Export limit exceeded: 401603 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 401603 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (401603 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-105693 | 1 Penpot | 1 Penpot | 2026-10-05 | 5.3 Medium |
| Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the caller authenticated with only one scoped share link. A holder of a restrictive link can obtain other links' secret IDs, page scopes, comment permissions, and inspection permissions, then replay a more permissive token to access page data that was not included in the original share. This issue is fixed in version 2.18.0. | ||||
| CVE-2026-105694 | 1 Penpot | 1 Penpot | 2026-10-05 | 5.4 Medium |
| Penpot is an open-source design and prototyping platform. Prior to 2.18.0, authenticated users with file-edit permission can upload SVG media whose scripts, event-handler attributes, and foreignObject elements are stored without sanitization and served as image/svg+xml from the Penpot origin. A victim who navigates to the asset URL executes attacker-controlled JavaScript in that origin, allowing requests and data access with the victim's Penpot session authority. This issue is fixed in version 2.18.0. | ||||
| CVE-2026-105695 | 1 Penpot | 1 Penpot | 2026-10-05 | 5.9 Medium |
| Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticated user who obtains another user's live, completed upload-session UUID can assemble the victim's chunks into the attacker's own file, team font, or project import, disclosing the uploaded bytes and deleting the victim's pending session. This issue is fixed in version 2.18.0. | ||||
| CVE-2026-105696 | 1 Penpot | 1 Penpot | 2026-10-05 | 6.5 Medium |
| Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-page RPC accepts a share-link permission object with blanket read access but does not verify that the caller-selected page-id belongs to the link's authorized pages set. An attacker with both a valid share link and the attacker's own authenticated Penpot session can retrieve the complete shape and design data of another page in the same file when its identifier is known, because get-page requires authentication. The related get-file-fragment RPC also permits share-link access without mapping fragments to authorized pages. This issue is fixed in version 2.18.0. | ||||
| CVE-2026-102295 | 2 Red Hat, Redhat | 2 Red Hat Quay 3, Quay | 2026-10-05 | 5.4 Medium |
| A flaw was found in Quay. A cross-site scripting (XSS) vulnerability in the OAuth callback handler allows a remote attacker to execute arbitrary JavaScript code within a user's browser session. By tricking a logged-in user into visiting a specially crafted link, an attacker can exploit improper input sanitization to run client-side scripts in the application context. Successful exploitation could allow the attacker to compromise the user's session, access sensitive registry information, or perform unauthorized actions on their behalf. | ||||
| CVE-2026-91107 | 1 Os4ed | 1 Opensis-classic | 2026-10-05 | N/A |
| openSIS Classic 9.3 allows an authenticated user with the built-in teacher role can select an arbitrary staff record through staff_id and cause the School Information update path to reset that selected account's password. | ||||
| CVE-2026-94544 | 1 Vercel | 1 Next.js | 2026-10-05 | 4.2 Medium |
| Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An overlapping regular request can receive unauthenticated unpublished content from an editor's Draft Mode fill, while an overlapping Draft Mode request can receive published content from a regular fill. When the regular request prerenders a page, the draft-dependent content can persist in the generated page and be served to later visitors until revalidation. Sites are affected when Cache Components or experimental.useCache is enabled and cached functions return draft-dependent content. This issue is fixed in version 16.3.8. | ||||
| CVE-2026-93354 | 1 Gimanh | 1 Taskview-community | 2026-10-05 | 8.1 High |
| Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint, which is enabled by default and requires no authentication. Attackers can send a POST request to the registration endpoint to obtain a client_id and client_secret, then craft a malicious authorization link pointing to an attacker-controlled redirect URI to capture authorization codes and exchange them for access tokens granting full API access to victim account data. | ||||
| CVE-2026-82045 | 1 Utmstack | 1 Utmstack | 2026-10-05 | 6.5 Medium |
