Export limit exceeded: 403988 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (403988 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-101998 1 Docker 2 Docker Sandboxes, Sandboxes 2026-10-08 N/A
Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned data together with an error, affected handlers could forward unmasked bytes. Code inside an authorized sandbox could use this to recover host-managed OAuth access and refresh tokens or a derived Anthropic API key intended to remain outside the sandbox.
CVE-2026-107397 1 Indico 1 Indico 2026-10-08 4.4 Medium
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, users who can create content, including speakers who can create minutes, can store crafted HTML in event minutes. When concurrent edits are made to the same minutes, the minute editor conflict UI can execute attacker-controlled script in the viewer's browser in the Indico origin. This issue is fixed in version 3.3.13.
CVE-2026-107376 1 Webonyx 1 Graphql-php 2026-10-08 8.2 High
webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote attacker can submit deeply nested selection sets, object or list values, or list types that exhaust the PHP process stack during pre-validation parsing, before query validation and complexity controls run. The resulting SIGSEGV can terminate PHP-FPM workers or long-running Swoole, RoadRunner, ReactPHP, or CLI processes and cannot be caught by application-level exception handling. This issue is fixed in version 15.32.3.
CVE-2026-107393 1 Freescout Helpdesk 1 Freescout 2026-10-08 6.1 Medium
FreeScout is a self-hosted help desk and shared mailbox. Prior to 1.8.235, when APP_CLOUDFLARE_IS_USED is enabled, FreeScout trusts an unvalidated CF-Connecting-IP header during failed login attempts and stores the spoofed value in the activity log. LogsMonitor inserts the value into an administrator alert email without HTML escaping, allowing injected HTML to execute when an administrator opens the email. This issue is fixed in version 1.8.235.
CVE-2026-81932 1 Ibm 1 Guardium Data Protection 2026-10-08 8.6 High
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
CVE-2026-84247 1 Ibm 1 Guardium Data Protection 2026-10-08 8.1 High
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.
CVE-2026-93034 1 Sglang 1 Sglang 2026-10-08 9.8 Critical
SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() in _maybe_unwrap_pickle without type allowlisting or authentication; this vulnerability persists via the msgpack path even when SGLANG_USE_PICKLE_IPC is disabled, and becomes remotely exploitable if data-parallel attention is enabled with a non-loopback --dist-init-addr setting.
CVE-2026-66087 1 Apache 1 Dolphinscheduler 2026-10-08 8.1 High
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to operate task instance in projects they are not authorized to access through the  * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/stop * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/savepoint This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
CVE-2026-66084 1 Apache 1 Dolphinscheduler 2026-10-08 8.1 High
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint. The endpoint fails to verify that the task definition identified by code belongs to the project specified by projectCode. An authenticated user can supply the code of a project they are authorized to access together with a task definition code from another project, bypassing project access restrictions and modifying the target task definition and its upstream dependencies. This vulnerability can compromise workflow integrity and disrupt task execution in unauthorized projects.This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
CVE-2026-66082 1 Apache 1 Dolphinscheduler 2026-10-08 6.5 Medium
An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to perform unauthorized operations on workflow schedules, workflow definitions, and task instances in other projects. The affected endpoints check permissions against the supplied projectCode but fail to verify that the target resource belongs to that project. An authenticated user with the required permissions in one project can supply that project's code together with a resource identifier from another project, bypassing the target project's access restrictions. The affected endpoints include: * POST /projects/{projectCode}/schedules/{id}/online and /offline: Activate or deactivate workflow schedules in another project. * POST /projects/{projectCode}/workflow-definition/{code}/release: Change the ONLINE/OFFLINE state of workflow definitions in another project. Successful exploitation allows users to alter workflow availability and interfere with task execution in projects they are not authorized to access. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
CVE-2023-51764 3 Fedoraproject, Postfix, Redhat 3 Fedora, Postfix, Enterprise Linux 2026-10-08 5.3 Medium
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Postfix supports <LF>.<CR><LF> but some other popular e-mail servers do not. To prevent attack variants (by always disallowing <LF> without <CR>), a different solution is required, such as the smtpd_forbid_bare_newline=yes option with a Postfix minimum version of 3.5.23, 3.6.13, 3.7.9, 3.8.4, or 3.9.
CVE-2023-32028 1 Microsoft 7 Ole Db Driver 18 For Sql Server, Ole Db Driver 19 For Sql Server, Ole Db Driver For Sql Server and 4 more 2026-10-08 7.8 High
Microsoft SQL OLE DB Remote Code Execution Vulnerability
CVE-2022-41850 2 Debian, Linux 2 Debian Linux, Linux Kernel 2026-10-08 4.7 Medium
roccat_report_event in drivers/hid/hid-roccat.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free in certain situations where a report is received while copying a report->value is in progress.
CVE-2022-36227 5 Debian, Fedoraproject, Libarchive and 2 more 6 Debian Linux, Fedora, Libarchive and 3 more 2026-10-08 9.8 Critical
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."
CVE-2022-33070 2 Fedoraproject, Protobuf-c Project 2 Fedora, Protobuf-c 2026-10-08 5.5 Medium
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
CVE-2022-30115 3 Haxx, Netapp, Splunk 15 Curl, Clustered Data Ontap, H300s and 12 more 2026-10-08 4.3 Medium
Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the HSTS cache and *not* using thetrailing dot in the URL.
CVE-2022-2522 1 Vim 1 Vim 2026-10-08 7.8 High
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0061.
CVE-2022-2345 2 Fedoraproject, Vim 2 Fedora, Vim 2026-10-08 7.8 High
Use After Free in GitHub repository vim/vim prior to 9.0.0046.
CVE-2022-2344 2 Fedoraproject, Vim 2 Fedora, Vim 2026-10-08 7.8 High
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0045.
CVE-2022-2343 2 Fedoraproject, Vim 2 Fedora, Vim 2026-10-08 7.8 High
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0044.