Export limit exceeded: 403510 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403510 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-82895 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow. | ||||
| CVE-2026-82900 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to delete arbitrary files due to improper limitation of a pathname to a restricted directory. | ||||
| CVE-2026-81932 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.6 High |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | ||||
| CVE-2026-84032 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 5.6 Medium |
| IBM Guardium Data Protection 12.2.2 could allow a remote attacker to conduct a man-in-the-middle attack due to improper certificate validation. | ||||
| CVE-2026-84035 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow. | ||||
| CVE-2026-84057 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | ||||
| CVE-2026-84058 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOGIN packet decoder. A remote attacker who can send a specially crafted TDS PRELOGIN packet to a network monitored by an IBM Guardium Collector may cause a denial of service or potentially execute arbitrary code on the Collector appliance. | ||||
| CVE-2026-84198 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow. | ||||
| CVE-2026-84209 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. | ||||
| CVE-2026-84230 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 7.5 High |
| IBM Guardium Data Protection 12.2.2 could allow a remote attacker to cause a denial of service due to a race condition resulting from concurrent unsynchronized writes to a shared map. | ||||
| CVE-2026-84246 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow. | ||||
| CVE-2026-84247 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability. | ||||
| CVE-2026-84249 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 9.8 Critical |
| IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary management operations due to missing authentication for critical function. | ||||
| CVE-2026-84875 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 7.5 High |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow. | ||||
| CVE-2026-84891 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 5.9 Medium |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to obtain sensitive information due to use of hard-coded credentials. | ||||
| CVE-2026-87980 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 3.1 Low |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a local attacker to obtain sensitive information due to cleartext storage of sensitive information in logs. | ||||
| CVE-2026-93034 | 1 Sglang | 1 Sglang | 2026-10-08 | 9.8 Critical |
| SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() in _maybe_unwrap_pickle without type allowlisting or authentication; this vulnerability persists via the msgpack path even when SGLANG_USE_PICKLE_IPC is disabled, and becomes remotely exploitable if data-parallel attention is enabled with a non-loopback --dist-init-addr setting. | ||||
| CVE-2026-66087 | 1 Apache | 1 Dolphinscheduler | 2026-10-08 | 8.1 High |
| An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to operate task instance in projects they are not authorized to access through the * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/stop * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/savepoint This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue. | ||||
| CVE-2026-66084 | 1 Apache | 1 Dolphinscheduler | 2026-10-08 | 8.1 High |
| An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint. The endpoint fails to verify that the task definition identified by code belongs to the project specified by projectCode. An authenticated user can supply the code of a project they are authorized to access together with a task definition code from another project, bypassing project access restrictions and modifying the target task definition and its upstream dependencies. This vulnerability can compromise workflow integrity and disrupt task execution in unauthorized projects.This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue. | ||||
| CVE-2026-66082 | 1 Apache | 1 Dolphinscheduler | 2026-10-08 | 6.5 Medium |
| An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to perform unauthorized operations on workflow schedules, workflow definitions, and task instances in other projects. The affected endpoints check permissions against the supplied projectCode but fail to verify that the target resource belongs to that project. An authenticated user with the required permissions in one project can supply that project's code together with a resource identifier from another project, bypassing the target project's access restrictions. The affected endpoints include: * POST /projects/{projectCode}/schedules/{id}/online and /offline: Activate or deactivate workflow schedules in another project. * POST /projects/{projectCode}/workflow-definition/{code}/release: Change the ONLINE/OFFLINE state of workflow definitions in another project. Successful exploitation allows users to alter workflow availability and interfere with task execution in projects they are not authorized to access. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue. | ||||