Export limit exceeded: 400860 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400860 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100771 | 1 Mozilla | 1 Firefox | 2026-10-01 | 8.1 High |
| Undefined behavior in the DOM: Streams component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | ||||
| CVE-2026-100788 | 1 Mozilla | 1 Firefox | 2026-10-01 | 9.8 Critical |
| Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17. | ||||
| CVE-2026-100792 | 1 Mozilla | 1 Firefox | 2026-10-01 | 7.1 High |
| JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17. | ||||
| CVE-2026-100794 | 1 Mozilla | 1 Firefox | 2026-10-01 | 9.6 Critical |
| Sandbox escape due to incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17. | ||||
| CVE-2026-17053 | 1 Zephyrproject | 1 Zephyr | 2026-10-01 | 4.4 Medium |
| The SMBus driver API exposed smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb() as Zephyr syscalls. Their verifiers in drivers/smbus/smbus_handlers.c validated only the dev argument with K_SYSCALL_OBJ(dev, K_OBJ_DRIVER_SMBUS) and forwarded the caller-supplied struct smbus_callback *cb pointer into kernel-mode driver code without any K_SYSCALL_MEMORY_READ/K_SYSCALL_MEMORY_WRITE validation. A companion change in 2023 had already removed the matching smbus_smbalert_set_cb() / smbus_host_notify_set_cb() syscalls for this reason, but the two removal syscalls were left exposed. On a build with CONFIG_USERSPACE=y, CONFIG_SMBUS=y and a driver implementing the callback operations (drivers/smbus/intel_pch_smbus.c with CONFIG_SMBUS_INTEL_PCH_SMBALERT/CONFIG_SMBUS_INTEL_PCH_HOST_NOTIFY, or drivers/smbus/smbus_stm32.c with CONFIG_SMBUS_STM32_SMBALERT), any user-mode thread that has been granted the SMBus device object can invoke these syscalls with an arbitrary pointer. The value reaches smbus_callback_remove() in drivers/smbus/smbus_utils.h, which uses it as a node identity against the kernel's sys_slist_t of registered callbacks. The consequence is that an unprivileged thread can unregister an SMBALERT or Host Notify callback that a supervisor-mode component registered, silently disabling alert handling for the rest of the system; because Zephyr images have fixed symbol addresses and the syscall returns 0 on a hit versus -ENOENT on a miss, the target address is both derivable and searchable. In builds with CONFIG_ASSERT=y the __ASSERT(callback->handler, ...) check additionally dereferences the caller-supplied address in supervisor mode, so a bogus pointer raises a kernel-mode fault and a fatal system error, and the fault/no-fault outcome discloses which addresses are mapped. The fix removes both syscall entry points, demoting the two functions to ordinary static inline calls so that callback list manipulation is available only to supervisor-mode code. There is no impact on builds without CONFIG_USERSPACE, and no impact on configurations that do not enable an SMBus driver with SMBALERT or Host Notify support. | ||||
| CVE-2026-103004 | 1 Vercel | 1 Next.js | 2026-10-01 | 3.7 Low |
| Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params. With Cache Components enabled (cacheComponents: true), a 'use cache' function that calls another 'use cache' function that reads a root param can be keyed incorrectly when the inner call is served from an existing entry: the enclosing function's cache key then omits that root param. The enclosing entry is written once and reused for all root param values, so a response for one root param value can serve content produced for a different value — whether the page is prerendered at build time or at runtime, or rendered dynamically. Shared cache headers let downstream caches redistribute the content further. What values are leaked cannot be attacker controlled. Which value's content is served depends only on which invocation wrote the entry first. This has been patched in 16.3.8. | ||||
| CVE-2026-95295 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-10-01 | 4.6 Medium |
| Information leak in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a local attacker to leak sensitive information via physical access. (Chromium security severity: Medium) | ||||
| CVE-2026-95330 | 1 Google | 1 Chrome | 2026-10-01 | 6.5 Medium |
| Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-95358 | 1 Google | 2 Android, Chrome | 2026-10-01 | 4.4 Medium |
| Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access restrictions into a privileged page via a co-installed app. (Chromium security severity: Medium) | ||||
| CVE-2026-102299 | 1 Google | 1 Chrome | 2026-10-01 | 8.8 High |
| Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-102300 | 1 Google | 1 Chrome | 2026-10-01 | 4.3 Medium |
| Uninitialized resource in WebGPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-102301 | 1 Google | 1 Chrome | 2026-10-01 | 8.3 High |
| Out of bounds write in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-102302 | 1 Google | 1 Chrome | 2026-10-01 | 8.8 High |
| Buffer overflow in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-97297 | 2026-10-01 | 7.6 High | ||
| Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions. | ||||
| CVE-2026-83589 | 2 Oauth2 Proxy Project, Redhat | 2 Oauth2 Proxy, Openshift | 2026-10-01 | 6.1 Medium |
| A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft. | ||||
| CVE-2026-51568 | 1 Agentscope-ai | 1 Agentscope | 2026-10-01 | 8.1 High |
| modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file. | ||||
| CVE-2026-12256 | 2 Theme-fusion, Wordpress | 2 Avada, Wordpress | 2026-10-01 | 8.8 High |
| Deserialization of Untrusted Data vulnerability in ThemeFusion Fusion Builder fusion-builder allows Object Injection.This issue affects Fusion Builder: from n/a through 3.15.3. | ||||
| CVE-2026-103690 | 1 Itsourcecode | 1 Leave Management System | 2026-10-01 | 6.3 Medium |
| A flaw has been found in itsourcecode Leave Management System 1.0. This vulnerability affects unknown code of the file /module/leave/controller.php. Executing a manipulation of the argument LEAVEID can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. | ||||
| CVE-2026-103267 | 1 Ghost | 1 Ghost | 2026-10-01 | 4.3 Medium |
| Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that allows users to specify any email address when creating their account. Attackers can accept leaked invite tokens with attacker-controlled email addresses, or legitimate recipients can register with unintended email providers. | ||||
| CVE-2026-103068 | 2026-10-01 | 8.8 High | ||
| Subscriber Privilege Escalation in ByteCoreStack – MCP Connector for AI Tools <= 1.2.2 versions. | ||||