Export limit exceeded: 403798 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403798 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403798 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-107614 | 1 Glavsoft | 1 Tightvnc | 2026-10-09 | 6.1 Medium |
| An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0xFFFFFFFF, producing an access roughly 4 GB beyond the 64 KB cursor buffer; a monochrome cursor of height 1 also becomes 0 because getCursorHeight() halves the height in place. | ||||
| CVE-2026-107615 | 1 Glavsoft | 1 Tightvnc | 2026-10-09 | 7.8 High |
| An uncontrolled search path element vulnerability in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to execute arbitrary code with SYSTEM privileges. DynamicLibrary::init() (and ThemeLib) load screenhooks32.dll / screenhooks64.dll with LoadLibrary() using a bare file name and no LOAD_LIBRARY_SEARCH_* flags, so the TightVNC service follows the default DLL search order and loads an attacker-planted DLL from a writable directory earlier in that order (for example, an installation directory with permissive ACLs). | ||||
| CVE-2026-91844 | 1 İzometri It | 1 Eimzamip | 2026-10-09 | 7.3 High |
| Unrestricted upload of file with dangerous type vulnerability in İzometri IT Services Domestic and Foreign Trade Co. Ltd. Eimzamip allows Using Malicious Files. This issue affects eimzamip: from v1.6.4 before v1.6.6. | ||||
| CVE-2026-89290 | 1 İzometri It | 1 Eimzamip | 2026-10-09 | 3.5 Low |
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in İzometri IT Services Domestic and Foreign Trade Co. Ltd. Eimzamip allows Stored XSS. This issue affects eimzamip: from v1.6.4 before v1.6.7. | ||||
| CVE-2026-107634 | 1 Aorimn | 1 Dislocker | 2026-10-09 | 6.1 Medium |
| Dislocker through 0.7.3 contains a heap out-of-bounds read vulnerability in get_dataset() and get_next_datum() that never validate dataset and datum sizes against the metadata allocation. Attackers can craft a BitLocker volume image with inflated dataset or datum sizes that, when opened or mounted, crashes dislocker or discloses adjacent heap memory. | ||||
| CVE-2026-107635 | 1 Aorimn | 1 Dislocker | 2026-10-09 | 5.5 Medium |
| Dislocker through 0.7.3 contains an integer underflow vulnerability in get_vmk() and get_fvek() that allows attackers to trigger out-of-bounds heap reads via crafted datum sizes. Attackers can supply a malicious BitLocker volume image with a datum_size smaller than the 36-byte AES-CCM header, causing hexdump() to over-read and crash dislocker. | ||||
| CVE-2026-107640 | 1 Integrics | 1 Enswitch | 2026-10-09 | 9.1 Critical |
| Integrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json/user/password/update/ that allows unauthenticated attackers to change account passwords by omitting the reset parameter. Attackers can target accounts with no pending reset, whose empty reset_key matches the defaulted empty value, to take over administrator accounts after enumerating valid usernames. | ||||
| CVE-2026-12859 | 1 Caz Informatics | 1 Advancity Alms Cloud | 2026-10-09 | 6.5 Medium |
| Missing Authorization vulnerability in Caz Informatics Services Trade Inc. Advancity ALMS Cloud allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Advancity ALMS Cloud: through 2026-10-08. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-107565 | 2 Luksmeta, Redhat | 4 Luksmeta, Enterprise Linux, Openshift and 1 more | 2026-10-09 | 5.1 Medium |
| A flaw was found in luksmeta. A local attacker with administrative privileges can cause data corruption when saving metadata to a Linux Unified Key Setup (LUKS) device. Due to incorrect boundary calculations and flawed overlap detection, new metadata entries can be written beyond available free space or over existing records. This issue can corrupt stored encrypted payload data or existing metadata, potentially rendering the affected data inaccessible. | ||||
| CVE-2026-107623 | 1 Redhat | 4 Build Keycloak, Build Of Keycloak, Red Hat Single Sign On and 1 more | 2026-10-09 | 4.3 Medium |
| A flaw was found in the OIDC Dynamic Client Registration (DCR) component of Keycloak. A bug in the response serialization causes the backchannel logout offline token revocation setting to be omitted from responses. When a client performs a standard update, this missing information causes the setting to be silently disabled. As a result, offline tokens may remain valid even after a user session is terminated via backchannel logout. | ||||
