Export limit exceeded: 400910 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400910 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103533 | 1 David-crty | 1 Databasement | 2026-10-01 | 4.1 Medium |
| A vulnerability was found in David-Crty databasement up to 1.7.1. This impacts the function https:/github.com/David-Crty/databasement/pull/511 of the file app/Http/Requests/Api/V1/RestoreRequest.php of the component database-servers API Endpoint. The manipulation of the argument schema_name results in path traversal. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been made public and could be used. Upgrading to version 1.7.2 will fix this issue. You should upgrade the affected component. | ||||
| CVE-2026-103530 | 1 Decolua | 1 9router | 2026-10-01 | 7.3 High |
| A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated remotely. Applying a patch is the recommended action to fix this issue. | ||||
| CVE-2026-103290 | 1 Ghost | 1 Ghost | 2026-10-01 | 3.8 Low |
| Ghost versions 6.14.0 through versions prior to 6.27.0 contain a path traversal vulnerability in the ImageSize service. Insufficient input validation of user-supplied file paths may allow authenticated staff users to access local files outside the intended data storage directories on the server. | ||||
| CVE-2026-103282 | 1 Ghost | 1 Ghost | 2026-10-01 | 4.3 Medium |
| Ghost versions 0.5.0 before 6.23.0 contain a concurrency issue in the staff invitation acceptance mechanism that allows multiple accounts to be created from a single invite token. Attackers can exploit this race condition by submitting concurrent requests with the same invitation token to create duplicate user accounts. | ||||
| CVE-2026-103278 | 1 Ghost | 1 Ghost | 2026-10-01 | 7.3 High |
| Ghost versions 5.8.0 before 6.34.0 contain an input validation vulnerability in the admin iframe that allows attackers to take over staff user accounts. Attackers with content publishing privileges can craft malicious pages that, when visited by active staff users, enable account takeover through improper input validation. | ||||
| CVE-2026-103274 | 1 Ghost | 1 Ghost | 2026-10-01 | 5.3 Medium |
| Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settings. | ||||
| CVE-2026-103269 | 1 Ghost | 1 Ghost | 2026-10-01 | 5.3 Medium |
| Ghost versions 5.3.0 before 6.62.0 contain a missing authorization vulnerability that allows an authenticated site member to read the excerpts of posts they do not have access to (gated content). | ||||
| CVE-2026-103265 | 1 Fleetdm | 1 Fleet | 2026-10-01 | 4.3 Medium |
| Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results for hosts on other teams when a shared command UUID targets hosts across multiple teams, exposing host UUIDs, command payloads, and device responses. | ||||
| CVE-2026-103261 | 1 Tornadoweb | 1 Tornado | 2026-10-01 | 5.3 Medium |
| Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by sending requests with thousands of query parameters. Attackers can send unauthenticated GET requests with unbounded query-string field counts to degrade response times for all clients sharing the same IOLoop. | ||||
| CVE-2026-103257 | 1 N8n | 1 N8n | 2026-10-01 | 7.7 High |
| n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the n8n node that fails to validate resource identifiers. Attackers can craft malicious resource IDs to redirect API calls to unintended resources, allowing unauthorized access to workflows, executions, and credential secrets within the API key's scope. | ||||
| CVE-2026-103249 | 1 N8n | 1 N8n | 2026-10-01 | 7.6 High |
| n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a stored DOM cross-site scripting vulnerability in Resource Locator parameter dropdown link handling. Workflow authors can inject malicious script URLs that execute arbitrary JavaScript in the editor origin when other users open the node dropdown and click the external-link icon, with the payload persisting across workflow imports and shares. | ||||
| CVE-2026-102278 | 1 Juliangruber | 1 Brace-expansion | 2026-10-01 | 7.5 High |
| The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11. | ||||
| CVE-2026-102271 | 1 Jpadilla | 1 Pyjwt | 2026-10-01 | 7.4 High |
| PyJWT is a Python implementation of JSON Web Token standards. From 2.4.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because asymmetric-key guard relies on textual markers that are absent from DER encoding. This occurs when an application mixes HMAC and asymmetric algorithms and supplies a DER public key as the shared verification key. As a result, PyJWT uses public DER bytes as an HMAC secret. Consequently, an attacker who knows the public key can forge authenticated HMAC tokens. This issue is fixed in version 2.14.0. | ||||
