Export limit exceeded: 400180 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400180 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-102330 | 1 Google | 1 Chrome | 2026-09-30 | 6.5 Medium |
| Incorrect authorization in SiteIsolation in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-100279 | 2026-09-30 | 6.5 Medium | ||
| In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials | ||||
| CVE-2026-47552 | 2026-09-30 | 7.8 High | ||
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass an authorization check and modify privileged configuration. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-47554 | 2026-09-30 | 7.1 High | ||
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where improper verification of cryptographic signatures may cause signature verification to be bypassed under memory pressure. A successful exploit of this vulnerability might lead to denial of service and data tampering. | ||||
| CVE-2026-47509 | 2026-09-30 | 6.7 Medium | ||
| NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-47522 | 2026-09-30 | 6.7 Medium | ||
| NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-47525 | 2026-09-30 | 6.7 Medium | ||
| NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of an array index. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-47529 | 2026-09-30 | 6.7 Medium | ||
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-103470 | 1 Internet2 | 1 Grouper | 2026-09-30 | N/A |
| In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges. | ||||
| CVE-2026-47547 | 1 Nvidia | 5 Geforce, Nvs, Quadro and 2 more | 2026-09-30 | 6.7 Medium |
| NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-47549 | 1 Nvidia | 7 Geforce, Guest Driver, Nvs and 4 more | 2026-09-30 | 5.5 Medium |
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel module where an unprivileged local user could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to denial of service. | ||||
| CVE-2026-94216 | 1 St Engineering Idirect | 2 Evolution, Velocity Webserver Evolution | 2026-09-30 | 4.3 Medium |
| A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution. This vulnerability affects unknown code of the file /authorize of the component HTTP Request Handler. Executing a manipulation of the argument Success can lead to http response splitting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The validated environment is an EOL X7 (or an un-modelled legacy Evolution 21.x), and current supported releases (X10, X11, Velocity 5.x+) have no validated evidence of impact. | ||||
| CVE-2026-19445 | 2026-09-30 | N/A | ||
| A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected. Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected. | ||||
| CVE-2026-103056 | 2026-09-30 | 9 Critical | ||
| AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path, script_name, or script_args parameters to break out of quoted arguments and execute arbitrary commands on managed endpoints with SYSTEM or root privileges. | ||||
| CVE-2026-101884 | 2026-09-30 | 7.5 High | ||
| OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution. | ||||
| CVE-2026-101883 | 2026-09-30 | 5.4 Medium | ||
| OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to make the node's WebView send requests to localhost, private networks, or tailnet services from the user's machine. | ||||
| CVE-2026-101882 | 2026-09-30 | 8.8 High | ||
| OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through system.run without operator checks or user prompts. | ||||
| CVE-2026-101880 | 2026-09-30 | 8.8 High | ||
| OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving arbitrary command execution on Windows hosts. | ||||
| CVE-2026-101879 | 2026-09-30 | 6.5 Medium | ||
| OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera snaps, and location captures without consent prompts. Attackers can invoke screen.snapshot, camera.snap, and location.get over the node WebSocket to silently capture screenshots, photograph users through webcams, and obtain device geolocation without user interaction. | ||||
| CVE-2026-47491 | 2026-09-30 | 7.8 High | ||
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can cause improper release of memory resources, leaving a mapping accessible after the underlying memory is reused. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||