Export limit exceeded: 402651 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402651 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402651 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402651 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-106246 | 2026-10-06 | N/A | ||
| Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106214 | 1 Google | 1 Chrome | 2026-10-06 | 5.3 Medium |
| Information leak in Proxy in Google Chrome on on Windows prior to 155.0.8059.39 allowed an adjacent attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: High) | ||||
| CVE-2026-106212 | 1 Google | 1 Chrome | 2026-10-06 | 8.8 High |
| Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-103005 | 1 Elastic | 1 Elasticsearch | 2026-10-06 | 6.5 Medium |
| Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management privileges could cause the cluster to allocate an uncontrolled amount of memory when connector resources with an excessively large `description` field are created and subsequently accessed, exhausting available heap memory and crashing the affected node. | ||||
| CVE-2026-103006 | 1 Elastic | 1 Elasticsearch | 2026-10-06 | 6.5 Medium |
| Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted, deeply nested request submitted to the aggregation feature of the search API. Elasticsearch contains an uncontrolled recursion weakness in its search aggregation processing. An authenticated user with read access to a single index can submit a specially crafted request containing deeply nested aggregation definitions. Processing this request triggers unbounded recursive execution that exhausts the server process's available resources, causing the affected node to terminate. The node does not recover automatically and requires manual intervention to restore service. | ||||
| CVE-2026-88394 | 2026-10-06 | 7.5 High | ||
| WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The project task export endpoint /api/project/task/export downloads an arbitrary file from the server when the data parameter is supplied with a crafted JSON payload. The file value inside the JSON is concatenated directly into storage_path($file) without any path normalization or directory boundary check, so directory traversal (../) escapes the storage/ directory and response()->download() streams any file readable by the web server process. | ||||
| CVE-2026-105170 | 1 Kishor-23 | 1 Food-waste-management-system | 2026-10-06 | 7.3 High |
| A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file admin/signup.php of the component Admin Signup. This manipulation of the argument sign causes missing authentication. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-105166 | 1 Kishor-23 | 2 Food-waste-management-system, Food Waste Management System | 2026-10-06 | 7.3 High |
| A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of the file fooddonateform.php of the component Food Donation Form. Performing a manipulation of the argument image-choice results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-105161 | 1 Invariant-systems-ai | 1 Aiir | 2026-10-06 | 5.3 Medium |
| A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The attack can be executed remotely. It is advisable to upgrade the affected component. The GitHub repository of this project is not available anymore. This vulnerability only affects products that are no longer supported by the maintainer. | ||||
| CVE-2026-106509 | 2026-10-06 | 7.7 High | ||
| Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs theme configuration in techdocs. When TechDocs is configured to build documentation locally or in a container, a user with write access to a registered repository can include configuration values in mkdocs.yml that cause arbitrary code execution during the documentation build process. This issue is fixed in versions 1.14.6 and 1.15.4. | ||||
| CVE-2026-106508 | 2026-10-06 | 5.3 Medium | ||
| Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. When using the local TechDocs publisher (techdocs.publisher.type: 'local'), it was possible for the documentation serving endpoint to follow filesystem references outside the intended documentation tree, potentially exposing host files to authenticated users. This is mitigated by the fact that exploration requires preconditions that do not arise through normal MkDocs operation. Cloud-based publishers (S3, GCS, Azure Blob Storage) are not affected. This issue is fixed in version 1.15.4. | ||||
| CVE-2026-106507 | 2026-10-06 | 5.3 Medium | ||
| Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. Unsafe path resolution in TechDocs source tree handling allows an authenticated user who can register documentation sources to include content from outside the intended documentation boundary. Depending on deployment, this may expose files readable by the build process. This issue is fixed in version 1.15.4. | ||||
| CVE-2026-106288 | 2026-10-06 | N/A | ||
| Missing authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-104047 | 1 Redhat | 2 Enterprise Linux, Openshift | 2026-10-06 | 5.3 Medium |
| A flaw was found in SSSD. When configured to use Microsoft Entra ID, search inputs are not properly sanitized before being incorporated into directory query filters. A local user can exploit this vulnerability by submitting a crafted lookup request, manipulating the query logic to cause unauthorized information disclosure from the directory. | ||||
| CVE-2026-106506 | 2026-10-06 | 5.3 Medium | ||
| Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list ordering. An authenticated Backstage user with permission to create and read relevant scaffolder tasks may be able to infer confidential task data under specific conditions. Successful exploitation requires retained task secrets, visibility of a target task, knowledge of the secret structure, and repeated requests. This issue is fixed in version 4.1.0. | ||||
| CVE-2026-106505 | 2026-10-06 | 7.7 High | ||
| Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by bypass of mkdocs configuration sanitizer in techdocs backend. Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer introduced in response to CVE-2026-25153 and execute arbitrary code on the TechDocs backend host during documentation generation. This issue is fixed in versions 1.14.6 and 1.15.4. | ||||
| CVE-2026-106504 | 2026-10-06 | 6.5 Medium | ||
| Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder task logs. An authenticated user who can create and read scaffolder tasks may be able to observe sensitive values in task logs in deployments with restrictive action permissions and affected templates. Exploitation requires a denied action whose input contains such a value. This issue is fixed in version 4.1.0. | ||||
| CVE-2026-39758 | 2 Midtrans, Wordpress-extensions | 2 Midtrans-woocommerce, Midtrans-woocommerce | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Midtrans-WooCommerce <= 2.32.3 versions. | ||||
| CVE-2026-39759 | 2 Amentotech, Wordpress-extensions | 2 Workreap, Workreap | 2026-10-06 | 9.9 Critical |
| Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions. | ||||
| CVE-2026-39761 | 2 Elightup, Wordpress-extensions | 2 Meta Box Aio, Meta Box Aio | 2026-10-06 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Meta Box AIO <= 3.7.1 versions. | ||||