Search

Search Results (377122 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-48762 1 Baptistearno 1 Typebot.io 2026-08-13 5.4 Medium
TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a user-supplied audio URL using `fetch()` without applying the SSRF protection that exists elsewhere in the codebase. An attacker can direct the server to make HTTP requests to arbitrary internal addresses and localhost. The fetched content is passed to the OpenAI Whisper API and the transcription result is returned to the attacker. Version 3.16.0 fixes the issue.
CVE-2026-48702 2026-08-13 7.5 High
Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file into in-memory buffers without bounding the total decompressed size. The existing `max_apk_metadata_size` check (default 1MB) is only applied to individual tar entry header sizes after decompression completes, so it does not prevent a decompression bomb from consuming unbounded heap memory. An attacker can craft a gzip stream that compresses at a ~1000:1 ratio (e.g., 2MB compressed zeros → 2GB decompressed). When submitted as spec.package.content in an Alpine `ProposedEntry`, the server decompresses the full payload into memory during request processing, triggering a fatal Go runtime out-of-memory error or OS OOM-kill that cannot be caught by the server's recover() middleware. This is reachable via two unauthenticated endpoints, `POST /api/v1/log/entries (createLogEntry)` and `POST /api/v1/log/entries/retrieve (searchLogQuery)`. Both invoke `V001Entry.Canonicalize()` → `fetchExternalEntities()` → `apk.Unmarshal(packageData)`, which performs the unbounded decompression. Version 1.5.2 patches the issue. There is no effective workaround. Setting `max_request_body_size` reduces but does not eliminate exposure due to the ~1000:1 compression ratio (a 1MB body limit still allows ~1GB heap allocation). Setting `max_apk_metadata_size` has no effect on this vulnerability since the check is applied after decompression.
CVE-2026-48046 1 Truelockmc 1 Streambert 2026-08-13 N/A
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process download and execute an arbitrary binary, resulting in remote code execution. Version 2.5.0 contains a patch.
CVE-2026-47229 1 Admidio 1 Admidio 2026-08-13 5.4 Medium
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm_csrf_token` on every state-changing branch except `enable`. The `enable` case loads the SAML or OIDC client by UUID, calls `$client->enable($enabled)`, and persists the new state with no token check. Because the action is reachable via plain GET parameters, a third-party page can trick an authenticated administrator into disabling (or silently re-enabling) any configured SAML or OIDC client. Disabling an SSO client breaks every downstream relying-party application that authenticates through it. Version 5.0.10 contains a fix.
CVE-2026-42018 1 Jfrog 1 Artifactory 2026-08-13 7.5 High
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CVE-2026-29036 1 Davegamble 1 Cjson 2026-08-13 7.5 High
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted JSON Pointer escape sequences (~0 or ~1) in patch paths. Attackers can submit malicious RFC 6902 JSON Patch input to applications using cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() to silently corrupt data or delete unintended keys, potentially bypassing authorization controls in applications that rely on JSON Patch for access-controlled data modification.
CVE-2026-28189 2026-08-13 7.4 High
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions.
CVE-2026-28186 2026-08-13 8.1 High
Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions.
CVE-2026-28185 2026-08-13 9.8 Critical
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
CVE-2026-28174 2 Arraytics, Wordpress 2 Wp Event Solution, Wordpress 2026-08-13 6.5 Medium
Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
CVE-2026-28170 2 Meril, Wordpress 2 Blog Floating Button, Wordpress 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions.
CVE-2026-28168 2026-08-13 8.5 High
Subscriber SQL Injection in CubeWP <= 1.1.30 versions.
CVE-2026-28161 2026-08-13 8.8 High
Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
CVE-2026-28159 2026-08-13 6.5 Medium
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
CVE-2026-28158 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions.
CVE-2026-28157 2026-08-13 7.5 High
Subscriber Path Traversal in Do Lasso <= 358 versions.
CVE-2026-28156 2026-08-13 8.5 High
Subscriber SQL Injection in Do Lasso <= 358 versions.
CVE-2026-28155 2026-08-13 6.5 Medium
Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.
CVE-2026-28149 2026-08-13 9.8 Critical
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
CVE-2026-28148 2026-08-13 9.8 Critical
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.