| UTMStack before 11.2.16 contains a JPQL injection vulnerability that allows authenticated attackers to read arbitrary entity data by exploiting UtmNetworkScanService.searchPropertyValues(), which builds a JPQL query with String.format() and executes it via em.createQuery() without parameter binding. Attackers can inject malicious JPQL through the value parameter in the GET /api/utm-network-scans/searchPropertyValues endpoint to extract sensitive data including credential tables such as jhi_user. | ||||
| CVE-2026-82040 | 1 Utmstack | 1 Utmstack | 2026-10-05 | 5 Medium |
| UTMStack before 11.2.16 contains a server-side request forgery vulnerability in IdentityProviderService.validateMetadataUrl() that allows authenticated attackers to make the server send requests to arbitrary internal or cloud metadata hosts by supplying a malicious metadata URL to the identity-providers endpoint. Attackers can exploit the POST/PUT /api/identity-providers endpoint with no validation of target host, IP, or scheme to perform internal network port scanning and access cloud instance-metadata services. | ||||
| CVE-2026-76782 | 1 Drupal | 1 Screenshot | 2026-10-05 | 7.3 High |
| Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*. | ||||
| CVE-2026-70650 | 1 Getsimple-ce | 1 Getsimple Cms | 2026-10-05 | N/A |
| GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is saved, but the backup viewer decodes them again (htmldecode() / strip_decode()) and prints the result without re-escaping. A user who can edit a page can store JavaScript in a page's Keywords, Description, Menu text or Content; it executes in the browser of any administrator who later views that page's backup, in the context of the admin control panel. At time of publication, there are no publicly available patches. | ||||
| CVE-2026-55251 | 1 Netbox-community | 1 Devicetype-library | 2026-10-05 | 6.5 Medium |
| NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to commit f41fc1e, the CI workflow .github/workflows/validation.yml runs on pull_request and executes code supplied by the pull request before any maintainer review. Three PR-editable files drive this: "requirements.txt", ".pre-commit-hooks-config.yaml" / ".pre-commit-yamlfmt-config.yaml", and ".gitmodules". A contributor with no special repository access could open a pull request that modifies these files and have their code run on the CI runner. This issue has been patched via commit f41fc1e. | ||||
| CVE-2026-53953 | 1 Getsimple-ce | 1 Getsimple Cms | 2026-10-05 | 9.1 Critical |
| GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and immediately stores its hash as the user's new password. The temporary password is generated using PHP rand() seeded with microtime(). Because this seed is time-based and has a limited effective search space, an attacker can generate possible reset password candidates. Since the admin login endpoint does not enforce rate limiting or account lockout, these candidates can be tested online until the correct password is found. Successful exploitation may lead to administrator account takeover. At time of publication, there are no publicly available patches. | ||||
| CVE-2026-105294 | 2026-10-05 | 7.4 High | ||
| Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set additionalArguments to persistently add --proxy-server and --ignore-certificate-errors switches, routing all client traffic through an interception proxy. | ||||
| CVE-2026-105221 | 2026-10-05 | 7.4 High | ||
| The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists. | ||||
| CVE-2026-105216 | 2 Micro, Micro-ecc Project | 2 Go-micro, Micro-ecc | 2026-10-05 | 7.4 High |
| go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials. | ||||
| CVE-2026-105214 | 1 Zitadel | 1 Zitadel | 2026-10-05 | N/A |
| Zitadel before 4.16.2 contains a server-side request forgery vulnerability that allows attackers to make the server request internal resources through organization domain HTTP verification. The challenge fetch uses Go's default http.Get instead of the protected client, so attackers can register domains that redirect to loopback, internal, or cloud metadata addresses to scan ports and map internal networks. | ||||
| CVE-2026-105209 | 1 Zitadel | 1 Zitadel | 2026-10-05 | 9.6 Critical |
| ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account. | ||||
| CVE-2026-105131 | 1 Mayswind | 1 Ezbookkeeping | 2026-10-05 | 5.4 Medium |
| ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because TokenRefreshHandler never checks token type, attackers can exchange short-lived or IP-restricted API tokens for 30-day normal session tokens that bypass API token expiry and allowlists. | ||||