Search

Search Results (399812 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-102910 1 Sourcecodester 1 Online Reviewer Management System 2026-09-30 7.3 High
A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/examproper/exam-delete.php. The manipulation of the argument test_id results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
CVE-2026-73597 2026-09-30 6.5 Medium
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Launch of phishing attacks, and Protection mechanism bypass.
CVE-2026-66083 1 Apache 1 Dolphinscheduler 2026-09-30 6.5 Medium
The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source configuration and other sensitive metadata, depending on the fields returned by the endpoint. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue.
CVE-2026-100779 1 Mozilla 1 Firefox 2026-09-30 8.8 High
Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100783 1 Mozilla 1 Firefox 2026-09-30 4.3 Medium
Uninitialized memory in the Audio/Video component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100799 1 Mozilla 1 Firefox 2026-09-30 4.3 Medium
Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
CVE-2026-100801 1 Mozilla 1 Firefox 2026-09-30 8.8 High
Privilege escalation in the DLL Services component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
CVE-2026-100817 1 Mozilla 1 Firefox 2026-09-30 N/A
Other issue in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 157.
CVE-2026-100826 1 Mozilla 1 Firefox 2026-09-30 6.5 Medium
Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-103088 1 Jknack 1 Handlebars.java 2026-09-30 7.5 High
Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application with a file: template prefix and a request-derived view name, a percent-encoded traversal such as %2e%2e/ bypasses both the view-resolver check and the loader-side containment and reads files outside the configured template base directory.
CVE-2026-103108 1 Pexip 1 Infinity 2026-09-30 7.5 High
Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service
CVE-2026-100802 1 Mozilla 1 Firefox 2026-09-30 4.3 Medium
Uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 157.
CVE-2026-102908 1 Sourcecodester 1 Online Reviewer Management System 2026-09-30 7.3 High
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/examproper/questions-view.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-100821 1 Mozilla 1 Firefox 2026-09-30 N/A
Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-100823 1 Mozilla 1 Firefox 2026-09-30 N/A
Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157.
CVE-2026-100829 1 Mozilla 1 Firefox 2026-09-30 N/A
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-96422 1 Wireshark 1 Wireshark 2026-09-30 5.5 Medium
Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-100762 1 Mozilla 1 Firefox 2026-09-30 9.6 Critical
Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVE-2026-96869 1 Mozilla 1 Firefox 2026-09-30 4.3 Medium
Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
CVE-2026-102906 1 0xshariq 1 Github-mcp-server 2026-09-30 6.3 Medium
A vulnerability was identified in 0xshariq github-mcp-server up to 52e764a7d66eac1726fce02ca7bb5a638571801a. This issue affects the function child_process.exec of the file src/github.ts of the component Git Remove MCP Tool. Such manipulation of the argument File leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.