Search

Search Results (403624 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-84209 1 Ibm 1 Guardium Data Protection 2026-10-09 8.1 High
IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
CVE-2026-79842 1 Hewlett Packard Enterprise(hpe) 1 Intelligent Management Center 2026-10-09 9.1 Critical
An authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713
CVE-2026-46569 1 Tuxera 1 Ntfs-3g 2026-10-09 7.7 High
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by extending a directory, e.g., by creating a file.
CVE-2026-18740 1 Ibm 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more 2026-10-09 8.8 High
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to perform unauthorized actions due to argument injection.
CVE-2026-11318 1 Zuler Technology 1 Deskin 2026-10-09 7.8 High
Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service without authentication. Attackers can invoke the privileged installer method to run an attacker-supplied installer, achieving full root compromise of the macOS host.
CVE-2026-107831 1 Banq 1 Jivejdon 2026-10-09 4.3 Medium
Jivejdon through 5.0 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing actions by abusing GET endpoints lacking anti-CSRF tokens. Attackers can lure authenticated users to crafted links targeting /account/protected/delAll, /account/protected/sub/delSub, or /message/updateAction to delete private messages and subscriptions or rename threads.
CVE-2026-107715 1 Sparklemotion 1 Mechanize 2026-10-09 6.8 Medium
The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize sends caller-supplied credential headers to a different host after an HTTP redirect. Mechanize#request_headers= is reapplied by Mechanize::HTTP::Agent#request_add_headers even after Mechanize::HTTP::Agent#response_redirect strips per-request headers, and the protected header lists omit Proxy-Authorization and Cookie2. An attacker who controls a redirect target can capture bearer tokens or session cookies supplied through request_headers= or the per-request headers argument, while Mechanize#cookie_jar and Mechanize::HTTP::AuthStore are not affected. This issue is fixed in version 2.14.1.
CVE-2026-105827 1 Imagemagick 1 Imagemagick 2026-10-09 5.3 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105826 1 Imagemagick 1 Imagemagick 2026-10-09 5.3 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105825 1 Imagemagick 1 Imagemagick 2026-10-09 5.3 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105824 1 Imagemagick 1 Imagemagick 2026-10-09 5.9 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105823 1 Imagemagick 1 Imagemagick 2026-10-09 4.0 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105405 1 Imagemagick 1 Imagemagick 2026-10-09 5.9 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105404 1 Imagemagick 1 Imagemagick 2026-10-09 5.3 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105403 1 Imagemagick 1 Imagemagick 2026-10-09 6.2 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105402 1 Imagemagick 1 Imagemagick 2026-10-09 5.3 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105401 1 Imagemagick 1 Imagemagick 2026-10-09 5.3 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-11936 1 Ibm 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more 2026-10-09 4.9 Medium
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 local management interface in certain configurations is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2026-105400 1 Imagemagick 1 Imagemagick 2026-10-09 3.3 Low
This CVE ID has been rejected as a duplicate.
CVE-2026-105399 1 Imagemagick 1 Imagemagick 2026-10-09 5.3 Medium
This CVE ID has been rejected as a duplicate.