Export limit exceeded: 28628 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (28628 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103389 | 1 Misp | 1 Misp | 2026-09-30 | N/A |
| MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpoints. The stored value was subsequently concatenated directly into HTML markup by the D3-based correlation graph rendering scripts (both the default and Overmind themes) using the .html() method. A user holding the perm_galaxy_editor permission, which is granted to the stock User role, could store arbitrary HTML or JavaScript in the icon field. Any other user who opened the correlation graph of an event containing a cluster belonging to that galaxy would have the injected script executed in their browser session. Impact: - Arbitrary script execution in the context of the victim's MISP session - Potential theft of session credentials, manipulation of displayed data, or initiation of actions on behalf of the victim - Affects both the default and Overmind UI themes Affected versions: <2.5.48 | ||||
| CVE-2026-97302 | 2026-09-30 | 5.3 Medium | ||
| Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions. | ||||
| CVE-2026-97261 | 2026-09-30 | 5.3 Medium | ||
| Unauthenticated Sensitive Data Exposure in Notivo <= 1.4.2 versions. | ||||
| CVE-2026-97241 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions. | ||||
| CVE-2026-97240 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions. | ||||
| CVE-2026-83560 | 2026-09-30 | 5.3 Medium | ||
| The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users. | ||||
| CVE-2026-80333 | 2026-09-30 | 5.3 Medium | ||
| The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of any type that WordPress would otherwise not serve. | ||||
| CVE-2026-102845 | 1 Gedelumbung | 1 Hospitalmanagement | 2026-09-30 | 5.3 Medium |
| A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function error_reporting of the file index.php of the component HTTP Response. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-103321 | 1 Misp | 1 Misp | 2026-09-30 | N/A |
| MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature. The event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element's src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script. Preconditions: - An authenticated MISP user with the ability to create or modify an event graph entry. - A second user (the victim) who views the event graph and triggers the preview popover. Impact: - Execution of arbitrary JavaScript in the victim's browser within the MISP application context. - Potential theft of session tokens, cookies, or sensitive data accessible to the victim's browser. - Potential for performing actions on behalf of the victim within the MISP application. Affected: MISP versions prior to the fix (commit applied after v2.5.48). | ||||
| CVE-2026-88774 | 1 Citrix | 3 Netscaler Adc, Netscaler Application Delivery Controller, Netscaler Gateway | 2026-09-30 | 7.2 High |
| Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage. | ||||
| CVE-2026-100548 | 1 Openclaw | 1 Openclaw | 2026-09-30 | 5.3 Medium |
| OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 contain a credential exposure issue in memory embedding failover. When remote embedding fallback is configured and the primary embedding provider fails, the request can be sent to a different fallback provider while still reusing the primary provider's configured API key, causing that credential to be transmitted as a bearer token to an unintended vendor. The practical impact depends on the configured providers, whether failover occurs, and the privileges attached to the primary provider key. The issue is fixed in 2026.8.1; as a workaround, disable cross-provider embedding fallback or configure each provider with separate, narrowly scoped credentials. | ||||
| CVE-2026-100528 | 1 Openclaw | 1 Openclaw | 2026-09-30 | 5.4 Medium |
| OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In affected versions, when a third-party provider uses an OpenAI-compatible API and the resolved model metadata lacks a concrete base URL, a pinned session that continues after a model configuration hot reload retains that provider's credential while the OpenAI SDK selects its own default endpoint. A resulting request could disclose the configured third-party provider credential to an unrelated provider endpoint and fail with a misleading authentication error. Operators who observed this condition should rotate the affected credential. The issue is fixed in 2026.8.1. | ||||
| CVE-2026-100286 | 1 Devolutions | 1 Server | 2026-09-30 | 6.5 Medium |
| Missing authorization in the data source settings API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated non-administrative user to disclose integration secrets via a crafted API request. | ||||
| CVE-2026-77696 | 1 Openssl | 1 Openssl | 2026-09-29 | 3.7 Low |
| Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. | ||||
| CVE-2026-54872 | 1 Openssl | 1 Openssl | 2026-09-29 | 3.7 Low |
| Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. | ||||
| CVE-2026-54875 | 1 Openssl | 1 Openssl | 2026-09-29 | 3.7 Low |
| Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov | ||||
| CVE-2026-88059 | 1 Angular | 1 Angular | 2026-09-29 | 4 Medium |
| Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.1, Angular's @angular/common HttpTransferCache can cache an authenticated response when Server-Side Rendering (SSR) and hydration use a hierarchical HttpClient configured with withRequestsMadeViaParent. The child TransferCache evaluates an initially anonymous request before delegation, then a parent withInterceptors chain adds an Authorization header, cookie, or API token; although the parent cache skips the authenticated request, the child still stores the private response in TransferState serialized as JSON in the ng-state script. Exploitation requires provideClientHydration, child provideHttpClient delegation through withRequestsMadeViaParent, parent-level credential injection, and an SSR HTML response shared across users by a CDN, reverse proxy, or application cache. A later unauthenticated or unauthorized visitor can receive the cached HTML containing the earlier authenticated user's sensitive response data. Applications can mitigate by attaching credentials at the child, filtering sensitive endpoints with withHttpTransferCacheOptions, disabling transfer caching for sensitive routes, or marking personalized HTML private or no-store. This issue is fixed in versions 20.3.28, 21.2.20, and 22.1.1. | ||||
| CVE-2026-19503 | 1 Mongodb | 4 Atlas Sql Odbc Driver, Odbc Driver, Schema Builder Cli and 1 more | 2026-09-29 | 4.8 Medium |
| MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document. A user induced to connect to an uncontrolled MongoDB deployment using MONGODB-OIDC authentication may have an uncontrolled URI dispatched to their operating system's default protocol handler, potentially exposing credentials or, under certain conditions, resulting in code execution in the user's context. | ||||
| CVE-2026-97027 | 2 Flatpak, Redhat | 2 Flatpak, Enterprise Linux | 2026-09-29 | 3.6 Low |
| Flatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.desktop) and D-Bus Service (.service) files, instead of validating against an allowlist. A malicious Flatpak app can use this to cause denial of service (e.g. forced application restart loops) or to influence host D-Bus/systemd activation behavior beyond what the sandbox is intended to permit. | ||||
| CVE-2026-39372 | 1 Invoiceplane | 1 Invoiceplane | 2026-09-29 | 4.9 Medium |
| InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores and serves uploaded image attachments without stripping EXIF metadata. When an administrator uploads an image through invoice attachments, quote attachments, or another attachment feature and shares it with another user, the recipient can retrieve embedded GPS coordinates, timestamps, and device information. The preserved metadata can disclose private location and device details across users. This vulnerability is fixed in 1.7.2. | ||||