Export limit exceeded: 399985 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399985 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-71899 | 1 Apache | 1 Dolphinscheduler | 2026-09-29 | N/A |
| A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows being queried. An authenticated user who does not have permission to access a specific project can invoke the API with parameters referencing workflows belonging to that project and retrieve workflow information. This allows users to access workflow data outside their authorized project scope, resulting in unauthorized information disclosure. This issue affects Apache DolphinScheduler: from 3.2.0 before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue. | ||||
| CVE-2026-71897 | 1 Apache | 1 Dolphinscheduler | 2026-09-29 | 4.3 Medium |
| An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects. This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue. | ||||
| CVE-2026-61744 | 1 Inventree | 1 Inventree | 2026-09-29 | 6.5 Medium |
| InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesized internal JSON barcode containing a lowercase model label and integer primary key, while BarcodeView uses IsAuthenticatedOrReadScope and requires only authentication or a general read scope. The built-in barcode plugin selects the object with model.objects.get(pk=...), and InvenTreeBarcodeMixin.format_matched_response() returns the complete model serializer output as instance without checking the caller's per-model view role. A low-privilege user can enumerate primary keys for parts, stock, locations, supplier and manufacturer parts, orders, and builds to disclose commercially sensitive inventory, pricing, supplier, customer, and order data. This issue is fixed in version 1.4.0. | ||||
| CVE-2026-58504 | 1 Jgraph | 1 Drawio | 2026-09-29 | 6.1 Medium |
| draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.5, opening or importing a crafted .drawio file can execute attacker-controlled JavaScript in the draw.io origin when selected cells are processed by TextFormatPanel.addFont() in src/main/webapp/js/grapheditor/Format.js. An HTML sibling cell keeps the formatted-label path enabled while an editable=0 plain-text sibling is excluded from the merged selection style but remains in the iteration set. graph.cellRenderer.getLabelValue() returns that plain-text label without HTML encoding, and mxUtils.canConvertHtmlToSvg() parses it as HTML, bypassing the earlier CVE-2026-46642 remediation. Successful exploitation can expose diagram data, browser storage, non-HttpOnly cookies, and same-origin actions available to the victim. This issue is fixed in version 30.2.5. | ||||
| CVE-2026-54710 | 1 Freepbx | 1 Security-reporting | 2026-09-29 | N/A |
| FreePBX is an open source IP PBX. Prior to versions 16.0.40 and 17.0.7, a critical remote code execution (RCE) vulnerability exists in the superfecta module due to unsafe inclusion of arbitrary PHP files, allowing authenticated attackers to execute arbitrary PHP code on the server with the privileges of the web server user. Authentication with a known username is required. The vulnerability is rooted in the options and save_options cases in the Superfecta module's AJAX handler. The code dynamically includes PHP files from the sources/ directory based on user-supplied input. This allows an attacker to execute arbitrary code when combined with arbitrary directory creation (e.g., via the backup module) and file uploads that reveal full paths (e.g., via the soundlang module). This issue has been patched in versions 16.0.40 and 17.0.7. | ||||
| CVE-2026-54708 | 1 Freepbx | 1 Security-reporting | 2026-09-29 | N/A |
| FreePBX is an open source IP PBX. Prior to versions 16.0.72 and 17.0.7, a critical vulnerability exists in the FreePBX backup Module that allows authenticated attackers to execute arbitrary code on the server. Authentication with a known username that has sufficient access permissions and/or write access to backup files is required. This vulnerability is caused by improper path sanitization in the backup restore functionality, enabling attackers to upload malicious PHP files to the web root directory. This issue has been patched in versions 16.0.72 and 17.0.7. | ||||
| CVE-2026-51996 | 1 Geelen | 1 Mcp-remote | 2026-09-29 | 9.8 Critical |
| An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function | ||||
| CVE-2026-51772 | 1 Openstack | 1 Glance | 2026-09-29 | 8.1 High |
| A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance. When the show_multiple_locations configuration option is enabled in glance-api.conf, an authenticated attacker can manipulate the locations attribute of an image in the queued state by sending a crafted HTTP PATCH request | ||||
| CVE-2026-102598 | 2026-09-29 | 5.3 Medium | ||
| Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without first removing an empty NTFS ADS marker. The trigger is that an application runs on Windows with NTFS and serves a user-specified path ending in a special device name such as NUL:. The attack mechanism is that a requested path ends in a Windows special device name with an empty ADS marker. The impact is that the special device opens successfully and the file read hangs indefinitely. This issue is fixed in version 3.1.9. | ||||
| CVE-2026-102004 | 1 Windriver | 1 Vxworks | 2026-09-29 | 7.8 High |
| Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption within the memory management subsystem. Fixed in Version 26.09 | ||||
| CVE-2026-101041 | 1 Circl | 1 Vulnerability-lookup | 2026-09-29 | N/A |
| The account recovery (password reset) functionality in the vulnerability-lookup web application contains a time-of-check-to-time-of-use (TOCTOU) race condition in the consumption of single-use recovery tokens. The original implementation verified the token nonce against the stored digest and then consumed (cleared) it in separate database operations. Two concurrent HTTP requests presenting the same valid recovery token could both pass the verification check before either transaction committed, allowing both to set their own password on the target account. The last transaction to commit overwrites the first, enabling an attacker who possesses a valid recovery token to replace the legitimate user's password with one of their choosing. A secondary defect in the same endpoint (confirm_account) allowed a valid recovery link to be used to set an empty or trivially short password (e.g., three characters). The view handler performed only a manual equality comparison between the two password fields and never invoked the form's validation logic, bypassing the intended minimum-length and complexity constraints. The affected component is the user account recovery endpoint (/user/confirm_account/<token>) and the associated token verification and consumption logic in the User model (website/models/user.py) and the view layer (website/web/views/user.py). | ||||
| CVE-2026-88027 | 1 Mongodb | 2 Laravel Mongodb, Laravel Mongodb (php) | 2026-09-29 | 7.1 High |
| Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded record identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence such an identifier may delete all embedded documents in a targeted record or overwrite an embedded document other than the intended target. | ||||
| CVE-2026-100238 | 2026-09-29 | N/A | ||
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Flow Extension allows Stored XSS. This issue affects Mediawiki - Flow Extension: from * before 1.46.1, 1.45.5, 1.43.10. | ||||
| CVE-2026-102557 | 1 Redhat | 1 Enterprise Linux | 2026-09-29 | 8.6 High |
| A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total message size against the limits of the underlying buffer type. A remote peer could send fragments that caused size truncation while the implementation still used the full length, leading to heap corruption or a crash. | ||||
| CVE-2026-88028 | 1 Mongodb | 2 Laravel Mongodb, Laravel Mongodb (php) | 2026-09-29 | 6.5 Medium |
| Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel can cause a caller-supplied relation identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence a stored relation identifier may cause an affected application to return a document other than the intended relation target. | ||||
| CVE-2026-68881 | 1 Microsoft | 20 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 17 more | 2026-09-29 | 5.5 Medium |
| Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-88029 | 1 Mongodb | 1 Python Driver | 2026-09-29 | 8.3 High |
| Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. The affected rename operation may also rename a stored file other than the intended target. | ||||
| CVE-2026-68885 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-29 | 7.8 High |
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-88030 | 1 Mongodb | 1 Ruby Driver | 2026-09-29 | 8.3 High |
| Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. | ||||
| CVE-2026-87902 | 1 Wordpress | 1 Wordpress | 2026-09-29 | 8.1 High |
| An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE. | ||||