Export limit exceeded: 400803 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (400803 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-93495 1 Asus 13 Motherboard Prime Z390-a , Motherboard Prime Z390-a H10 , Motherboard Pro Ws C246-ace and 10 more 2026-10-01 N/A
Improper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a specially crafted device.
CVE-2026-82829 1 Hitachi Industrial Equipment Systems 1 Hitachi Coding Software Suite 2026-10-01 9.8 Critical
Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain unauthorized access by exploiting hidden accounts or hard coded credentials. This issue affects Hitachi Coding Software Suite: through 3.3.0.
CVE-2026-82828 1 Hitachi Industrial Equipment Systems 1 Hitachi Coding Software Suite 2026-10-01 8.8 High
Hitachi Coding Software Suite contains an Incorrect Authorization vulnerability that allows an unprivileged user to perform administrator-level operations. This issue affects Hitachi Coding Software Suite: through 3.3.0.
CVE-2026-82827 1 Hitachi Industrial Equipment Systems 1 Hitachi Coding Software Suite 2026-10-01 9.8 Critical
Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to generate unauthorized Bearer tokens and exploit administrative functions. This issue affects Hitachi Coding Software Suite: through 3.3.0.
CVE-2026-82826 1 Hitachi Industrial Equipment Systems 1 Hitachi Coding Software Suite 2026-10-01 7.5 High
Hitachi Coding Software Suite contains a vulnerability related to the Cleartext Transmission of Sensitive Information which allows an attacker to eavesdrop on with authentication credentials and sensitive data in transit. This issue affects Hitachi Coding Software Suite: through 3.3.0.
CVE-2026-82825 1 Hitachi Industrial Equipment Systems 1 Hitachi Coding Software Suite 2026-10-01 9.8 Critical
Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Function. This allows an unauthenticated attacker to invoke a critical API, potentially leading to unauthorized retrieval or alteration of sensitive information, or unauthorized manipulation. This issue affects Hitachi Coding Software Suite: through 3.3.0.
CVE-2026-82824 1 Hitachi Industrial Equipment Systems 1 Hitachi Coding Software Suite 2026-10-01 9.8 Critical
Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files. This issue affects Hitachi Coding Software Suite: through 3.3.0.
CVE-2026-80276 1 Comelit Group 1 1456b Multi-user Gateway 2026-10-01 7.5 High
Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 expose a network-accessible management interface that does not require authentication. Through this interface, sensitive device configuration data - including the Remote Configuration Password - can be read in cleartext by a remote, unauthenticated attacker.
CVE-2026-80275 1 Comelit Group 1 1456b Multi-user Gateway 2026-10-01 8.8 High
Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated user level can invoke this function to overwrite the installer (administrator) account password.
CVE-2026-78249 2026-10-01 N/A
A path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 1.1.3 and earlier, Apeos C3567 1.1.3, or other products listed, specifically in the handling of externally supplied parameters. If the device receives a specially crafted, malicious request, it may trigger unintended processing.
CVE-2026-76146 1 Genians, Inc 1 Genian Ssl Pns (xenics Auther) 2026-10-01 N/A
An OS command injection vulnerability in Genian SSL PNS allows an attacker who knows only the client access ID, without the password, to execute arbitrary commands remotely
CVE-2026-15809 1 Redhat 4 Confidential Compute Attestation, Openshift, Openshift Container Platform and 1 more 2026-10-01 7.8 High
A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
CVE-2026-67075 1 Hcltech 1 Digital Experience 2026-10-01 6.5 Medium
HCL Digital Experience is affected by improper input sanitation.  This can result in HTML injection which could be leveraged in content spoofing from a trusted domain. Apply HCL Digital Experience 9.5 CF238 or later to address this.
CVE-2026-34190 1 Pandora Fms 1 Pandora Fms 2026-10-01 N/A
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands via sequential, unvalidated GET requests when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
CVE-2026-34189 1 Pandora Fms 1 Pandora Fms 2026-10-01 N/A
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
CVE-2026-12855 1 Insyde Software 1 Insydeh2o 2026-10-01 8.2 High
Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.
CVE-2026-103687 1 Rhukster 1 Dom-sanitizer 2026-10-01 7.3 High
A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.16 is sufficient to fix this issue. The name of the patch is 139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a. Upgrading the affected component is recommended.
CVE-2026-103664 1 Misp 1 Misp 2026-10-01 N/A
MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, was passed directly into inline JavaScript within the rendered HTML response without any sanitization or type enforcement. An attacker who can convince an authenticated MISP user to navigate to a crafted URL (for example, via a phishing link) can inject arbitrary JavaScript that executes in the victim's browser context. This may allow the attacker to read session tokens, manipulate the page, or perform actions on behalf of the victim. Preconditions: - The victim must be authenticated to MISP and access the analyst data view for an attribute or object. - The attacker must supply a malicious seed value in the URL path. Impact: - Execution of arbitrary JavaScript in the victim's browser session. - Potential theft of session credentials or sensitive data visible in the page. - Manipulation of the analyst data interface. Affected: MISP versions prior to the fix (commit 58925dbf0, post v2.5.48).
CVE-2026-103662 1 Misp 1 Misp 2026-10-01 N/A
MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag). The affected forms echoed a user-supplied tag name value from the request unescaped into the rendered HTML output. An attacker who can induce a site administrator to visit a crafted URL containing a malicious tag name parameter can execute arbitrary JavaScript in the administrator's browser session. Preconditions: - The target must be running a MISP instance with the legacy taxonomy tag confirmation views enabled. - The victim must be an authenticated site administrator. - The victim must navigate to the attacker-crafted URL (e.g., via a phishing link). Security impact: - Execution of arbitrary client-side script in the context of the administrator's browser. - Potential theft of session tokens, CSRF tokens, or other sensitive data accessible from the page. - Potential for performing privileged actions on behalf of the administrator within the MISP interface. Affected versions: <2.5.48.
CVE-2026-103659 1 Misp 1 Misp 2026-10-01 N/A
MISP contains an authorization bypass in the event flattening feature. When a user requests an event with the flatten option enabled, the application removes the Object containment from the query and returns object attributes as top-level event attributes. In doing so, the object-level distribution and sharing-group access control check was not re-applied to those attributes. As a result, a user who can view a community-distributed event could retrieve attributes belonging to organisation-only objects (distribution level 0) or objects restricted to a specific sharing group, even though the user's organisation does not have access to those objects. This constitutes an unauthorized disclosure of sensitive threat intelligence data. A secondary issue was introduced by the initial remediation: the fix reused the full Object contain conditions (including soft-delete state) as the gate for flattened attributes, causing an event owner requesting deleted attributes to lose all attributes whose parent object was still live. The final fix isolates the distribution ACL condition as the sole gate. Preconditions: - An authenticated user with access to a community-distributed event - The event contains at least one object with a distribution level or sharing group that restricts access beyond the event's own distribution Impact: - Unauthorized disclosure of attributes belonging to restricted objects - Potential exposure of organisation-specific threat intelligence to other organisations Affected versions: <2.5.48