Export limit exceeded: 383876 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (383876 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-62440 | 1 Apache | 2 Apache Cloudstack, Cloudstack | 2026-08-27 | 9.1 Critical |
| Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.22.1.1 or later, which fixes the issue. | ||||
| CVE-2026-63046 | 1 Apache | 1 Inlong | 2026-08-27 | 8.8 High |
| Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell commands via ExcuteLinux.exeCmd() with no filtering or whitelist validation. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1]/[2] to solve it. [1] https://github.com/apache/inlong/pull/12151 . [2] https://github.com/apache/inlong/pull/12155 . | ||||
| CVE-2026-47878 | 2026-08-27 | 5.6 Medium | ||
| DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes directly to ObjectInputStream.readObject() without an ObjectInputFilter that restricts types to a trusted class allowlist. Spring Batch 6.0.0 - 6.0.4 Spring Batch 5.2.6 and earlier | ||||
| CVE-2026-16434 | 1 Adminer | 1 Adminer | 2026-08-27 | N/A |
| Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GHSA-8478-xrj3-h9c2). The validation guard (bootstrap.inc.php) only rejects prefixes matching ^/[^/], blocking //evil.com but allowing values such as /\evil.com whose second character is a backslash. Because browsers normalize backslash to forward slash, a network-path reference survives into REQUEST_URI and reaches cookie_path(), affecting the Set-Cookie Path attribute. Exploitation requires that clients can set the X-Forwarded-Prefix header (a misconfigured or absent reverse proxy). Impact is limited to anomalous cookie-path scoping. | ||||
| CVE-2026-55059 | 2026-08-27 | 6.1 Medium | ||
| OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and 3.4.13 contain a heap out-of-bounds write in Imf_4_0::SampleCountChannel::set(int r, unsigned int newNumSamples[]). The row-based sample-count setter computes the target Y coordinate with dataWindow.min.x instead of dataWindow.min.y. For a valid deep image data window where min.x != min.y, a valid row index can be translated into an invalid Y coordinate, causing writes before the allocated _numSamples buffer. The vulnerability is reachable through the public OpenEXRUtil DeepImage API and can lead to heap corruption and process crashes. This issue has been fixed in versions 3.2.10, 3.3.12 and 3.4.13. | ||||
| CVE-2026-78288 | 2026-08-27 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions. | ||||
| CVE-2026-30047 | 2026-08-27 | N/A | ||
| A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request. | ||||
| CVE-2026-30046 | 2026-08-27 | N/A | ||
| A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request. | ||||
| CVE-2026-78435 | 1 Faveo | 1 Helpdesk | 2026-08-27 | 3.8 Low |
| A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-30045 | 2026-08-27 | N/A | ||
| An integer overflow in the /nnrf-disc/v1/nf-instances component of open5gs v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted HTTP/2 GET request. | ||||
| CVE-2026-81271 | 2 Paolo, Wordpress | 2 Geodirectory, Wordpress | 2026-08-27 | 8.8 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions. | ||||
| CVE-2026-78276 | 2026-08-27 | 7.2 High | ||
| Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions. | ||||
| CVE-2026-81277 | 2026-08-27 | 8.5 High | ||
| Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions. | ||||
| CVE-2026-78261 | 2 Realtyna, Wordpress | 2 Realtyna Organic Idx Plugin, Wordpress | 2026-08-27 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions. | ||||
| CVE-2026-32550 | 2026-08-27 | 8.5 High | ||
| Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions. | ||||
| CVE-2026-68569 | 1 Apache | 1 Tomcat | 2026-08-27 | 8.1 High |
| Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue. | ||||
| CVE-2026-79938 | 2026-08-27 | 7.6 High | ||
| Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | ||||
| CVE-2026-67275 | 2026-08-27 | 5.3 Medium | ||
| Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Cache poisoning. | ||||
| CVE-2026-75357 | 2026-08-27 | N/A | ||
| An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components. | ||||
| CVE-2026-78267 | 2 Cozmoslabs, Wordpress | 2 Translatepress, Wordpress | 2026-08-27 | 9.8 Critical |
| Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions. | ||||