 1 Jpadilla | 1 Pyjwt | 2026-10-06 | 6.5 Medium |
| PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or decode_complete() call and changes verify_signature to true, the mapping can retain false values for expiration, not-before, issued-at, audience, issuer, subject, and JWT ID checks. A signed token with invalid registered claims can then be accepted without disabling signature verification, but applications that create a fresh options mapping for each call are not affected. | ||||
| CVE-2026-51917 | 1 Ai4finance | 1 Finrobot | 2026-10-06 | 7.3 High |
| FinRobot v1.0.0 is vulnerable to Code Injection in CodingUtils.modify_code. | ||||
| CVE-2026-49937 | 1 Google | 1 Android | 2026-10-06 | 7.8 High |
| In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-104038 | 1 Redhat | 2 Enterprise Linux, Openshift | 2026-10-06 | 5.9 Medium |
| A flaw was found in sssd. A remote attacker can cause a denial of service (DoS) by submitting a certificate that lacks an expected Security Identifier (SID) extension. In deployments configured with SID-based certificate mapping rules, the service fails to verify the presence of the extension before processing it, causing the process to crash during authentication or lookup operations. | ||||
| CVE-2026-104037 | 1 Redhat | 2 Enterprise Linux, Openshift | 2026-10-06 | 5.5 Medium |
| A flaw was found in SSSD. A local attacker can exploit this issue by sending a specially crafted request with an invalid packet length to the autofs responder UNIX socket. This causes an integer underflow and an out-of-bounds memory read, which can crash the responder process and result in a denial of service (DoS). | ||||
| CVE-2026-92821 | 1 Redhat | 2 Enterprise Linux, Openshift | 2026-10-06 | 6.8 Medium |
| A flaw was found in SSSD. When configured to evaluate password expiration warnings before restrictive access rules in LDAP (Lightweight Directory Access Protocol) environments, an expired-password warning terminates rule evaluation early and treats the access request as successful. A remote authenticated user with an expired password using an alternative authentication method, such as SSH public key authentication, can exploit this flaw to bypass access control restrictions and gain unauthorized access to protected systems. | ||||
| CVE-2026-104036 | 1 Redhat | 2 Enterprise Linux, Openshift | 2026-10-06 | 5.8 Medium |
| A flaw was found in SSSD's NFS idmap plugin. When retrieving cached user or group names, the plugin detects if an entry exceeds the destination buffer size but fails to abort before copying data. A local attacker can trigger this vulnerability by requesting identity lookups that resolve to oversized cached entries, resulting in an out-of-bounds write. This flaw primarily leads to a Denial of Service (DoS) by crashing the identity mapping service, and may also corrupt adjacent process memory. | ||||
| CVE-2026-104035 | 1 Redhat | 2 Enterprise Linux, Openshift | 2026-10-06 | 5.5 Medium |
| A flaw was found in SSSD. An issue in the Kerberos Credential Manager (KCM) responder allows a local user to cause a Denial of Service (DoS) by maintaining a persistent connection and repeatedly storing and destroying credentials. Because the service fails to release cached objects from memory when credentials are removed, memory consumption grows continuously, ultimately exhausting available memory and rendering the service unresponsive. | ||||
| CVE-2026-104034 | 1 Redhat | 2 Enterprise Linux, Openshift | 2026-10-06 | 4.7 Medium |
| A flaw was found in SSSD. A use-after-free vulnerability exists in the Kerberos Credential Manager (KCM) responder during Kerberos ticket-granting ticket (TGT) renewal, where a deferred callback accesses memory that has already been released. An authenticated local user with a renewable Kerberos ticket can trigger this issue on systems configured with KCM renewal, causing the KCM responder service to crash and resulting in a Denial of Service (DoS). | ||||
| CVE-2026-104033 | 1 Redhat | 2 Enterprise Linux, Openshift | 2026-10-06 | 5.4 Medium |
| A flaw was found in SSSD. When configured to enforce account expiration using LDAP (Lightweight Directory Access Protocol) shadow attributes, SSSD fails to treat an expiration value of zero as an expired account. A user with valid credentials for an expired account can exploit this flaw to bypass access controls and authenticate to the system. This allows unauthorized access to persist after the account was intended to be deactivated. | ||||
| CVE-2026-104032 | 1 Redhat | 2 Enterprise Linux, Openshift | 2026-10-06 | 5.5 Medium |
| A flaw was found in SSSD. An unprivileged local user can repeatedly request master automount map updates through the autofs responder due to missing authorization checks. This triggers global cache invalidation and forces repeated lookups to backend directory providers, leading to a Denial of Service (DoS) from degraded automount availability and elevated resource consumption. | ||||
| CVE-2026-104031 | 1 Redhat | 2 Enterprise Linux, Openshift | 2026-10-06 | 5.5 Medium |
| A flaw was found in SSSD. In configurations where the autofs responder service is enabled, memory allocated during successful request processing is not released until the client connection terminates. A local attacker can exploit this vulnerability by maintaining an open connection and repeatedly submitting valid requests, leading to memory exhaustion and a Denial of Service (DoS). | ||||
| CVE-2026-2575 | 2 Keycloak, Redhat | 5 Keycloak, Build Keycloak, Build Of Keycloak and 2 more | 2026-10-06 | 5.3 Medium |
| A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS) by sending a highly compressed SAMLRequest through the SAML Redirect Binding. The server fails to enforce size limits during DEFLATE decompression, leading to an OutOfMemoryError (OOM) and subsequent process termination. This vulnerability allows an attacker to disrupt the availability of the service. | ||||
| CVE-2026-55265 | 1 Google | 1 Android | 2026-10-06 | 6.5 Medium |
| In multiple functions of PduParser.java, there is a possible out of bounds read due to a missing bounds check. This could lead to a remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-58856 | 1 Google | 1 Android | 2026-10-06 | 3.3 Low |
| In returnOutputBufferLocked of DeprecatedCamera3StreamSplitter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-103531 | 1 Opensc | 1 Opensc | 2026-10-05 | 5.5 Medium |
| A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to stack-based buffer overflow. The attack can be launched remotely. This patch is called ad730304052937c32b4eb489a06835ac6123632c. It is best practice to apply a patch to resolve this issue. | ||||
| CVE-2026-51897 | 2026-10-05 | 9.8 Critical | ||
| RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution | ||||
| CVE-2026-49885 | 1 Google | 1 Android | 2026-10-05 | 7.8 High |
| In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||