Export limit exceeded: 400722 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400722 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-21975 | 1 Vmware | 3 Cloud Foundation, Vrealize Operations Manager, Vrealize Suite Lifecycle Manager | 2026-10-01 | 9.8 Critical |
| Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials. | ||||
| CVE-2026-93820 | 1 Linux | 1 Linux Kernel | 2026-10-01 | 5.5 Medium |
| In the Linux kernel, the following vulnerability has been resolved: PCI: rockchip: Protect root bus removal with rescan lock Hold the pci_rescan_remove_lock lock while stopping and removing a root bus to avoid racing with concurrent rescan or hotplug operations triggered via sysfs. Such races may lead to use-after-free issues or system crashes. [bhelgaas: commit log] | ||||
| CVE-2026-100775 | 1 Mozilla | 1 Firefox | 2026-10-01 | 9.6 Critical |
| Sandbox escape in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100793 | 1 Mozilla | 1 Firefox | 2026-10-01 | 6.5 Medium |
| JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | ||||
| CVE-2026-95314 | 1 Google | 1 Chrome | 2026-10-01 | 8.1 High |
| Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-104056 | 1 Authlib | 1 Authlib | 2026-10-01 | N/A |
| Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server metadata URL. | ||||
| CVE-2026-55252 | 2026-10-01 | N/A | ||
| OpenRun is an open-source, self-hosted GitOps platform for deploying web apps and internal tools to Docker or Kubernetes. Prior to version 0.17.7, the restrictions on redirect URLs in openrun can be bypassed by attackers, leading to open redirect attacks. This issue has been patched in version 0.17.7. | ||||
| CVE-2026-95303 | 1 Google | 1 Chrome | 2026-10-01 | 6.5 Medium |
| Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-95275 | 1 Google | 1 Chrome | 2026-10-01 | 6.5 Medium |
| Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-51856 | 2026-10-01 | 9.8 Critical | ||
| In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to Toolkit.call_tool_function, which invokes execute_python_code without an additional approval or isolation boundary on that path. | ||||
| CVE-2026-51860 | 1 Dataelement | 1 Bisheng | 2026-10-01 | 7.5 High |
| bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Directory Traversal in src/backend/bisheng/linsight/domain/task_exec.py. | ||||
| CVE-2026-102628 | 2026-10-01 | 9.3 Critical | ||
| The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the entire server environment, including all .env configuration variables, in plaintext. Fixed on or before 2026-09-02. | ||||
| CVE-2026-100251 | 2026-10-01 | 6.5 Medium | ||
| Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance metadata or to source TCP connections from the Wormhole relay's IP. | ||||
| CVE-2026-102671 | 2026-10-01 | 5.3 Medium | ||
| The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default. | ||||
| CVE-2026-102670 | 2026-10-01 | 4.3 Medium | ||
| Joyland AI app explicitly permits cleartext HTTP traffic on Android 9+ where the default is to block it. | ||||
| CVE-2026-102669 | 2026-10-01 | 5.3 Medium | ||
| Joyland AI app does not verify hostnames, allowing a malicious host to connect or intercept chat messages. | ||||
| CVE-2026-102668 | 2026-10-01 | 5.3 Medium | ||
| The Joyland AI app accepts any TLS certificates from any server without validation. | ||||
| CVE-2026-102667 | 2026-10-01 | 8.3 High | ||
| Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, or access app-internal storage. If the installed app has been granted permissions previously, the attacker can access the entire file system, camera, microphone, and GPS tracking. | ||||
| CVE-2026-82358 | 2026-10-01 | 6.5 Medium | ||
| RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation 'src/co_sdo_server.c' that fails to properly validate write permissions when processing download-segment frames. An unauthenticated attacker on the CAN bus can initiate an SDO upload for a read-only Object Dictionary (OD) entry, which sets a data pointer to the read-only object, then send download-segment frames to write to that memory location. The download-segment handler does not verify that a download session is active, allowing any CANopen node to overwrite read-only OD entries using two SDO frames. Note that CANopen protocol operates over CAN bus and does not provide built-in authentication mechanisms. Fixed in 1.1.1. | ||||
| CVE-2026-102666 | 2026-10-01 | 6.5 Medium | ||
| The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content to any user, group of users, or all users of the app at once. | ||||