Export limit exceeded: 390637 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (390637 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-49309 | 1 Huawei | 2 Emui, Harmonyos | 2026-09-10 | 4.8 Medium |
| Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||||
| CVE-2026-21108 | 1 Samsung Mobile | 1 Bixby | 2026-09-10 | N/A |
| Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information. | ||||
| CVE-2026-81021 | 2 Supportcandy, Wordpress | 2 Supportcandy, Wordpress | 2026-09-10 | 5.3 Medium |
| The SupportCandy WordPress plugin before 3.5.3 does not perform an authorization check on one of its support-ticket attachment download paths, allowing unauthenticated attackers to read protected customer-uploaded attachments by enumerating sequential attachment identifiers. | ||||
| CVE-2026-84222 | 2 Kirki, Wordpress | 2 Kirki, Wordpress | 2026-09-10 | 5.3 Medium |
| The Kirki WordPress plugin before 6.3.0 does not check whether the requester is allowed to read a post before rendering and returning its page content, allowing unauthenticated users to retrieve the content of pages that are not publicly available, such as private, draft, pending and trashed ones. | ||||
| CVE-2026-85117 | 2 Contact Form 7 Captcha Project, Wordpress | 2 Contact Form 7 Captcha, Wordpress | 2026-09-10 | 6.5 Medium |
| The Contact Form 7 Captcha WordPress plugin before 0.1.9 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. | ||||
| CVE-2026-79696 | 1 Google Cloud | 1 Agent Development Kit (adk) | 2026-09-10 | N/A |
| A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay. | ||||
| CVE-2026-9327 | 1 Ibm | 1 Websphere Application Server | 2026-09-10 | 6.3 Medium |
| IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service. | ||||
| CVE-2026-41869 | 1 Apache | 1 Nutch | 2026-09-10 | 9.1 Critical |
| Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are recommended to upgrade to version 1.23, which removes the Nutch Server. If an upgrade is not possible, user must restrict access to instances running the Nutch Service to trusted users only. Please, also visit the Apache Nutch security advisories https://nutch.apache.org/documentation/security/ . | ||||
| CVE-2026-84968 | 1 Mongodb | 1 Php Driver | 2026-09-10 | 5.3 Medium |
| An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is returned to application code. This may result in unintended disclosure of limited memory contents. | ||||
| CVE-2026-8862 | 1 Ibm | 2 Netezza Performance Server, Netezza Software | 2026-09-10 | 7.5 High |
| IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing proprietary code, configuration details, and other sensitive information. | ||||
| CVE-2026-41871 | 1 Apache | 1 Nutch | 2026-09-10 | 9.8 Critical |
| Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are recommended to upgrade to version 1.23, which removes the Nutch Server. If an upgrade is not possible, user must restrict access to instances running the Nutch Service to trusted users only. Please, also visit the Apache Nutch security advisories https://nutch.apache.org/documentation/security/ . | ||||
| CVE-2026-54048 | 1 Apache | 1 Impala | 2026-09-10 | 5.3 Medium |
| Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages. Users are recommended to upgrade to version 4.5.2, which fixes this issue. | ||||
| CVE-2026-9036 | 1 Ibm | 2 Netezza Performance Server, Netezza Software | 2026-09-10 | 5.9 Medium |
| IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques. | ||||
| CVE-2026-56207 | 1 Apache | 1 Impala | 2026-09-10 | 9.8 Critical |
| Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommended to upgrade to version 4.5.2, which fixes this issue. | ||||
| CVE-2026-57866 | 1 Apache | 1 Impala | 2026-09-10 | 8.8 High |
| Server side request forgery in Apache Impala versions 4.4.x and 4.5.x. Authenticated Impala users with permissions to execute the ai_generate_text() function can exfiltrate secrets provided by the credential providers configured in the `hadoop.security.credential.provider.path` property of `core-site.xml`. The secret's key must be known to the user. | ||||
| CVE-2026-65181 | 1 Apache | 1 Impala | 2026-09-10 | 8.1 High |
| Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code. Users are recommended to upgrade to version 4.5.2, which fixes this issue. | ||||
| CVE-2026-9736 | 1 Ibm | 2 Netezza Performance Server, Netezza Software | 2026-09-10 | 5.3 Medium |
| IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files. | ||||
| CVE-2026-9744 | 1 Ibm | 2 Netezza Performance Server, Netezza Software | 2026-09-10 | 5.3 Medium |
| IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques. | ||||
| CVE-2026-28642 | 1 Google | 1 Android | 2026-09-10 | 7.8 High |
| In executeRequest of ActivityStarter.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-87807 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2026-09-10 | 7.5 High |
| siyuan versions before v3.8.2 contain an authenticated SQL injection vulnerability in the fullTextSearchBlock endpoint's method=1 query parameter. Attackers can inject UNION SELECT statements to read the entire blocks table, bypassing publish-access controls and exposing all document content and sensitive attributes. | ||||