Export limit exceeded: 401266 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (401266 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-54403 | 1 Yonyou | 1 U8 Crm | 2026-10-02 | 7.5 High |
| Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath parameter. Attackers can exploit this flaw to read sensitive files outside the web application directory, including configuration files containing database or service credentials. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14. | ||||
| CVE-2026-91775 | 1 Limesurvey | 1 Limesurvey | 2026-10-02 | N/A |
| LimeSurvey Community Edition 7.0.14 fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface. | ||||
| CVE-2026-100264 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 2.7 Low |
| In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host | ||||
| CVE-2026-100265 | 1 Jetbrains | 1 Rider | 2026-10-02 | 4.8 Medium |
| In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation | ||||
| CVE-2026-51904 | 2026-10-02 | N/A | ||
| SuperAGI up to v0.0.14 contains an improper access control vulnerability in the agent execution controller. In affected source snapshots, create_agent_execution and create_agent_run in superagi/controllers/agent_execution.py accept a caller-supplied agent_id and fail to verify that the referenced agent belongs to the authenticated user's organization. A remote authenticated attacker from one organization can create or start execution records for agents owned by another organization through /agentexecutions/add or /agentexecutions/add_run. | ||||
| CVE-2026-12544 | 2 Redhat, Theforeman | 4 Satellite, Satellite Capsule, Satellite Utils and 1 more | 2026-10-02 | 7.7 High |
| A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection (SSTI) and insecure deserialization. This vulnerability can lead to remote code execution, total infrastructure compromise and supply chain risk. | ||||
| CVE-2026-100266 | 1 Jetbrains | 1 Hub | 2026-10-02 | 7.7 High |
| In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address | ||||
| CVE-2026-94645 | 1 Apache | 1 Thrift | 2026-10-02 | N/A |
| Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||
| CVE-2026-94644 | 1 Apache | 1 Thrift | 2026-10-02 | N/A |
| Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||
| CVE-2026-61373 | 1 Apache | 1 Thrift | 2026-10-02 | N/A |
| Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java TSaslNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||
| CVE-2026-100270 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 3.3 Low |
| In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations | ||||
| CVE-2026-100271 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 2.7 Low |
| In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects | ||||
| CVE-2026-100272 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 4.9 Medium |
| In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues | ||||
| CVE-2026-100273 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 8.2 High |
| In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution | ||||
| CVE-2026-51898 | 1 Sinaptik-ai | 1 Pandas-ai | 2026-10-02 | N/A |
| sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute. | ||||
| CVE-2026-51901 | 1 Transformeroptimus | 1 Superagi | 2026-10-02 | N/A |
| SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated users from one organization to schedule existing agents belonging to a different organization without proper authorization checks. The endpoint accepts an agent_id parameter but does not verify that the agent belongs to the authenticated user's organization. | ||||
| CVE-2026-94646 | 2 Apache, Redhat | 2 Thrift, Hummingbird | 2026-10-02 | 7.5 High |
| Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||
| CVE-2026-100274 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template | ||||
| CVE-2026-39717 | 2026-10-02 | 4.3 Medium | ||
| Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through 4.4.9.1. | ||||
| CVE-2026-39439 | 2026-10-02 | 6.5 Medium | ||
| Missing Authorization vulnerability in Kiera Howe WebSamurai websamurai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebSamurai: from n/a through 1.0.7. | ||||