Export limit exceeded: 402609 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402609 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-105302 | 1 Redhat | 4 Build Keycloak, Build Of Keycloak, Red Hat Single Sign On and 1 more | 2026-10-06 | 5.7 Medium |
| A flaw was found in the User Session Note mapper of the Keycloak identity and access management solution. The issue occurs because the mapper does not validate whether a requested session note contains sensitive internal credentials, such as federated access tokens from external identity providers. This allows a delegated client administrator to leak a user's upstream bearer tokens into the tokens issued to their managed application, potentially leading to unauthorized access to the user's data on external platforms. | ||||
| CVE-2026-105306 | 1 Redhat | 4 Build Keycloak, Build Of Keycloak, Red Hat Single Sign On and 1 more | 2026-10-06 | 6.5 Medium |
| A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server. The issue occurs because the registration process fails to filter security-sensitive client attributes when a new client is created. An attacker with a valid Initial Access Token can register a client that bypasses audience checks during token introspection. This allows the attacker to view sensitive identity information, roles, and session details from access tokens belonging to other applications in the same realm. | ||||
| CVE-2026-84169 | 1 Wordpress-extensions | 1 Upi Qr Code Payment Gateway | 2026-10-06 | 5.3 Medium |
| The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary order as paid without making any payment. | ||||
| CVE-2026-100727 | 1 Growi | 1 Growi | 2026-10-06 | N/A |
| An improper access control vulnerability exists in GROWI, which allow an unauthenticated attacker to read files contained in non-public pages of the affected product when the file upload setting is configured as "Local". | ||||
| CVE-2017-20285 | 1 Ingydotnet | 1 Yaml | 2026-10-06 | 9.1 Critical |
| YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names. | ||||
| CVE-2019-25777 | 1 Ingydotnet | 1 Yaml | 2026-10-06 | 7.3 High |
| YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution. A perl/glob document names a package and a symbol, and supplies the value assigned to it. Nothing restricts the name, so the target can be @INC or YAML's own load options. A perl/glob document that sets $YAML::LoadCode or $YAML::UseCode turns on code loading, which is off by default, for every later Load() in the process. A perl/code document is then passed to a string eval, so an attacker who supplies two documents to separate Load() calls in one process can execute arbitrary Perl code. | ||||
| CVE-2026-19954 | 1 Perl | 1 Net::whois::raw | 2026-10-06 | 5.4 Medium |
| Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names. pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by "cole" encodes to "xn--cole-pka" rather than "xn--cole-9oa". The Net::Whois::Raw library modules are not affected. | ||||
| CVE-2026-39763 | 2 Deepak Anand, Wordpress-extensions | 2 Wp Dummy Content Generator, Wp Dummy Content Generator | 2026-10-06 | 4.3 Medium |
| Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through 4.0.0. | ||||
| CVE-2026-94669 | 2 Wordpress-extensions, Wpmanageninja | 2 Fluent Forms Pro Add On Pack, Fluent Forms Pro Add On Pack | 2026-10-06 | 5.3 Medium |
| Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13. | ||||
| CVE-2026-105073 | 2 Arraytics, Wordpress-extensions | 2 Wp Event Solution, Wp Event Solution | 2026-10-06 | 5.3 Medium |
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Arraytics WP Event Solution wp-event-solution allows Retrieve Embedded Sensitive Data.This issue affects WP Event Solution: from n/a through 4.1.25. | ||||
| CVE-2026-103684 | 2 Arraytics, Wordpress-extensions | 2 Wp Event Solution, Wp Event Solution | 2026-10-06 | 5.3 Medium |
| Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through 4.1.25. | ||||
| CVE-2026-39783 | 2 Wordpress-extensions, Wp Syntex | 2 Polylang, Polylang | 2026-10-06 | 4.3 Medium |
| Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a through 3.8.7. | ||||
| CVE-2026-77803 | 1 Progress Software | 1 Progress Telerik Fiddler Classic | 2026-10-06 | 3.6 Low |
| In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component. A request that contains both a Content-Length and a Transfer-Encoding header is forwarded with both headers present, while Fiddler frames the body using Transfer-Encoding only. The remaining bytes on the reused client connection are then parsed as a separate pipelined request, so a local threat actor with low privileges can cause a single malformed request to be split into two requests forwarded to the origin server and receive an additional smuggled response, without requiring a vulnerable server. | ||||
| CVE-2026-106329 | 2026-10-06 | 9.6 Critical | ||
| Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-18161 | 2 Ibm, Redhat | 3 Financial Transaction Manager, Financial Transaction Manager Ftmfor Redhat Openshift, Openshift | 2026-10-06 | 4.3 Medium |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to falsify transaction audit logs due to improper validation of a client-supplied HTTP header. | ||||
| CVE-2026-18162 | 2 Ibm, Redhat | 3 Financial Transaction Manager, Financial Transaction Manager Ftmfor Redhat Openshift, Openshift | 2026-10-06 | 9.8 Critical |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor. | ||||
| CVE-2026-102322 | 2026-10-06 | 9.6 Critical | ||
| Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-18163 | 2 Ibm, Redhat | 3 Financial Transaction Manager, Financial Transaction Manager Ftmfor Redhat Openshift, Openshift | 2026-10-06 | 9.8 Critical |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data. | ||||
| CVE-2026-18169 | 2 Ibm, Redhat | 3 Financial Transaction Manager, Financial Transaction Manager Ftmfor Redhat Openshift, Openshift | 2026-10-06 | 9.9 Critical |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. | ||||
| CVE-2026-65142 | 2026-10-06 | 7.8 High | ||
| NVIDIA Model-Optimizer contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. | ||||