Export limit exceeded: 403995 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403995 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-83589 | 2 Oauth2 Proxy Project, Redhat | 2 Oauth2 Proxy, Openshift | 2026-10-06 | 6.1 Medium |
| A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft. | ||||
| CVE-2026-98233 | 1 Linux | 1 Linux Kernel | 2026-10-06 | 5.5 Medium |
| In the Linux kernel, the following vulnerability has been resolved: net/packet: clear RX owner on VNET header error Commit 61fad6816fc1 ("net/packet: tpacket_rcv: avoid a producer race condition") added rx_owner_map and made tpacket_rcv() claim a V1 or V2 ring slot before converting the virtio-net header. If the conversion fails, the drop path leaves the slot claimed. With a one-frame TPACKET_V2 ring, an unsupported UDP GSO packet leaves the only slot unavailable, so the ring also drops the next valid packet. Clear the ownership bit on this error path. TPACKET_V3 already clears its block state here. | ||||
| CVE-2026-98242 | 1 Linux | 1 Linux Kernel | 2026-10-06 | 5.5 Medium |
| In the Linux kernel, the following vulnerability has been resolved: dma-buf: Fix silent overflow for phys vec to sgt In case MMIO size is bigger than 4G and peer2peer DMA goes through host bridge, we trigger a code path that assigns the total linked IOVA (which is greater than 4G) to mapped_len. Previously, `mapped_len` was declared as 32-bit `unsigned int`. When accumulating `size_t` lengths, this leads to a silent wrap-around. This truncation causes truncated lengths to be passed to functions like `fill_sg_entry()`. Fix this by changing `mapped_len` to `size_t` (64-bit). While at it, fix similar potential overflow issues in `calc_sg_nents` by using `check_add_overflow()` for `nents` and using `unsigned int` for the loop iterator in `fill_sg_entry` to match. | ||||
| CVE-2026-105207 | 1 Zitadel | 1 Zitadel | 2026-10-06 | 9.8 Critical |
| ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim. | ||||
| CVE-2026-105149 | 1 Moosocial | 1 Moosocial | 2026-10-06 | 7.3 High |
| A security flaw has been discovered in mooSocial up to 3.2.4. This issue affects some unknown processing of the file /stores/all-products. Performing a manipulation of the argument rating results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-105145 | 1 Weaviate | 1 Verba | 2026-10-06 | 5.3 Medium |
| A vulnerability has been found in Weaviate Verba up to 2.1.3. Affected by this vulnerability is the function get_environment of the file goldenverba/components/util.py of the component generate_stream Endpoint. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-105135 | 1 Internlm | 1 Mindsearch | 2026-10-06 | 10 Critical |
| A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-105089 | 1 Wwbn | 1 Avideo | 2026-10-06 | 8.7 High |
| WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe src attributes to execute JavaScript in victims' browsers. | ||||
| CVE-2026-105170 | 1 Kishor-23 | 1 Food-waste-management-system | 2026-10-06 | 7.3 High |
| A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file admin/signup.php of the component Admin Signup. This manipulation of the argument sign causes missing authentication. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-105166 | 1 Kishor-23 | 2 Food-waste-management-system, Food Waste Management System | 2026-10-06 | 7.3 High |
| A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of the file fooddonateform.php of the component Food Donation Form. Performing a manipulation of the argument image-choice results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-105161 | 1 Invariant-systems-ai | 1 Aiir | 2026-10-06 | 5.3 Medium |
| A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The attack can be executed remotely. It is advisable to upgrade the affected component. The GitHub repository of this project is not available anymore. This vulnerability only affects products that are no longer supported by the maintainer. | ||||
| CVE-2026-39758 | 2 Midtrans, Wordpress-extensions | 2 Midtrans-woocommerce, Midtrans-woocommerce | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Midtrans-WooCommerce <= 2.32.3 versions. | ||||
| CVE-2026-39759 | 2 Amentotech, Wordpress-extensions | 2 Workreap, Workreap | 2026-10-06 | 9.9 Critical |
| Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions. | ||||
| CVE-2026-39761 | 2 Elightup, Wordpress-extensions | 2 Meta Box Aio, Meta Box Aio | 2026-10-06 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Meta Box AIO <= 3.7.1 versions. | ||||
| CVE-2026-39762 | 2 Patterns In The Cloud, Wordpress-extensions | 2 Autoship Cloud For Woocommerce Subscription Products, Autoship Cloud For Woocommerce Subscription Products | 2026-10-06 | 6.5 Medium |
| Missing Authorization vulnerability in Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products autoship-cloud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.17.1. | ||||
| CVE-2026-39764 | 2 Radiustheme, Wordpress-extensions | 2 Radius Booking — Booking Calendar For Appointments & Services, Radius Booking | 2026-10-06 | 9.3 Critical |
| Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments & Services <= 1.0.19 versions. | ||||
| CVE-2026-39765 | 2 Webappick, Wordpress-extensions | 2 Challan, Challan | 2026-10-06 | 7.2 High |
| Shop Manager Privilege Escalation in Challan <= 3.7.88 versions. | ||||
| CVE-2026-39766 | 2 Reputeinfosystems, Wordpress-extensions | 2 Arforms, Arforms | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions. | ||||
| CVE-2026-39767 | 2 Baseapp, Wordpress-extensions | 2 Wpbase Cache, Wpbase Cache | 2026-10-06 | 6.5 Medium |
| Subscriber Denial of Service Attack in WPBase Cache <= 5.5.6 versions. | ||||
| CVE-2026-39769 | 2 Iqonicdesign, Wordpress-extensions | 2 Graphina, Graphina | 2026-10-06 | 7.5 High |
| Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions. | ||||