Export limit exceeded: 373611 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (373611 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-69110 | 1 Microck | 1 Opencode-studio | 2026-08-05 | 9.1 Critical |
| OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can retrieve intermediate audio, video artifacts, and subtitles belonging to other users' jobs, and additionally delete any video by ID through the unauthenticated DELETE /api/short-video/:videoId endpoint. | ||||
| CVE-2026-10032 | 1 A2ui-project | 1 A2ui | 2026-08-05 | N/A |
| The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI as the url argument of a Button component's functionCall action. When the user clicks the rendered button, arbitrary JavaScript executes in the victim application's browser origin, constituting a stored/reflected XSS with Critical severity. No non-default configuration is required; the Basic Catalog is enabled by default. | ||||
| CVE-2026-63455 | 1 Hpe | 1 Edgeconnect Sd-wan Orchestrator | 2026-08-05 | 9.8 Critical |
| Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system. | ||||
| CVE-2026-63456 | 1 Hpe | 1 Edgeconnect Sd-wan Orchestrator | 2026-08-05 | 9.8 Critical |
| Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system. | ||||
| CVE-2026-15314 | 1 Tp-link | 1 P110 V1 | 2026-08-05 | N/A |
| Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service process to crash. Successful exploitation may cause the web service process to stop responding or restart, resulting in a denial-of-service condition. | ||||
| CVE-2026-24253 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 8.2 High |
| NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering. | ||||
| CVE-2026-24254 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 9.8 Critical |
| NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-24255 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 7.5 High |
| NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering. | ||||
| CVE-2026-47612 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 7.5 High |
| NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure. | ||||
| CVE-2026-47613 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 7.5 High |
| NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure. | ||||
| CVE-2026-47614 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 7.5 High |
| NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. | ||||
| CVE-2026-47615 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 7.5 High |
| NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure. | ||||
| CVE-2026-47616 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 7.5 High |
| NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. | ||||
| CVE-2026-47617 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 7.5 High |
| NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure. | ||||
| CVE-2026-47618 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 7.5 High |
| NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. | ||||
| CVE-2026-47619 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 6.6 Medium |
| NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-47620 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 6.5 Medium |
| NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service. | ||||
| CVE-2026-47621 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 6.5 Medium |
| NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to denial of service and data tampering. | ||||
| CVE-2026-47622 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 5.3 Medium |
| NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure. | ||||
| CVE-2026-47623 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 8.2 High |
| NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering. | ||||