Export limit exceeded: 392967 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (392967 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-11926 | 1 Ibm | 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more | 2026-09-15 | 7.5 High |
| IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. | ||||
| CVE-2025-70820 | 2026-09-15 | 3.5 Low | ||
| Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder. | ||||
| CVE-2024-14029 | 1 Tornadoweb | 1 Tornado | 2026-09-15 | 7.5 High |
| Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization. | ||||
| CVE-2026-84653 | 2 Jenkins, Jenkins Project | 2 Jenkins, Jenkins | 2026-09-15 | 3.5 Low |
| Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to. | ||||
| CVE-2026-55770 | 1 Openbao | 1 Openbao | 2026-09-15 | 6.8 Medium |
| OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/ldaputil/client.go GetUserDN. With the LDAP authentication backend configured for an Active Directory UPNDomain path or UserDN and UserAttr binding, an attacker-controlled username containing filter metacharacters could alter the search predicate and select a different directory entry because EscapeLDAPValue does not neutralize the characters handled by ldap.EscapeFilter. A resulting token could be associated with another LDAP identity and gain access to secrets, policies, or modification capabilities assigned to that identity. This issue is fixed in version 2.5.5. | ||||
| CVE-2026-84655 | 2 Jenkins, Jenkins Project | 2 Jenkins, Jenkins | 2026-09-15 | 4.3 Medium |
| Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses. | ||||
| CVE-2026-84656 | 2 Jenkins, Jenkins Project | 2 Jenkins, Jenkins | 2026-09-15 | 4.3 Medium |
| A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they have no access to. | ||||
| CVE-2026-84555 | 1 Apple | 1 Macos | 2026-09-15 | 5.5 Medium |
| An authorization issue was addressed with improved access control. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8. An app may be able to access sensitive user data. | ||||
| CVE-2026-84657 | 2 Jenkins, Jenkins Project | 2 Jenkins, Jenkins | 2026-09-15 | 4.2 Medium |
| In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users. | ||||
| CVE-2026-18065 | 1 Ibm | 1 I | 2026-09-15 | 5.3 Medium |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information through session IP binding bypass in Navigator for i. | ||||
| CVE-2026-16435 | 1 Ibm | 1 Websphere Application Server | 2026-09-15 | 5.9 Medium |
| IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features. | ||||
| CVE-2026-16189 | 1 Ibm | 1 Websphere Application Server | 2026-09-15 | 4.8 Medium |
| IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log. | ||||
| CVE-2026-16190 | 1 Ibm | 1 Websphere Application Server | 2026-09-15 | 3.1 Low |
| IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability. | ||||
| CVE-2026-15955 | 1 Ibm | 1 Db2 | 2026-09-15 | 7.5 High |
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths. | ||||
| CVE-2026-19816 | 2 Packagekit, Redhat | 2 Packagekit, Enterprise Linux | 2026-09-15 | 7.1 High |
| A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend. | ||||
| CVE-2026-12765 | 1 Ibm | 1 Langflow Oss | 2026-09-15 | 6.5 Medium |
| IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | ||||
| CVE-2026-65405 | 1 Apple | 5 Ios And Ipados, Macos, Tvos and 2 more | 2026-09-15 | 5.5 Medium |
| A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to determine kernel memory layout. | ||||
| CVE-2026-19280 | 1 Ibm | 1 I | 2026-09-15 | 5.2 Medium |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process. | ||||
| CVE-2026-14276 | 1 Ibm | 1 I Access Family | 2026-09-15 | 6.3 Medium |
| IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a malicious emulator macro RunProgram action. | ||||
| CVE-2026-13275 | 1 Ibm | 1 Mq | 2026-09-15 | 7.1 High |
| IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 Managed File Transfer could allow an authenticated attacker to read arbitrary files or perform server-side request forgery due to XML external entity injection in reply message processing. | ||||