Export limit exceeded: 399925 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 399925 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 399925 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399925 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-92873 | 2026-09-30 | N/A | ||
| Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node. | ||||
| CVE-2026-102587 | 1 Moodle | 1 Moodle | 2026-09-30 | 2.7 Low |
| A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized information disclosure by inferring hidden user data. | ||||
| CVE-2026-92899 | 1 Apache | 1 Wss4j | 2026-09-30 | 4.8 Medium |
| Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. | ||||
| CVE-2026-93903 | 1 Litespeedtech | 1 Litespeed Web Server | 2026-09-30 | N/A |
| LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case." | ||||
| CVE-2026-95349 | 1 Google | 2 Android, Chrome | 2026-09-30 | 9.6 Critical |
| Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | ||||
| CVE-2026-6223 | 1 Bahçelievler Muncipality | 1 Bihayat App | 2026-09-30 | 9.4 Critical |
| Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication Bypass. This issue affects BiHayat App: from 2.1.7 before 2.3. | ||||
| CVE-2026-92121 | 1 Apache | 1 Wss4j | 2026-09-30 | N/A |
| In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, so it stops evaluating SignedParts and SignedElements for the rest of the message. A policy requiring the SOAP Body to be signed is then satisfied even when the Body carries no signature, removing the protection against XML Signature Wrapping. Signature verification itself is unaffected. The DOM code is not affected. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4 which fix this issue. | ||||
| CVE-2026-103118 | 1 Graphicsmagick | 1 Graphicsmagick | 2026-09-30 | 4.3 Medium |
| A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. | ||||
| CVE-2026-95352 | 1 Google | 1 Chrome | 2026-09-30 | 5.4 Medium |
| Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low) | ||||
| CVE-2026-95292 | 1 Google | 1 Chrome | 2026-09-30 | 4.8 Medium |
| Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low) | ||||
| CVE-2026-95287 | 1 Google | 1 Chrome | 2026-09-30 | 5.4 Medium |
| Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-94286 | 1 X.org | 1 Libxtst | 2026-09-30 | 7.1 High |
| An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients. | ||||
| CVE-2026-94285 | 1 X.org | 1 Libx11 | 2026-09-30 | 5.1 Medium |
| An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients. | ||||
| CVE-2026-94284 | 1 X.org | 1 Libx11 | 2026-09-30 | 5.5 Medium |
| An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients. | ||||
| CVE-2026-94283 | 1 X.org | 1 Libx11 | 2026-09-30 | 6.5 Medium |
| An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients. | ||||
| CVE-2026-94282 | 1 X.org | 1 Libxi | 2026-09-30 | 5.6 Medium |
| An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client. | ||||
| CVE-2026-86530 | 1 Buffalo | 2 Wex-g300, Wsr-300hp | 2026-09-30 | 7.2 High |
| BUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrative user may send a crafted HTTP request and execute an arbitrary OS command. | ||||
| CVE-2026-85532 | 2026-09-30 | N/A | ||
| Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages. The fixes enforce a minimum key length of 16 bytes, a maximum length of 512 bytes, and a maximum offset of 4096 bytes. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. | ||||
| CVE-2026-76738 | 2026-09-30 | 2.7 Low | ||
| A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers without manual intervention. | ||||
| CVE-2026-74865 | 2026-09-30 | N/A | ||
| sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account. This issue was fixed in version 5.8.0~ynh9. | ||||