Export limit exceeded: 399697 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 399697 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399697 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100520 | 1 Crivion | 1 Laranode | 2026-09-30 | 8.8 High |
| Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to write PHP files into other tenants' web roots and execute code as those tenants. | ||||
| CVE-2026-100502 | 1 Pawelmalak | 1 Flame | 2026-09-30 | 5 Medium |
| Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary lifespans by supplying unvalidated duration parameters. Attackers can mint near-permanent administrator tokens that survive password changes, retaining full control of the dashboard since tokens are verified only against a static JWT secret that is never rotated. | ||||
| CVE-2026-102844 | 1 Gedelumbung | 1 Hospitalmanagement | 2026-09-30 | 2.7 Low |
| A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects the function detail of the file application/modules/admin/controllers/laporan_data_pasien.php. Executing a manipulation of the argument id_param can lead to authorization bypass. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-100286 | 1 Devolutions | 1 Server | 2026-09-30 | 6.5 Medium |
| Missing authorization in the data source settings API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated non-administrative user to disclose integration secrets via a crafted API request. | ||||
| CVE-2026-103041 | 1 Modeltc | 1 Lightllm | 2026-09-30 | 9.8 Critical |
| LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges. | ||||
| CVE-2026-103042 | 1 Modeltc | 1 Lightllm | 2026-09-30 | 7.5 High |
| LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposed_set_value method to store unbounded key-value pairs without size limits, causing the worker process to crash and triggering node failure. | ||||
| CVE-2026-102843 | 1 Gedelumbung | 1 Hospitalmanagement | 2026-09-30 | 4.7 Medium |
| A security flaw has been discovered in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This affects the function hapus of the file application/modules/admin/controllers/data_galeri.php of the component Endpoint. Performing a manipulation of the argument gbr results in path traversal. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-100288 | 1 Devolutions | 1 Server | 2026-09-30 | N/A |
| Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records. | ||||
| CVE-2026-100289 | 1 Devolutions | 1 Server | 2026-09-30 | 5 Medium |
| Missing authorization in the gateway network scan token API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to generate a network scan token and perform internal network discovery and port scanning through the gateway via a crafted API request. | ||||
| CVE-2026-95376 | 1 Google | 1 Chrome | 2026-09-30 | N/A |
| Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium) | ||||
| CVE-2026-95390 | 1 Wireshark | 1 Wireshark | 2026-09-30 | 5.5 Medium |
| PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of service | ||||
| CVE-2026-102759 | 2026-09-30 | N/A | ||
| NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is never generated or compared. Empty TLS application-data records are legal, and are commonly emitted by TLS 1.0 implementations as a BEAST mitigation. | ||||
| CVE-2026-95350 | 1 Google | 1 Chrome | 2026-09-30 | 9.6 Critical |
| Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | ||||
| CVE-2026-95281 | 1 Google | 1 Chrome | 2026-09-30 | 9.6 Critical |
| Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | ||||
| CVE-2026-95322 | 1 Google | 1 Chrome | 2026-09-30 | 8.3 High |
| Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | ||||
| CVE-2026-95329 | 1 Google | 1 Chrome | 2026-09-30 | 9.6 Critical |
| Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | ||||
| CVE-2026-95335 | 1 Google | 1 Chrome | 2026-09-30 | 8.3 High |
| Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-95346 | 1 Google | 1 Chrome | 2026-09-30 | 4.8 Medium |
| UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via crafted network traffic. (Chromium security severity: Medium) | ||||
| CVE-2026-49243 | 1 Webmin | 1 Webmin | 2026-09-30 | N/A |
| Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.650, Webmin users who click on a malicious link to their server are vulnerable to this XSS vulnerability that could be used to execute attacker-controlled commands. This issue has been patched in version 2.650. | ||||
| CVE-2026-102630 | 2 Unopim, Webkul | 2 Unopim, Unopim | 2026-09-30 | 4.7 Medium |
| UnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies and honor the X-Forwarded-Host header without validation, allowing unauthenticated attackers to inject arbitrary origins into admin layout pages. Attackers can set X-Forwarded-Host to redirect JavaScript asset loading to their server, and when responses are cached by shared proxies, subsequent administrators execute attacker-supplied code in their authenticated sessions. | ||||