| CVE-2026-107589 | 1 Jacamar Ci | 1 Jacamar Ci | 2026-10-09 | 7.5 High |
| Insufficient job validation for service accounts in Jacamar CI prior to v0.30.0 allows authenticated CI users to generate arbitrary account names. | ||||
| CVE-2026-106177 | 1 Hp Inc | 4 Hp Sure Click Enterprise, Hp Wolf Pro Security, Hp Wolf Pro Security Edition and 1 more | 2026-10-09 | 6.4 Medium |
| A kernel buffer overflow vulnerability in HP Sure Click versions prior to 4.4.33 may allow local privilege escalation or arbitrary code execution. HP has released version 4.4.33 to address this vulnerability. | ||||
| CVE-2026-61801 | 2 Moby, Redhat | 2 Sys, Hummingbird | 2026-10-09 | 5.5 Medium |
| The `github.com/moby/sys/user` package provides Go utilities for parsing and looking up entries in Unix-style user and group database files. Versions before 0.4.1 do not sufficiently limit entries when parsing `/etc/passwd`- or `/etc/group`-style files, allowing an attacker who can supply a specially crafted file to cause excessive memory consumption and potentially terminate the affected process due to an out-of-memory condition. This issue is patched in version 0.4.1. As a workaround, avoid parsing attacker-controlled user or group database files, or validate and limit untrusted input before parsing it. | ||||
| CVE-2026-104077 | 1 Obsidian | 1 Obsidian Desktop | 2026-10-09 | 7.8 High |
| Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is processed by the bundled Reveal.js 4.3.1 within the Slides core plugin, allowing a javascript: URL to execute in the resulting background iframe. Because Node integration is enabled and context isolation is disabled in Obsidian's vault renderer, the injected script can call parent.require() to access Node APIs such as fs and child_process, enabling arbitrary operating system command execution when the victim opens the note and manually starts the presentation. | ||||
| CVE-2026-104078 | 1 Obsidian | 1 Obsidian Desktop | 2026-10-09 | 7.8 High |
| Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterURL to produce an empty protocol that bypasses the configured safeProtocols restrictions. Attackers can craft a note containing a malicious MathJax formula that renders as a javascript: URL anchor, which when clicked by the victim in Live Preview executes in the Node-integration-enabled vault renderer via require('child_process'), achieving arbitrary operating system command execution as the desktop user. | ||||
| CVE-2026-107709 | 1 Bower Decompress-zip | 1 Decompress-zip | 2026-10-09 | 7.8 High |
| A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3. The vulnerability located in `lib/decompress-zip.js` improperly validates archive entry paths during ZIP extraction. A crafted ZIP archive containing entries that resolve to prefix-sibling directories can cause files to be written outside the intended extraction directory. Successful exploitation may allow arbitrary file overwrite, application compromise, or remote code execution depending on the target environment and writable sibling paths. | ||||
| CVE-2026-107296 | 1 Mcollina | 1 Msgpack5 | 2026-10-09 | 3.7 Low |
| msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer while computing the value. Applications that retain or reuse encoded input for integrity checks, logging, or later processing can observe silently corrupted data, while positive integers and other MessagePack value types are unaffected. This issue is fixed in version 6.1.0. | ||||
| CVE-2026-107297 | 1 Mcollina | 1 Msgpack5 | 2026-10-09 | 5.9 Medium |
| msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack container across many small chunks, causing completed elements to be decoded repeatedly, producing quadratic CPU use and blocking the event loop. This issue is fixed in version 6.1.0. | ||||
| CVE-2026-107300 | 1 Mcollina | 1 Msgpack5 | 2026-10-09 | 7.5 High |
| msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue is fixed in version 6.1.0. | ||||
| CVE-2026-107301 | 1 Mcollina | 1 Msgpack5 | 2026-10-09 | 6.5 Medium |
| msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, constructing msgpack5 with an empty or partial options object disables the default protoAction: 'error' protection. A decoded map containing a __proto__ key can then replace the decoded object's prototype, potentially changing inherited properties or downstream behavior, although Object.prototype is not modified globally. This issue is fixed in version 6.1.0. | ||||