Search

Search Results (399173 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-84440 1 Ibm 1 Guardium Data Protection 2026-09-29 7.5 High
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.
CVE-2026-84422 1 Ibm 1 Guardium Data Protection 2026-09-29 7.2 High
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.
CVE-2026-81930 2026-09-29 6.3 Medium
Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the intended domain to a path, query or fragment and leaves the attacker in control of the request host. The provider sends that request with an `Authorization: Bearer` header carrying a JWT minted from the connection's private key, or the configured OAuth or programmatic access token. A user who can edit the Snowflake connection but cannot read its secrets — Airflow gives connection-configuration users write-only access to stored credentials, and a `private_key_file` lives on the worker rather than in the connection — can therefore cause a valid token for the account to be delivered to a host of their choosing and replay it against the genuine Snowflake endpoint. No Dag-authoring ability is required: the attacker edits the connection and waits for an existing Dag to use it. The same unvalidated value was also used to build the OAuth token-request URL and the Cortex Agent base URL. Affects deployments where Snowflake connections are editable by users who are not trusted with the connection's credentials. Users are advised to upgrade to `apache-airflow-providers-snowflake` `6.18.0` or later, which rejects `account` and `region` values containing anything other than letters, digits, `.`, `_` and `-` in every URL the provider builds from them.
CVE-2026-95292 1 Google 1 Chrome 2026-09-29 N/A
Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)
CVE-2026-100769 1 Mozilla 1 Firefox 2026-09-29 8.8 High
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
CVE-2026-102240 1 Netcore 1 Nap930 2026-09-29 10 Critical
A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-101858 1 Raspap 1 Raspap-webgui 2026-09-29 4.7 Medium
A flaw has been found in RaspAP raspap-webgui up to 3.5.5. Affected is the function WiFiManager::writeWpaSupplicant of the file src/RaspAP/Networking/Hotspot/WiFiManager.php of the component SSID Processing. This manipulation of the argument ssid causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2022-51019 1 Akaunting 1 Akaunting 2026-09-29 8.8 High
Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation and update flow where the alias parameter is passed unvalidated to shell command execution. Authenticated users with admin panel access can inject shell metacharacters into the alias parameter to execute arbitrary commands on the server.
CVE-2026-100800 1 Mozilla 1 Firefox 2026-09-29 9.6 Critical
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-100820 1 Mozilla 1 Firefox 2026-09-29 8.8 High
Privilege escalation in the Address Bar component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
CVE-2026-96429 2026-09-29 N/A
SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2026-96418 1 Wireshark 1 Wireshark 2026-09-29 5.5 Medium
TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-96417 1 Wireshark 1 Wireshark 2026-09-29 5.5 Medium
RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95394 1 Wireshark 1 Wireshark 2026-09-29 4.7 Medium
Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-101270 1 Pretix 1 Pretix 2026-09-29 N/A
Malicious HTML content could be injected into the help texts of various fields with organizer permissions.
CVE-2026-100773 1 Mozilla 1 Firefox 2026-09-29 8.8 High
Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100782 1 Mozilla 1 Firefox 2026-09-29 8.8 High
Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100789 1 Mozilla 1 Firefox 2026-09-29 8.8 High
Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100791 1 Mozilla 1 Firefox 2026-09-29 8.8 High
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100815 1 Mozilla 1 Firefox 2026-09-29 8.8 High
Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.