Search

Search Results (400204 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-103048 1 Wikimedia 1 Mediawiki-collection Extension 2026-09-30 N/A
URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - Collection extension allows Fake the Source of Data. This issue affects Mediawiki - Collection extension: before 1.46.1, 1.45.5, 1.43.10.
CVE-2026-103050 1 Wikimedia 1 Mediawiki - Massmessage Extension 2026-09-30 6.1 Medium
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - MassMessage extension allows Stored XSS. This issue affects Mediawiki - MassMessage extension: before 1.46.1, 1.45.5, 1.43.10.
CVE-2026-103051 1 Wikimedia 1 Mediawiki - Centralnotice Extension 2026-09-30 6.1 Medium
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralNotice extension allows Stored XSS. This issue affects Mediawiki - CentralNotice extension: before 1.46.1, 1.45.5, 1.43.10.
CVE-2026-103053 1 Beenuar 1 Aisoc 2026-09-30 5.4 Medium
AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and AISOC_ACTIONS_SERVICE_TOKEN is empty in the default Docker Compose deployment. Unauthenticated attackers can list response-action integrations, submit and approve actions on behalf of arbitrary principals, and dispatch containment actions using vendor credentials.
CVE-2026-103054 1 Beenuar 1 Aisoc 2026-09-30 7.1 High
AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own. Attackers can submit tenant UUIDs via the add_tenants_to_portfolio endpoint to claim unclaimed tenants and read their security alerts, incidents, and posture metrics without consent.
CVE-2026-103055 1 Beenuar 1 Aisoc 2026-09-30 7.5 High
AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant identifiers to access cross-tenant live alerts, cases, agent events and graph updates through the realtime endpoints.
CVE-2026-103056 1 Beenuar 1 Aisoc 2026-09-30 9 Critical
AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path, script_name, or script_args parameters to break out of quoted arguments and execute arbitrary commands on managed endpoints with SYSTEM or root privileges.
CVE-2026-103057 1 Beenuar 1 Aisoc 2026-09-30 4.3 Medium
AiSOC versions 5.1.0 before 12.0.0 contain an authentication bypass vulnerability in the realtime service internal endpoints POST /internal/agent-event and POST /internal/push. Attackers can post arbitrary events with spoofed tenant identifiers to broadcast malicious content over WebSocket and Redis SSE channels or send unauthorized notifications to registered devices.
CVE-2026-103087 1 Gosub-io 1 Gosub-engine 2026-09-30 N/A
Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service (stack exhaustion and application crash) via an SVG document containing an excessive number of deeply nested elements. Because the engine does not limit the nesting depth of processed SVG nodes, rendering such a document overflows the thread stack and terminates the application. The malicious SVG can be embedded through the SRC attribute of an IMG element, and thus exploitation only requires the victim to visit an attacker-controlled web page.
CVE-2026-78229 1 Pfu Limited 2 Image Scanner Driver For Linux (fi Series), Image Scanner Driver For Linux (sp Series) 2026-09-30 6.7 Medium
Image Scanner Driver for Linux contains an OS command injection vulnerability. An attacker who can log in to a Linux system where the affected product is installed may execute an arbitrary OS command by making certain preparations.
CVE-2026-81310 1 Pfu Limited 2 Image Scanner Driver For Linux (fi Series), Image Scanner Driver For Linux (sp Series) 2026-09-30 6.6 Medium
Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log in to a Linux system where the product is installed may overwrite arbitrary files by using a special method in advance.
CVE-2026-86556 1 Zte 1 U30 Air 2026-09-30 5.3 Medium
There is an information disclosure vulnerability in ZTE U30 Air. Due to improper permission control, attackers can exploit the vulnerability to obtain relevant information.
CVE-2026-97150 1 Basercms Users Community 1 Bcaddonmigrator 2026-09-30 N/A
When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user.
CVE-2026-92867 1 Pgpool Global Development Group 1 Pgpool-ii 2026-09-30 N/A
An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.
CVE-2026-92868 1 Pgpool Global Development Group 1 Pgpool-ii 2026-09-30 N/A
An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication.
CVE-2026-92869 1 Pgpool Global Development Group 1 Pgpool-ii 2026-09-30 N/A
An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.
CVE-2026-92870 1 Pgpool Global Development Group 1 Pgpool-ii 2026-09-30 N/A
A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.
CVE-2026-92871 1 Pgpool Global Development Group 1 Pgpool-ii 2026-09-30 N/A
A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.
CVE-2026-92872 1 Pgpool Global Development Group 1 Pgpool-ii 2026-09-30 N/A
Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.
CVE-2026-92873 1 Pgpool Global Development Group 1 Pgpool-ii 2026-09-30 N/A
Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.