| CVE-2026-102267 | 1 Jpadilla | 1 Pyjwt | 2026-10-01 | 7.4 High |
| PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because redirect destinations are not revalidated against the JWKS trust boundary. This occurs when a configured trusted JWKS endpoint returns an attacker-influenced redirect. As a result, PyJWKClient follows the redirect and consumes the redirected response as key material. Consequently, forwarded credentials may be disclosed or verification keys may be substituted. This issue is fixed in version 2.14.0. | ||||
| CVE-2026-102265 | 1 Jpadilla | 1 Pyjwt | 2026-10-01 | 5.3 Medium |
| PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affected because parser catches ValueError but not RecursionError. This occurs when a deeply nested token header reaches json.loads. As a result, RecursionError escapes the documented PyJWT error hierarchy. Consequently, an unauthenticated malformed token can cause a request-level failure and HTTP 500. This issue is fixed in version 2.14.0. | ||||
| CVE-2026-101916 | 1 Grpc | 1 Grpc-node | 2026-10-01 | 7.4 High |
| @grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from unauthorized peer certificates when server credentials set requireClientCertificate to false. When applications use the returned authentication context, they can treat an unauthorized certificate as authorized, causing improper authentication. @grpc/grpc-js-xds can reach this condition when RBAC authentication is enabled in affected configurations. This issue is fixed in version 1.14.5 and 1.13.6. | ||||
| CVE-2026-101915 | 1 Grpc | 1 Grpc-node | 2026-10-01 | 3.7 Low |
| @grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, when an application method handler throws an uncaught error, the server includes its error message in the status message sent to the client. The thrown error message is transmitted to the client, causing sensitive information disclosure when the message contains sensitive data. This issue is fixed in versions 1.13.6 and 1.14.5. | ||||
| CVE-2026-101911 | 1 Beaugunderson | 1 Ip-address | 2026-10-01 | 5.3 Medium |
| ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address6 constructor, Address6.isValid, and parse code in src/ipv6.ts accept unbounded strings and expand invalid characters through RE_BAD_CHARACTERS into large diagnostics. Material impact occurs only when an application accepts a very large attacker-controlled field and passes it to Address6 parsing without an earlier length bound. Common URL and header limits, and common body-parser defaults, generally constrain the effect; common defaults typically exclude 32 MiB fields. Megabyte-scale fields can cause a synchronous stall and high transient memory use, approximately 16 MiB can trigger an invalid string length exception, and process termination occurs at approximately 32 MiB. The affected entry points include Address6.isValid and construction paths that reach parse. This issue is fixed in version 10.7.1. | ||||
| CVE-2026-101909 | 1 Axios | 1 Axios | 2026-10-01 | 8.2 High |
| Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution. A separate same-process prototype-pollution flaw supplies inherited dots, indexes, metaTokens, maxDepth, visitor, or Blob values before object serialization. The inherited options alter toFormData field naming and data interpretation, maxDepth can force request failure, Blob changes value handling, and a polluted visitor can execute when an attacker already has the stronger ability to inject a function. Serialized field naming and data interpretation can change, maxDepth can cause request failure, Blob can alter value handling, and a polluted visitor can execute under the stronger function-injection primitive. This issue is fixed in versions 0.34.0 and 1.20.0. | ||||
| CVE-2026-101905 | 1 Axios | 1 Axios | 2026-10-01 | 7.4 High |
| Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process prototype-pollution flaw places a function on Object.prototype.createConnection. Node resolves and invokes the inherited createConnection socket factory, allowing the attacker-controlled function to select the transport endpoint. The attacker endpoint can receive request headers and bodies, including credentials, and return attacker-controlled responses while the URL appears legitimate. This issue is fixed in version 1.20.0. | ||||