Export limit exceeded: 401115 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 401115 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (401115 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-12540 | 1 Redhat | 3 Satellite, Satellite Capsule, Satellite Utils | 2026-10-02 | 8.2 High |
| A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ", or |) to break out of the intended command and execute arbitrary code. | ||||
| CVE-2026-12423 | 1 Redhat | 3 Satellite, Satellite Capsule, Satellite Utils | 2026-10-02 | 7.5 High |
| A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the server's valid_host_token? method evaluates to true, granting access to the kickstart template even if the requester provides no token at all in the URL. | ||||
| CVE-2026-12405 | 1 Redhat | 3 Satellite, Satellite Capsule, Satellite Utils | 2026-10-02 | 8.8 High |
| A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user property marked as overridable: true, the application fails to properly sanitize the effective_user input provided during the API request. The exploitation does not rely on the content or logic of the Job Template/playbook itself; rather, the injection occurs during the instantiation of the job execution environment by the Satellite server. An attacker with permissions to execute job templates can inject arbitrary shell commands into this parameter, which are executed on the target infrastructure with the privileges of the execution user. | ||||
| CVE-2026-96659 | 1 Redhat | 3 Satellite, Satellite Capsule, Satellite Utils | 2026-10-02 | 9.1 Critical |
| A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw may allow the user to execute arbitrary commands as the Foreman system account. | ||||
| CVE-2026-96658 | 1 Redhat | 3 Satellite, Satellite Capsule, Satellite Utils | 2026-10-02 | 9.9 Critical |
| A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling them to run arbitrary commands on the hosting server. | ||||
| CVE-2026-100266 | 1 Jetbrains | 1 Hub | 2026-10-02 | 7.7 High |
| In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address | ||||
| CVE-2026-94645 | 1 Apache | 1 Thrift | 2026-10-02 | N/A |
| Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||
| CVE-2026-94644 | 1 Apache | 1 Thrift | 2026-10-02 | N/A |
| Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||
| CVE-2026-61373 | 1 Apache | 1 Thrift | 2026-10-02 | N/A |
| Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java TSaslNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||
| CVE-2026-100270 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 3.3 Low |
| In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations | ||||
| CVE-2026-100271 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 2.7 Low |
| In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects | ||||
| CVE-2026-100272 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 4.9 Medium |
| In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues | ||||
| CVE-2026-100273 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 8.2 High |
| In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution | ||||
| CVE-2026-51898 | 1 Sinaptik-ai | 1 Pandas-ai | 2026-10-02 | N/A |
| sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute. | ||||
| CVE-2026-51901 | 1 Transformeroptimus | 1 Superagi | 2026-10-02 | N/A |
| SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated users from one organization to schedule existing agents belonging to a different organization without proper authorization checks. The endpoint accepts an agent_id parameter but does not verify that the agent belongs to the authenticated user's organization. | ||||
| CVE-2026-51906 | 2026-10-02 | N/A | ||
| In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers to write downloaded images to arbitrary locations on the server filesystem by manipulating the project_id parameter. | ||||
| CVE-2026-94646 | 2 Apache, Redhat | 2 Thrift, Hummingbird | 2026-10-02 | 7.5 High |
| Uncaught exception, Improper validation of specified quantity in input, Improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||
| CVE-2026-100274 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template | ||||
| CVE-2026-104849 | 2026-10-02 | N/A | ||
| Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.filename can replace the intended worker module. Applications are affected only when they pass their own second-argument options object to pool.run(); calls without that argument use the trusted default options object. An attacker who can first pollute the prototype can cause the worker pool to load attacker-selected JavaScript and can read or modify task data with the host process's privileges. This issue is fixed in version 2.1.2. | ||||
| CVE-2026-96288 | 2026-10-02 | N/A | ||
| Uncontrolled Recursion, Allocation of resources without limits or throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||