Export limit exceeded: 402679 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402679 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-80355 | 1 Dell | 6 Dell Openmanage Server Administrator Managed Node For Rhel 8.10, Dell Openmanage Server Administrator Managed Node For Rhel 9.4, Dell Openmanage Server Administrator Managed Node For Sles 15 and 3 more | 2026-10-06 | 5.4 Medium |
| Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | ||||
| CVE-2026-103630 | 1 Google | 1 Chrome | 2026-10-06 | 9.6 Critical |
| Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-81548 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-10-06 | 8.8 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | ||||
| CVE-2026-81549 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-10-06 | 9.6 Critical |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header. | ||||
| CVE-2026-51878 | 1 Hkuds | 1 Deeptutor | 2026-10-06 | 4.3 Medium |
| deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TurnRuntimeManager.regenerate_last_turn. A remote caller can enumerate or obtain a session_id and trigger regenerate on another user's session. | ||||
| CVE-2026-51873 | 1 Stitionai | 1 Devika | 2026-10-06 | 8.8 High |
| Devika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_project function, which allows attackers to write files outside the intended project workspace. | ||||
| CVE-2026-37719 | 2026-10-06 | 9.8 Critical | ||
| An issue in dormakaba evolo Service (all versions) allows a remote attacker to execute arbitrary code as SYSTEM via a .NET component. | ||||
| CVE-2026-105048 | 1 Zilliz | 1 Attu | 2026-10-06 | 4 Medium |
| The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses). | ||||
| CVE-2025-31626 | 1 Wordpress | 1 Wordpress | 2026-10-06 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alisaleem252 Support Helpdesk Ticket System Lite ticket-help-desk-system-lite allows Reflected XSS.This issue affects Support Helpdesk Ticket System Lite: from n/a through 4.5.2. | ||||
| CVE-2026-81552 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-10-06 | 8.8 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables. | ||||
| CVE-2026-104070 | 2026-10-06 | 9.8 Critical | ||
| The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a malicious .html skeleton file, disclose sensitive configuration files containing the site secret, and forge a signed ajax context to execute the uploaded skeleton, achieving arbitrary PHP code execution as the web-server user. | ||||
| CVE-2026-82093 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-10-06 | 8.8 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data. | ||||
| CVE-2026-82094 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-10-06 | 7.1 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory. | ||||
| CVE-2026-98218 | 1 Linux | 1 Linux Kernel | 2026-10-06 | N/A |
| In the Linux kernel, the following vulnerability has been resolved: i2c: atr: fix dangling adapter pointer on add failure i2c_atr_add_adapter() stores atr->adapter[chan_id] before i2c_add_adapter() so that the I2C bus notifier can match child clients during registration. On failure the channel is freed but the slot was left pointing at freed memory, which can lead to use-after-free in i2c_atr_del_adapter() / cleanup and also block reuse with -EEXIST. Clear the slot on the i2c_add_adapter() error path before freeing chan. | ||||
| CVE-2026-80379 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-10-06 | 8.8 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | ||||
| CVE-2026-80412 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-10-06 | 8.8 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper escaping of connector property values during OSH script generation. | ||||
| CVE-2026-80425 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-10-06 | 8.8 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | ||||
| CVE-2026-80423 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-10-06 | 8.8 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts. | ||||
| CVE-2026-81208 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-10-06 | 7.7 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnerability to obtain credentials intended for other users or environments. | ||||
| CVE-2026-81536 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-10-06 | 7.7 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection. | ||||