Export limit exceeded: 401118 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 28619 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (28619 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-90441 1 Watchguard 1 Fireware Os 2026-09-30 N/A
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.
CVE-2026-95276 1 Google 1 Chrome 2026-09-30 8.3 High
Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: Medium)
CVE-2026-95312 1 Google 1 Chrome 2026-09-30 3.1 Low
Information leak in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95327 1 Google 1 Chrome 2026-09-30 6.5 Medium
Information leak in Networking in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-95336 1 Google 1 Chrome 2026-09-30 6.5 Medium
Information leak in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95341 1 Google 1 Chrome 2026-09-30 8.3 High
Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
CVE-2026-22101 1 Evbee 1 Dc-80 2026-09-30 N/A
The access to the service menu is obfuscated, but possible with only physical access. This menu exposes sensitive information such as serial numbers, MAC addresses, and WiFi network and password.
CVE-2026-100851 1 Azuracast 1 Azuracast 2026-09-30 7.6 High
AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to read Icecast/Shoutcast admin, source, and relay passwords. Attackers with View-only access can call this endpoint and receive plaintext frontend credentials in the JSON response, then use the admin password to authenticate to the Icecast admin interface without Broadcasting permission.
CVE-2026-70125 1 Microsoft 3 365 Apps, Office 2021, Office 2024 2026-09-30 8.8 High
Microsoft Office Outlook Remote Code Execution Vulnerability
CVE-2026-93995 1 Apache 1 Mina Sshd 2026-09-30 6.5 Medium
Improper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though class GitPgmCommandFactory a way to configure an Apache MINA SSHD server such that authenticated SSH clients can remotely execute git commands via the JGit library on git repositories stored on the server. In CVE-2026-58624 this mechanism was restricted to only a few git commands, including "git archive" without "--output" or "-o" options such that the resulting archive would not be written on the server but instead sent back to the client over the SSH connection. The fix done for CVE-2026-58624 was insufficient as it missed removing the single-argument "-o=file.zip" version of the command parameter from the "archive" command. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.
CVE-2026-103389 1 Misp 1 Misp 2026-09-30 N/A
MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpoints. The stored value was subsequently concatenated directly into HTML markup by the D3-based correlation graph rendering scripts (both the default and Overmind themes) using the .html() method. A user holding the perm_galaxy_editor permission, which is granted to the stock User role, could store arbitrary HTML or JavaScript in the icon field. Any other user who opened the correlation graph of an event containing a cluster belonging to that galaxy would have the injected script executed in their browser session. Impact: - Arbitrary script execution in the context of the victim's MISP session - Potential theft of session credentials, manipulation of displayed data, or initiation of actions on behalf of the victim - Affects both the default and Overmind UI themes Affected versions: <2.5.48
CVE-2026-97302 2026-09-30 5.3 Medium
Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions.
CVE-2026-97261 2026-09-30 5.3 Medium
Unauthenticated Sensitive Data Exposure in Notivo <= 1.4.2 versions.
CVE-2026-97241 2026-09-30 7.5 High
Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions.
CVE-2026-97240 2026-09-30 7.5 High
Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions.
CVE-2026-83560 2026-09-30 5.3 Medium
The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.
CVE-2026-80333 2026-09-30 5.3 Medium
The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of any type that WordPress would otherwise not serve.
CVE-2026-102845 1 Gedelumbung 1 Hospitalmanagement 2026-09-30 5.3 Medium
A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function error_reporting of the file index.php of the component HTTP Response. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-103321 1 Misp 1 Misp 2026-09-30 N/A
MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature. The event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element's src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script. Preconditions: - An authenticated MISP user with the ability to create or modify an event graph entry. - A second user (the victim) who views the event graph and triggers the preview popover. Impact: - Execution of arbitrary JavaScript in the victim's browser within the MISP application context. - Potential theft of session tokens, cookies, or sensitive data accessible to the victim's browser. - Potential for performing actions on behalf of the victim within the MISP application. Affected: MISP versions prior to the fix (commit applied after v2.5.48).
CVE-2026-88774 1 Citrix 3 Netscaler Adc, Netscaler Application Delivery Controller, Netscaler Gateway 2026-09-30 7.2 High
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage.