Export limit exceeded: 21084 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402022 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402022 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104477 | 1 Showdownjs | 1 Showdown | 2026-10-05 | 6.1 Medium |
| Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown links or images containing a double quote followed by onerror or onmouseover handlers to execute script when victims view rendered HTML. | ||||
| CVE-2026-104182 | 1 Uhop | 1 Stream-json | 2026-10-05 | 6.2 Medium |
| stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js and verifier at stream-json/jsonc/verifier.js restart comment-terminator scanning from the opening slash whenever a block or line comment spans an input chunk, while retaining the accumulated comment buffer. Delivering a large valid comment across many small chunks therefore causes quadratic CPU work and can stall the Node.js event loop. The maintainer characterizes the attack vector as local because the documented JSONC input is locally owned or user-controlled configuration, rather than input intended for the open internet. This JSONC-only scope does not include the plain JSON parser, which advances through and discards consumed string and number data. This issue is fixed in version 3.6.0. | ||||
| CVE-2025-56361 | 1 Csa-iot | 1 Matter | 2026-10-05 | 5.7 Medium |
| A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Level Control cluster's server tick logic (`emberAfLevelControlClusterServerTickCallback`). When a MoveToLevel command is executed and followed by a conflicting write to the OperationMode attribute (in the Pump Configuration and Control cluster), an invariant check (`minLevel < currentLevel`) fails and causes the device to abort. This leads to a denial of service condition. The issue is confirmed in SDK versions 1.3 and 1.4 (commit ab3d5ae), and is triggered remotely without authentication. | ||||
| CVE-2026-51894 | 1 Infiniflow | 1 Ragflow | 2026-10-05 | 6.5 Medium |
| infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_mindmap. A reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object. | ||||
| CVE-2026-51918 | 1 Ai4finance | 1 Finrobot | 2026-10-05 | 9.8 Critical |
| FinRobot 1.0.0 contains code injection in CodingUtils.create_file_with_code (). | ||||
| CVE-2026-88395 | 2026-10-05 | 9.8 Critical | ||
| GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter. | ||||
| CVE-2026-78860 | 2026-10-05 | N/A | ||
| An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the storage of information in plaintext | ||||
| CVE-2026-95166 | 2026-10-05 | N/A | ||
| In Bacularis v1.0.0 - 6.5.1 when adding a new pool, the LabelFormat field allows for a Cross Site Scripting (XSS) payload. | ||||
| CVE-2026-105712 | 1 Gnupg | 1 Gnupg | 2026-10-05 | 3.6 Low |
| gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk. | ||||
| CVE-2026-71298 | 1 Redhat | 1 Multicluster Engine | 2026-10-05 | 6.4 Medium |
| A flaw was found in maestro. A remote attacker could exploit a SQL injection vulnerability in the `orderBy` query parameter of its REST API list endpoints. This flaw, which does not require authentication, allows for read-only blind extraction of data from the database. | ||||
| CVE-2026-71299 | 1 Redhat | 1 Multicluster Engine | 2026-10-05 | 6.5 Medium |
| A flaw was found in Maestro. Its REST API write endpoints were registered without proper authentication middleware. This allows a remote attacker to perform unauthorized write operations, such as creating, modifying, or deleting consumers and resource bundles. This could lead to data integrity issues or a denial of service (DoS). | ||||
| CVE-2026-104711 | 1 Apache | 1 Struts | 2026-10-05 | 8.1 High |
| Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote code execution. Struts 7 is affected only when the OGNL allowlist is disabled; it is enabled by default. Applications using the default action mapper, the restful2 mapper, or the Struts REST plugin are not affected. This issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue. | ||||
| CVE-2026-51879 | 1 Hkuds | 1 Deeptutor | 2026-10-05 | 9.1 Critical |
| deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TutorBotManager.write_bot_file. A remote caller can enumerate bot IDs and overwrite another bot's whitelisted control files through the HTTP tutorbot file route. | ||||
| CVE-2026-51893 | 2026-10-05 | 9.8 Critical | ||
| infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object. | ||||
| CVE-2026-88424 | 2026-10-05 | N/A | ||
| FineAdmin v1.0 was discovered to contain a SQL injection vulnerability via the field/order parameter at ButtonService.GetListByFilter(). This vulnerability allows attackers to access sensitive database information via crafted SQL statements. | ||||
| CVE-2026-93318 | 1 Moby | 1 Buildkit | 2026-10-05 | N/A |
| A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised DiffIDs to derive cache and snapshot identity without validating that they matched the actual layer contents. If a BuildKit daemon with shared or persistent cache first processes such a malicious image, a later build using the victim image may mount the attacker-controlled layer contents as the base image. This can allow code from the malicious image to run in the victim build, for example by replacing a commonly executed path such as /bin/sh. The attacker-controlled code may read build secrets mounted into the build, access other build resources, alter output artifacts, or hang the build. The issue affects both regular snapshotters and lazy-pulling snapshotters such as stargz. | ||||
| CVE-2026-93322 | 1 Moby | 1 Buildkit | 2026-10-05 | 6.2 Medium |
| A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon. | ||||
| CVE-2026-28641 | 1 Google | 1 Android | 2026-10-05 | N/A |
| In shouldDisableUninstallButton of ApplicationActionButtonsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-105326 | 1 Redhat | 2 Enterprise Linux, Hummingbird | 2026-10-05 | 2.5 Low |
| An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription requests that supply a mailto notify-recipient-uri. The mailto notifier passes the recipient address to the configured sendmail program without ensuring it cannot be interpreted as command-line options. A remote attacker who can reach the CUPS service could supply a crafted recipient value starting with "-" to influence sendmail behavior. Successful exploitation depends on the installed mail transfer agent and CUPS network exposure, and may lead to execution of attacker-controlled commands with the privileges of the CUPS service user. | ||||
| CVE-2026-93320 | 1 Moby | 1 Buildkit | 2026-10-05 | 8.2 High |
| BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access. | ||||