Export limit exceeded: 401185 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (401185 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104402 | 2 Farvisun, Wordpress-extensions | 2 Mindio Magic Mcp, Mindio Magic Mcp | 2026-10-04 | 4.3 Medium |
| Insertion of Sensitive Information Into Sent Data vulnerability in farvisun Mindio Magic MCP mindio-magic-mcp allows Retrieve Embedded Sensitive Data.This issue affects Mindio Magic MCP: from n/a through 0.5.6. | ||||
| CVE-2026-105216 | 2 Micro, Micro-ecc Project | 2 Go-micro, Micro-ecc | 2026-10-04 | 7.4 High |
| go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials. | ||||
| CVE-2026-105218 | 1 Go-pay | 1 Gopay | 2026-10-04 | 7.4 High |
| gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses. | ||||
| CVE-2026-75762 | 1 Redhat | 1 Multicluster Globalhub | 2026-10-04 | 6.8 Medium |
| No description is available for this CVE. | ||||
| CVE-2026-80220 | 1 Postgres-exporter | 1 Postgres-exporter | 2026-10-04 | 5.4 Medium |
| No description is available for this CVE. | ||||
| CVE-2026-76594 | 1 Advisor-backend | 1 Advisor-backend | 2026-10-04 | 8.1 High |
| A flaw was found in advisor-backend. A network-adjacent unauthenticated attacker could exploit a vulnerability in the `/private/import_content/` endpoint, which lacks proper authentication and permission checks. This allows the attacker to overwrite the global Advisor rule, resolution, and playbook catalogue. When combined with another vulnerability involving unsafe YAML deserialization, this could lead to arbitrary code execution on affected systems. | ||||
| CVE-2026-76595 | 1 Advisor-backend | 1 Advisor-backend | 2026-10-04 | N/A |
| A flaw was found in advisor-backend. Multiple code paths within the application deserialize YAML (YAML Ain't Markup Language) with an unsafe full Loader, which can instantiate arbitrary Python objects via YAML tags. An unauthenticated remote attacker can exploit this by submitting specially crafted YAML input, leading to remote code execution (RCE) within the `advisor-backend` pod. This compromise could allow access to shared database credentials and impact all tenants. | ||||
| CVE-2026-87052 | 1 Operator-foundry | 1 Operator-foundry | 2026-10-04 | 2.6 Low |
| A flaw was found in operator-foundry. The absence of automated dependency-update and vulnerability-scanning configurations in the repository increases the risk of undetected security vulnerabilities. This lack of automated security checks could potentially lead to the inclusion of known vulnerable components, which might then be exploited by an attacker if those underlying vulnerabilities are present and exploitable. | ||||
| CVE-2026-87054 | 1 Operator-sdk-builder | 1 Operator-sdk-builder | 2026-10-04 | 4.2 Medium |
| A flaw was found in operator-sdk-builder. The containers-policy.json configuration file defaults to insecureAcceptAnything for container image registries that are not explicitly listed. This default setting causes signature verification to be entirely skipped for images pulled from these unlisted registries, which could allow for the use of untrusted or malicious container images. | ||||
| CVE-2026-87057 | 1 Olm-operator-konflux-sample | 1 Olm-operator-konflux-sample | 2026-10-04 | 4.2 Medium |
| A flaw was found in olm-operator-konflux-sample. The build pipelines use mutable floating tags to reference runtime base images instead of immutable SHA256 digests. This configuration allows for the content of the base images to be altered without detection, potentially leading to the introduction of malicious code or unexpected changes in the build process. An attacker could exploit this to compromise the integrity of the software supply chain. | ||||
| CVE-2026-87061 | 1 Olm-operator-konflux-sample | 1 Olm-operator-konflux-sample | 2026-10-04 | 2.6 Low |
| A flaw was found in olm-operator-konflux-sample. The `bundle-hack/update_bundle.sh` script lacks mechanisms to stop execution immediately upon encountering an error. This oversight allows critical data processing steps, such as those involving `skopeo` or `jq` commands, to fail silently and proceed with outdated or incomplete information. Consequently, this could lead to data integrity issues within the system. | ||||
| CVE-2026-87064 | 1 Konflux-operator-tasks | 1 Konflux-operator-tasks | 2026-10-04 | 2.6 Low |
| A flaw was found in konflux-operator-tasks. The GitHub workflows used by this component do not explicitly define their required permissions. This oversight means the workflows may inherit default access tokens that grant broader privileges than intended. Such excessive permissions could potentially allow an attacker to gain unauthorized access or perform actions beyond the intended scope, leading to information disclosure or unauthorized modifications. | ||||
| CVE-2026-96577 | 2 Oc-mirror, Redhat | 3 Oc-mirror, Assisted Installer, Openshift | 2026-10-04 | 7.1 High |
| A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an adjacent network can connect to the exposed service to push tampered container images, delete cached images, or access mirrored content. | ||||
| CVE-2026-94282 | 2 Libxi, X.org | 2 Libxi, Libxi | 2026-10-04 | 5.6 Medium |
| An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client. | ||||
| CVE-2026-95622 | 1 Modemmanager | 1 Modemmanager | 2026-10-04 | 6.5 Medium |
| A flaw was found in ModemManager. When parsing a Cell Broadcast Message, some 3GPP data-coding-scheme values (8-bit and reserved character sets) are not handled. The process hits a reachable assertion and aborts. An attacker who can deliver a crafted Cell Broadcast PDU over the radio network, or via a modem AT channel, can cause ModemManager to exit. Repeated aborts can exhaust systemd's default start limit and leave the service failed. | ||||
| CVE-2026-94603 | 1 Podman Project | 1 Podman | 2026-10-04 | 8.6 High |
| A flaw was found in Podman. When a container image with checkpoint annotations is executed using the podman run command, Podman treats the image as a restored checkpoint and ignores user-specified sandboxing options, such as dropped privileges. An attacker can exploit this issue by enticing a user to run a specially crafted image, leading to a container sandbox bypass and potential execution with elevated system privileges. | ||||
| CVE-2026-103431 | 1 Collectl | 1 Collectl | 2026-10-04 | 7.7 High |
| colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored host to inject escape sequences into the terminal of an operator running colmux, via a crafted process name (argv[0]). | ||||
| CVE-2026-67172 | 1 Hcltech | 1 Bigfix Service Management | 2026-10-04 | 3.7 Low |
| HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to certain API endpoints . This information could enable an attacker to facilitate further attacks. | ||||
| CVE-2025-31980 | 1 Hcltech | 1 Bigfix Service Management | 2026-10-04 | 4.3 Medium |
| HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, enabling potential injection attacks or errors in downstream processing systems. | ||||
| CVE-2026-12423 | 2 Redhat, Theforeman | 4 Satellite, Satellite Capsule, Satellite Utils and 1 more | 2026-10-04 | 7.5 High |
| A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the server's valid_host_token? method evaluates to true, granting access to the kickstart template even if the requester provides no token at all in the URL. | ||||