Export limit exceeded: 51431 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (51431 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104433 | 1 Kvcache-ai | 1 Mooncake | 2026-10-03 | 7.5 High |
| Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference server. | ||||
| CVE-2026-67989 | 2026-10-02 | 7.5 High | ||
| crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x | ||||
| CVE-2026-105048 | 2026-10-02 | 4 Medium | ||
| The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses). | ||||
| CVE-2026-84411 | 1 Mikrotik | 1 Routeros | 2026-10-02 | 9.8 Critical |
| The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request. | ||||
| CVE-2026-105050 | 1 Peazip | 1 Peazip | 2026-10-02 | N/A |
| PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled. | ||||
| CVE-2026-103956 | 2026-10-02 | 10 Critical | ||
| Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to managed agent roles, via any request to the application API in a deployment where no identity provider is configured. To remediate this issue, users should upgrade to version 1.6.1 or later. | ||||
| CVE-2026-103552 | 1 Apache | 1 Directory Ldap Api | 2026-10-02 | 7.3 High |
| Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a deeply nested search filter that overflows the stack in the server's decoder. This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9. Users are recommended to upgrade to version 1.2.9, which fixes the issue. | ||||
| CVE-2026-103036 | 1 Middleapi | 1 Orpc | 2026-10-02 | 6.5 Medium |
| oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.9, the @orpc/json-schema SmartCoercionPlugin uses JsonSchemaCoercer to collect object properties in a plain object and to resolve schema.properties entries through the prototype chain. A remote client that can reach a procedure with an object input schema can supply __proto__ to replace the prototype of the single coerced request object, or supply Object.prototype member names such as constructor and toString so inherited values are treated as sub-schemas and pass the coercer's satisfaction check. Attacker-controlled inherited properties can consequently affect handler, Object.assign, or configuration lookups, while legitimate __proto__ properties are dropped. The global Object.prototype, unrelated objects, other requests, and other users are not modified, and downstream schema validation still runs. This issue is fixed in version 1.14.9. | ||||
| CVE-2026-103918 | 1 Middleapi | 1 Orpc | 2026-10-02 | 6.5 Medium |
| oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.10, the @orpc/zod ZodSmartCoercionPlugin and experimental_ZodSmartCoercionPlugin collect object and record properties in plain objects and resolve shape keys through the prototype chain. A remote client that can reach a procedure with an object or record input can supply __proto__ to replace the prototype of the returned request object, allowing attacker-controlled inherited values to reach application lookups. For object schemas, keys such as constructor, toString, and __proto__ can instead resolve inherited members as Zod schemas and cause an unhandled TypeError before validation. The global Object.prototype, unrelated objects, other requests, and other users are not modified, and the availability effect is limited to crafted requests rather than persistent process-wide state. This issue is fixed in version 1.14.10. | ||||
| CVE-2026-96940 | 1 Microsoft | 7 Exchange Server 2016, Exchange Server 2019, Exchange Server Se and 4 more | 2026-10-02 | 8.8 High |
| Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. | ||||
| CVE-2026-42528 | 2 Apache, Redhat | 2 Http Server, Hummingbird | 2026-10-02 | 4.3 Medium |
| A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to version 2.4.69, which fixes this issue | ||||
| CVE-2026-90451 | 1 Cisagov | 1 Malcolm | 2026-10-02 | 5.9 Medium |
| An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that regenerates the value will use the known default, allowing an attacker aware of the default to forge valid authentication cookies for that component. | ||||
| CVE-2026-90455 | 1 Cisagov | 1 Malcolm | 2026-10-02 | 3.7 Low |
| A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a single fixed, trusted vendor URL at initialization and does not process attacker-controlled input through the library, limiting practical exploitability of the reintroduced version in this context. | ||||
| CVE-2026-100255 | 1 Jetbrains | 1 Teamcity | 2026-10-02 | 8.1 High |
| In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset | ||||
| CVE-2026-90456 | 1 Cisagov | 1 Malcolm | 2026-10-02 | 8.1 High |
| An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value. | ||||
| CVE-2026-100260 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 5.3 Medium |
| In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset | ||||
| CVE-2026-71448 | 1 Johnson Controls | 1 Easyio Fs32 | 2026-10-02 | N/A |
| : Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: before 3.0b63. | ||||
| CVE-2026-34494 | 1 Johnson Controls | 1 Neo Series Mvp2 | 2026-10-02 | N/A |
| - On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue affects Neo Series MVP2: before 3.3b63. | ||||
| CVE-2026-34493 | 1 Johnson Controls | 1 Easyio Fs32 | 2026-10-02 | N/A |
| - On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations. This issue affects EasyIO FS32: before 3.3b63. | ||||
| CVE-2026-18397 | 1 Thales | 1 Sconnect | 2026-10-02 | N/A |
| This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component. The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks. | ||||