Export limit exceeded: 372067 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 372067 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372067 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16266 | 2026-07-30 | 4 Medium | ||
| Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype chain by supplying a crafted property path containing special keys such as __proto__. | ||||
| CVE-2026-18245 | 1 Aws | 1 Amplify Codegen Ui | 2026-07-30 | 9 Critical |
| Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio component or theme schema values due to insufficient coverage and effectiveness of the input validation introduced for CVE-2025-4318. To remediate this issue, users should upgrade to version 2.20.6 | ||||
| CVE-2024-25039 | 1 Ibm | 1 Engineering Requirements Management Doors And Doors Web Access | 2026-07-30 | 7.5 High |
| IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive. | ||||
| CVE-2024-40683 | 1 Ibm | 1 Operations Analytics Log Analysis | 2026-07-30 | 6.3 Medium |
| IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 does not invalidate session after a password chance which could allow an authenticated user to impersonate another user on the system. | ||||
| CVE-2026-11707 | 1 Ibm | 1 Tivoli System Automation Application Manager | 2026-07-30 | 9.3 Critical |
| IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page. | ||||
| CVE-2026-15969 | 2026-07-30 | N/A | ||
| SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads. | ||||
| CVE-2026-15978 | 2026-07-30 | N/A | ||
| SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data transfer, attackers can exfiltrate all model weights. | ||||
| CVE-2026-15977 | 2026-07-30 | N/A | ||
| SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the --admin-api-key is configured. | ||||
| CVE-2026-15971 | 2026-07-30 | N/A | ||
| SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on inference requests. | ||||
| CVE-2026-16416 | 1 Google | 1 Chrome | 2026-07-30 | 9.3 Critical |
| Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High) | ||||
| CVE-2026-17716 | 1 Google | 1 Chrome | 2026-07-30 | 8.4 High |
| Use after free in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via malicious network traffic. (Chromium security severity: High) | ||||
| CVE-2026-17877 | 1 Google | 1 Chrome | 2026-07-30 | 8.4 High |
| Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium) | ||||
| CVE-2026-17909 | 1 Google | 1 Chrome | 2026-07-30 | 5.3 Medium |
| Insufficient validation of untrusted input in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via malicious network traffic. (Chromium security severity: Low) | ||||
| CVE-2025-36336 | 1 Ibm | 1 Watsonxdata Intelligence | 2026-07-30 | 5.9 Medium |
| IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques. | ||||
| CVE-2025-12530 | 1 Ibm | 1 Watsonxdata Intelligence | 2026-07-30 | 5.9 Medium |
| IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through Patch 1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques. | ||||
| CVE-2026-17980 | 1 Google | 1 Chrome | 2026-07-30 | 3.1 Low |
| Inappropriate implementation in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-28812 | 1 Apache | 1 Jspwiki | 2026-07-30 | N/A |
| UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue. | ||||
| CVE-2026-48910 | 1 Apache | 1 Jspwiki | 2026-07-30 | 6.5 Medium |
| A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the markdown renderer, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. This issue affects Apache JSPWiki: through 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes the issue. | ||||
| CVE-2026-10842 | 1 Ibm | 3 Websphere Application Server, Websphere Application Server Liberty, Websphere Application Server Liberty | 2026-07-30 | 7.5 High |
| IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints. | ||||
| CVE-2026-52680 | 1 Apache | 1 Kyuubi | 2026-07-30 | N/A |
| Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the filename and cause the Kyuubi server process to write controlled content outside the intended upload directory, subject to filesystem permissions. This issue affects Apache Kyuubi: from 1.7.0 through 1.11.1. Users are recommended to upgrade to version 1.12.0, which fixes the issue. | ||||