Export limit exceeded: 403798 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403798 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403798 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-20536 | 2 Mediatek, Mediatek, Inc. | 27 Mt6878, Mt6878 Firmware, Mt6881 and 24 more | 2026-10-09 | 6.7 Medium |
| In aidl, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11242428; Issue ID: MSV-9038. | ||||
| CVE-2026-106405 | 1 Google | 2 Android, Chrome | 2026-10-09 | 6 Medium |
| Race condition in CustomTabs in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Medium) | ||||
| CVE-2026-106407 | 1 Google | 1 Chrome | 2026-10-09 | 6.5 Medium |
| Incorrect authorization in GetUserMedia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106408 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-10-09 | 6.5 Medium |
| Protection mechanism failure in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-78406 | 1 Ibm | 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more | 2026-10-09 | 9.8 Critical |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data. | ||||
| CVE-2026-19498 | 1 Ibm | 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more | 2026-10-09 | 5.9 Medium |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to cause a denial of service due to uncontrolled recursion. | ||||
| CVE-2026-12109 | 1 Ibm | 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more | 2026-10-09 | 5.5 Medium |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow an attacker with administrative privileges and access to the local management interface to execute arbitrary code due to an unbounded write to a fixed-size stack buffer. | ||||
| CVE-2026-102490 | 3 Docker, Linux, Zammad | 3 Docker, Linux Kernel, Zammad | 2026-10-09 | 7.8 High |
| Zammad packages built with packager.io (DEB and RPM) could have allowed a local attacker who already had file system write privileges as the unprivileged zammad service account to escalate to full root privileges on the host. Service processes began running as root and executed files that were owned and writable by the zammad account before dropping their identity to that account. An attacker holding that foothold could have escalated within seconds, because the affected services were restarted automatically whenever they stopped; no administrator interaction was required. Only installations from the DEB and RPM packages were affected — installations from source or the official container images were not. All released packaged versions were affected. | ||||
| CVE-2015-3306 | 5 Debian, Fedoraproject, Opensuse and 2 more | 5 Debian Linux, Fedora, Tumbleweed and 2 more | 2026-10-09 | 10 Critical |
| The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. | ||||
| CVE-2026-11888 | 1 Ibm | 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more | 2026-10-09 | 6.4 Medium |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to an information disclosure attack. | ||||
| CVE-2026-11930 | 1 Ibm | 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more | 2026-10-09 | 5.9 Medium |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 may not enforce authorization correctly for some web servers. | ||||
| CVE-2026-84209 | 1 Ibm | 1 Guardium Data Protection | 2026-10-09 | 8.1 High |
| IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. | ||||
| CVE-2026-18740 | 1 Ibm | 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more | 2026-10-09 | 8.8 High |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to perform unauthorized actions due to argument injection. | ||||
| CVE-2026-11318 | 1 Zuler Technology | 1 Deskin | 2026-10-09 | 7.8 High |
| Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service without authentication. Attackers can invoke the privileged installer method to run an attacker-supplied installer, achieving full root compromise of the macOS host. | ||||
| CVE-2026-107831 | 1 Banq | 1 Jivejdon | 2026-10-09 | 4.3 Medium |
| Jivejdon through 5.0 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing actions by abusing GET endpoints lacking anti-CSRF tokens. Attackers can lure authenticated users to crafted links targeting /account/protected/delAll, /account/protected/sub/delSub, or /message/updateAction to delete private messages and subscriptions or rename threads. | ||||
| CVE-2026-107715 | 1 Sparklemotion | 1 Mechanize | 2026-10-09 | 6.8 Medium |
| The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize sends caller-supplied credential headers to a different host after an HTTP redirect. Mechanize#request_headers= is reapplied by Mechanize::HTTP::Agent#request_add_headers even after Mechanize::HTTP::Agent#response_redirect strips per-request headers, and the protected header lists omit Proxy-Authorization and Cookie2. An attacker who controls a redirect target can capture bearer tokens or session cookies supplied through request_headers= or the per-request headers argument, while Mechanize#cookie_jar and Mechanize::HTTP::AuthStore are not affected. This issue is fixed in version 2.14.1. | ||||
| CVE-2026-105827 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.3 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105826 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.3 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105825 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.3 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105824 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.9 Medium |
| This CVE ID has been rejected as a duplicate. | ||||