Export limit exceeded: 403800 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 403800 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (403800 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-25270 1 Qualcomm 407 Cologne, Cologne Firmware, Congo and 404 more 2026-10-09 6.7 Medium
Memory corruption when processing command buffer requests with invalid length parameters in the Android Camera driver.
CVE-2026-25269 1 Qualcomm 313 Cologne, Cologne Firmware, Cq2390m and 310 more 2026-10-09 6.7 Medium
Memory corruption when processing camera requests with excessive batch and IO buffer configurations exceeds allocated memory size.
CVE-2026-25267 1 Qualcomm 333 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, 9205 Lte Modem and 330 more 2026-10-09 7.8 High
Memory corruption when non-secure loader rewrites page tables before secure memory initialization.
CVE-2026-25263 1 Qualcomm 333 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, 9205 Lte Modem and 330 more 2026-10-09 6.6 Medium
Memory corruption while processing IOCTL command called from user space to the kernel with invalid parameters.
CVE-2026-108103 1 Open5gs 1 Open5gs 2026-10-09 5.3 Medium
Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_dropped_dl_traffic_threshold() that allows remote unauthenticated attackers to read past IE buffers via short IEs. Attackers can send PFCP Session Establishment or Modification Requests to the UPF on UDP port 8805 with DLPA and DLBY flags set, potentially crashing the UPF.
CVE-2026-108101 1 Hortusfox 1 Hortusfox 2026-10-09 7.5 High
HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under public/attachments/. Attackers can upload HTML or SVG files via /plants/attachments/add for stored cross-site scripting, or PHP files where .htaccess is unenforced to execute code.
CVE-2026-108100 1 Hortusfox 1 Hortusfox 2026-10-09 6.5 Medium
HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes.
CVE-2026-96890 1 Github 1 Enterprise Server 2026-10-09 8.8 High
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed a repository contributor to cause the appliance to issue requests to attacker-controlled internal hosts, which could be chained to achieve remote code execution on the appliance. The secret scanning validator for GCP service account credentials trusted the token endpoint embedded in a committed credential and issued a request to it without restricting the destination. Exploitation required an authenticated user with permission to push to a repository on an instance with GitHub Advanced Security and secret scanning validity checks enabled, a non-default configuration. This vulnerability affected GitHub Enterprise Server 3.20, 3.21, and 3.22 and was fixed in versions 3.20.9, 3.21.7, and 3.22.2. This vulnerability was reported through the GitHub Bug Bounty program.
CVE-2026-107781 1 Dromara 1 Skyeye 2026-10-09 7.4 High
Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side request forgery and missing authorization vulnerability in the OnlyOffice save callback editUploadOfficeFileById. Unauthenticated attackers can supply arbitrary url and key parameters to make the server fetch internal URLs and overwrite any user's stored file, then read results via queryFileToShowById.
CVE-2026-105278 2026-10-09 9.8 Critical
The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use. An attacker with network access to the management interface can authenticate using this credential and gain full administrative control of the application.
CVE-2026-94067 2026-10-09 8.1 High
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fuelthemes The Voux thevoux-wp allows PHP Local File Inclusion.This issue affects The Voux: from n/a through 6.9.5.
CVE-2026-94065 2026-10-09 8.8 High
Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio colorit allows Object Injection.This issue affects ColorFolio: from n/a through 1.3.
CVE-2026-94064 2026-10-09 8.8 High
Deserialization of Untrusted Data vulnerability in BuddhaThemes Neo | Barber Shop WordPress Theme neocut allows Object Injection.This issue affects Neo | Barber Shop WordPress Theme: from n/a through 3.5.
CVE-2026-85479 2026-10-09 5.3 Medium
The STTP-based data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and exchange data with it.
CVE-2026-105281 2026-10-09 7.5 High
The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve the complete device and measurement topology of the system.
CVE-2026-100730 2026-10-09 9.8 Critical
A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which could allow remote code execution under the privileges of the affected service account.
CVE-2026-104079 2026-10-09 4.3 Medium
Envira Gallery Lite before 1.16.2 contains a missing authorization vulnerability in its gallery conversion REST endpoint that allows lower-privileged authenticated users to create and publish Envira galleries without the required capabilities, because the endpoint only checks edit permissions on the source post and uses a hard-coded publish status. Attackers can also supply arbitrary caller-controlled image IDs without ownership verification to publish unauthorized content using attachments they are not authorized to use.
CVE-2026-103006 1 Elastic 1 Elasticsearch 2026-10-09 6.5 Medium
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted, deeply nested request submitted to the aggregation feature of the search API. Elasticsearch contains an uncontrolled recursion weakness in its search aggregation processing. An authenticated user with read access to a single index can submit a specially crafted request containing deeply nested aggregation definitions. Processing this request triggers unbounded recursive execution that exhausts the server process's available resources, causing the affected node to terminate. The node does not recover automatically and requires manual intervention to restore service.
CVE-2026-103007 1 Elastic 1 Elasticsearch 2026-10-09 7.2 High
Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch contains an incorrect authorization weakness in a configurable, non-default privilege that lets an administrator delegate limited role-management capability to another user, scoped to specific indices. The authorization check that enforces this scoping does not correctly account for a role-definition setting that can expand the matched index set. A user holding this delegated privilege with a broadly-scoped index pattern can exploit this inconsistency by updating their own assigned role to gain access to indices that should remain restricted, including internal security data. This can enable further escalation up to full administrative control of the cluster.
CVE-2026-100833 1 Edgelesssys 1 Contrast 2026-10-09 9.6 Critical
Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule that accepts storage entries using the `image_guest_pull` driver without verifying the image digest. An attacker with access to the Kata agent API — for example, a Kubernetes cluster administrator in Contrast's threat model — can therefore substitute a container image with an exploit payload, provided the substituted image satisfies the remaining policy rules, undermining the confidential container's integrity guarantees.