Export limit exceeded: 11003 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 401179 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (401179 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104413 | 1 Ghost | 1 Ghost | 2026-10-02 | 7.3 High |
| Ghost from 5.94.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users, including Contributors, to host arbitrary HTML by abusing bookmark card image fetching. Attackers can create bookmark cards that store non-image files from external websites as icons or thumbnails to compromise other staff users' admin sessions. | ||||
| CVE-2026-104059 | 1 Lektor | 1 Lektor | 2026-10-02 | 8.1 High |
| Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer validation, CORS configuration, or Host allowlisting. Attackers can exploit the newattachment, deleterecord, build, clean, and publish endpoints from a malicious web page to write arbitrary files, delete pages, wipe build output, trigger deployment publication, and via DNS rebinding reach read endpoints to disclose data. | ||||
| CVE-2026-103766 | 2 Macwarrior, Oxygenz | 2 Clipbucket-v5, Clipbucket | 2026-10-02 | 7.2 High |
| ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated users with ad_manager_access permission to inject SQL via the delete parameter in admin_area/ads_manager.php. Attackers can supply time-based blind payloads concatenated into AdsManager::DeleteAd queries to extract user credentials and emails or modify and delete arbitrary records. | ||||
| CVE-2026-103760 | 1 Kvcache-ai | 1 Mooncake | 2026-10-02 | 5.9 Medium |
| Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests. | ||||
| CVE-2026-103591 | 1 Asyncfuncai | 1 Deepwiki-open | 2026-10-02 | 7.5 High |
| DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment checks and read any file accessible to the API process by specifying absolute file paths. | ||||
| CVE-2026-100665 | 1 Netty | 1 Netty | 2026-10-02 | 7.5 High |
| Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, preventing endpoint identification from running even when HTTPS verification is configured. Attackers on the network path can present a certificate chain for the wrong hostname that the plain trust manager accepts, bypassing hostname authentication for QUIC clients. | ||||
| CVE-2026-104914 | 1 Misp | 1 Misp | 2026-10-02 | N/A |
| MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints. When a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute listing), the application returned soft-deleted attributes belonging to events owned by other organizations to any authenticated user who had visibility of the event. The event detail view correctly restricted soft-deleted attribute visibility to the owning organization and sync-permission users, but the attribute search and paginated view code paths lacked this restriction. Preconditions: - An authenticated MISP user with at least read access to an event owned by another organization. - The user issues a query for deleted attributes (search or paginated view with the deleted filter). Impact: - Confidentiality: Soft-deleted threat intelligence attributes (e.g., IOCs, indicators, context) from other organizations are disclosed to unauthorized users. This may expose sensitive intelligence that the owning organization intended to remove from general visibility. Affected versions: MISP versions prior to v2.5.48. | ||||
| CVE-2026-100276 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 5.9 Medium |
| In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action | ||||
| CVE-2026-100277 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 8.9 High |
| In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature | ||||
| CVE-2026-84386 | 1 Fortinet | 1 Forticlientwindows | 2026-10-02 | 4.7 Medium |
| A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via via an exposed minifilter communication port. | ||||
| CVE-2026-104286 | 1 Fortinet | 1 Fortimail | 2026-10-02 | 9.8 Critical |
| An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. | ||||
| CVE-2026-94648 | 1 Apache | 1 Thrift | 2026-10-02 | N/A |
| Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||
| CVE-2026-94653 | 1 Apache | 1 Thrift | 2026-10-02 | N/A |
| Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||
| CVE-2026-100278 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 4.9 Medium |
| In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments | ||||
| CVE-2026-100279 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials | ||||
| CVE-2026-100280 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 3.1 Low |
| In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible | ||||
| CVE-2026-95385 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-10-02 | 6.5 Medium |
| Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-51857 | 2026-10-02 | 9.8 Critical | ||
| In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary. | ||||
| CVE-2026-51861 | 1 Dataelement | 1 Bisheng | 2026-10-02 | 9.8 Critical |
| bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Code Injection in src/backend/bisheng/api/v1/validate.py. | ||||
| CVE-2026-51867 | 2026-10-02 | 9.8 Critical | ||
| agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object. | ||||