Export limit exceeded: 400318 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400318 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400318 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103270 | 1 Modeltc | 1 Lightllm | 2026-10-01 | 7.5 High |
| LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group to disrupt inference operations and wedge workers on deployments started with --enable_rl. | ||||
| CVE-2026-100262 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 7.6 High |
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates | ||||
| CVE-2026-100263 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 4.7 Medium |
| In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible | ||||
| CVE-2026-100265 | 1 Jetbrains | 1 Rider | 2026-10-01 | 4.8 Medium |
| In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation | ||||
| CVE-2026-100266 | 1 Jetbrains | 1 Hub | 2026-10-01 | 7.7 High |
| In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address | ||||
| CVE-2026-100267 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 5.9 Medium |
| In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters | ||||
| CVE-2026-100268 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 7.7 High |
| In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates | ||||
| CVE-2026-100276 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 5.9 Medium |
| In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action | ||||
| CVE-2026-100278 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 4.9 Medium |
| In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments | ||||
| CVE-2026-100280 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 3.1 Low |
| In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible | ||||
| CVE-2026-100823 | 1 Mozilla | 1 Firefox | 2026-10-01 | 5.4 Medium |
| Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157. | ||||
| CVE-2026-76727 | 1 Hewlett Packard Enterprise (hpe) | 1 Instant On | 2026-10-01 | 7.2 High |
| Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system. | ||||
| CVE-2026-76732 | 1 Hewlett Packard Enterprise (hpe) | 1 Instant On | 2026-10-01 | 6.4 Medium |
| A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control. | ||||
| CVE-2026-76736 | 1 Hewlett Packard Enterprise (hpe) | 1 Instant On | 2026-10-01 | 3.3 Low |
| A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service. | ||||
| CVE-2026-76737 | 1 Hewlett Packard Enterprise (hpe) | 1 Instant On | 2026-10-01 | 3 Low |
| An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service. | ||||
| CVE-2026-51570 | 2026-10-01 | 8.1 High | ||
| modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file. | ||||
| CVE-2026-51852 | 2026-10-01 | N/A | ||
| agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks. | ||||
| CVE-2026-51856 | 2026-10-01 | N/A | ||
| In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to Toolkit.call_tool_function, which invokes execute_python_code without an additional approval or isolation boundary on that path. | ||||
| CVE-2026-88920 | 1 Apache | 1 Wss4j | 2026-10-01 | 9.8 Critical |
| An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. | ||||
| CVE-2026-100257 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export | ||||