Export limit exceeded: 396554 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (396554 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-95958 | 1 Justicerage | 1 Manalyze | 2026-09-23 | 3.3 Low |
| A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of the file manape/pe.cpp of the component PE Parser. Performing a manipulation of the argument BlockSize results in integer underflow. The attack requires a local approach. The patch is named c372b6bbca9d8c63812be50596fefa4a79c65fd0. It is recommended to apply a patch to fix this issue. | ||||
| CVE-2026-95927 | 1 Sourcecodester | 1 Online Reviewer Management System | 2026-09-23 | 7.3 High |
| A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/pretest/exam-delete.php. Such manipulation of the argument test_id leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. | ||||
| CVE-2026-95843 | 1 Moquette-io | 1 Moquette | 2026-09-23 | N/A |
| Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter through SharedSubscriptionUtils.extractShareName before validating the complete $share/{shareName}/{topicFilter} structure. A remote client can send a filter such as $share/grp without a topic-filter portion, causing a StringIndexOutOfBoundsException while calculating the share name. The exception terminates command handling on the shared session event loop and can deny service to other client sessions assigned to that loop. This issue is fixed in version 0.18.1. | ||||
| CVE-2026-93739 | 1 Totolink | 1 A3002mu | 2026-09-23 | 9.9 Critical |
| A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. | ||||
| CVE-2026-93307 | 1 O-ran-sc | 1 Smo Oam | 2026-09-23 | 4.3 Medium |
| A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector. Such manipulation of the argument additionalFields.padding leads to uncontrolled memory allocation. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through a bug report but has not responded yet. | ||||
| CVE-2026-91775 | 1 Limesurvey | 1 Limesurvey | 2026-09-23 | N/A |
| LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface. | ||||
| CVE-2026-88832 | 1 Redhat | 1 Hummingbird | 2026-09-23 | 7.3 High |
| BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images. | ||||
| CVE-2026-19267 | 1 Ibm | 1 Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-23 | 6.2 Medium |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions. | ||||
| CVE-2026-78579 | 1 Okta | 1 Access Gateway | 2026-09-23 | 6.8 Medium |
| The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP datastore configuration. The raw values are substituted directly into the filter string and passed to the LDAP search operation, resulting in modification of the intended query logic. | ||||
| CVE-2026-18505 | 1 Ibm | 1 Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-23 | 5.4 Medium |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated `Host` header to redirect authenticated operators to attacker-controlled sites, enabling credential phishing. | ||||
| CVE-2026-18180 | 1 Ibm | 1 Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-23 | 6.5 Medium |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to SQL injection. | ||||
| CVE-2026-93618 | 2026-09-23 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetTricks allows Stored XSS. This issue affects JetTricks: from n/a through 2.0.1. | ||||
| CVE-2026-96656 | 1 Plex | 1 Media Server | 2026-09-23 | 7.2 High |
| Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The preference TranscoderH264Options is appended verbatim to x264's option string on every transcode. At startup, all .so files are run without signature, execute bit, or symbol checks. | ||||
| CVE-2026-95845 | 1 Moquette-io | 1 Moquette | 2026-09-23 | N/A |
| Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message queues. When a fast publisher sends messages to a slow subscriber whose in-flight window is full, queued messages can accumulate without bound in memory or persistent storage. Remote clients can use this condition to exhaust broker resources and cause a denial of service. This issue is fixed in version 0.18.1. | ||||
| CVE-2026-95604 | 2026-09-23 | 7.5 High | ||
| Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions. | ||||
| CVE-2026-95603 | 2026-09-23 | 7.2 High | ||
| Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions. | ||||
| CVE-2026-95601 | 2026-09-23 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions. | ||||
| CVE-2026-95600 | 2026-09-23 | 5.3 Medium | ||
| Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions. | ||||
| CVE-2026-95593 | 2026-09-23 | 7.6 High | ||
| Editor SQL Injection in Ultimeter <= 3.0.8 versions. | ||||
| CVE-2026-95592 | 2026-09-23 | 5.3 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions. | ||||