Export limit exceeded: 400423 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400423 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100574 | 1 Openclaw | 1 Openclaw | 2026-09-29 | 5.9 Medium |
| OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-host DNS checks. For fetches that use the trusted-host DNS recheck, a trusted hostname that resolves to an unspecified address (0.0.0.0 or ::) bypasses the SSRF destination validation. An attacker who can influence DNS for an allowed hostname can therefore cause a guarded fetch to reach a service bound only to loopback and disclose its response; the practical impact depends on the reachable service and the data it returns. Fixed in 2026.8.1. | ||||
| CVE-2026-100570 | 1 Openclaw | 1 Openclaw | 2026-09-29 | 7.8 High |
| OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an operator starts OpenClaw in attacker-controlled workspace content and then runs the Gmail setup flow, that value is inherited when gcloud is launched, and the gcloud launcher passes it as arguments to the trusted Python interpreter. A crafted CLOUDSDK_PYTHON_ARGS value can therefore cause Python to execute attacker-supplied code with the OpenClaw host user's permissions, allowing credentials to be read, files to be modified, or other processes to be started. This issue is fixed in version 2026.8.1; as a workaround, run Gmail setup only from trusted workspaces and clear inherited CLOUDSDK_* variables beforehand. | ||||
| CVE-2026-100566 | 1 Openclaw | 1 Line | 2026-09-29 | 6.5 Medium |
| OpenClaw LINE versions before 2026.8.1 contain an access control vulnerability where group allowlist mode silently inherits DM allowFrom values when groupAllowFrom is not explicitly configured. Attackers with group participation can trigger the agent despite configured group allowlist restrictions when DM access is broader than intended group access. | ||||
| CVE-2026-100561 | 1 Openclaw | 1 Openclaw | 2026-09-29 | 8 High |
| OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After an operator allowlisted or permanently approved a benign wrapper invocation, a later agent turn could substitute an arbitrary inner command and execute it with the OpenClaw process's host privileges without a further approval prompt. Exploitation requires the relevant wrapper to resolve on the host and a prior operator decision allowing that wrapper. Transparent shell carriers and opaque utilities such as process monitors, tracers, namespace tools, and proxy wrappers were affected through related trust-resolution gaps. Fixed in 2026.8.1. | ||||
| CVE-2026-96418 | 1 Wireshark | 1 Wireshark | 2026-09-29 | 5.5 Medium |
| TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-96417 | 1 Wireshark | 1 Wireshark | 2026-09-29 | 5.5 Medium |
| RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-95394 | 1 Wireshark | 1 Wireshark | 2026-09-29 | 4.7 Medium |
| Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-101266 | 1 Pretix | 1 Pretix | 2026-09-29 | N/A |
| A logic flaw in the checkout flow allows users to bypass validations performed during the check-in by skipping entire check-in steps. | ||||
| CVE-2026-101267 | 1 Pretix | 1 Pretix | 2026-09-29 | N/A |
| A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue. | ||||
| CVE-2026-101268 | 1 Pretix | 1 Pretix | 2026-09-29 | N/A |
| If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account. If the victim does not notice this, this might lead to their order details being stored into the attacker's account. The attack only works when the event is available on a different domain than the organizer page. | ||||
| CVE-2026-101269 | 1 Pretix | 1 Pretix | 2026-09-29 | N/A |
| The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users. Since API-uploaded files are refered to by randomly generated UUIDs and only exist for a day, there is virtually no risk, but it renders the added protection mechanism useless. | ||||
| CVE-2026-101270 | 1 Pretix | 1 Pretix | 2026-09-29 | N/A |
| Malicious HTML content could be injected into the help texts of various fields with organizer permissions. | ||||
| CVE-2026-101271 | 1 Pretix | 1 Pretix | 2026-09-29 | N/A |
| OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled. | ||||
| CVE-2026-93402 | 1 Rsyslog | 1 Rsyslog | 2026-09-29 | 3.1 Low |
| A flaw was found in rsyslog. When using the imdtls input module configured for name or fingerprint authentication, permitted-peer identity checks are not enforced after a successful DTLS handshake. A remote attacker possessing a valid certificate signed by the listener's trusted Certificate Authority could bypass peer restrictions and inject unauthorized syslog records into the input stream. | ||||
| CVE-2026-65129 | 2 Linux, Nvidia | 3 Linux Kernel, Infra Controller, Infrastructure Controller | 2026-09-29 | 6.7 Medium |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service. | ||||
| CVE-2026-100748 | 1 Svenbluege.de | 1 Event Gallery For Joomla | 2026-09-29 | N/A |
| Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0 | ||||
| CVE-2026-97164 | 1 Svenbluege.de | 1 Event Gallery For Joomla | 2026-09-29 | N/A |
| Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extension < 6.5.0 - Using the `images` parameter of the `cache.process` task, you can recursively delete any directories that the web server is authorized to write to. | ||||
| CVE-2026-67364 | 1 Balbooa.com | 1 Balbooa.com Balbooa Forms Extension For Joomla | 2026-09-29 | N/A |
| Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting an unauthenticated attacker inject arbitrary PHP that executes server-side. The CSRF token needed to reach the endpoint is itself disclosed anonymously via a separate task, so it provides no real protection. Exploitability requires the form to have a custom-PHP handler configured (a documented builder feature) referencing that shortcode, and no reCAPTCHA on the submit button. | ||||
| CVE-2026-88022 | 1 Mongodb | 2 Laravel Mongodb, Laravel Mongodb (php) | 2026-09-29 | 7.7 High |
| Improper neutralization of special elements in data query logic in the MongoDB integration for Laravel can cause an array supplied to an explicit equality filter to be interpreted as a query condition rather than as a literal value. This affects the three-argument `where` method when the operator is `=` or `eq`, as well as the `find` and `delete` methods that use that code path. An attacker who can cause an affected application to supply an operator-shaped array to one of these APIs may obtain a document other than the intended target or delete documents beyond the intended target. | ||||
| CVE-2026-63498 | 2 Grokability, Snipeitapp | 2 Snipe-it, Snipe-it | 2026-09-29 | 8.7 High |
| Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML and XSLT attachments and request them with the inline=true parameter. The app/Http/Controllers/Api/UploadedFilesController.php show() path does not apply the safe-inline allowlist used by the equivalent web controller, so the browser can process an attacker-controlled xml-stylesheet reference and execute JavaScript generated by the stylesheet in the Snipe-IT origin. A victim who is authorized to view the object must open the attachment URL, after which the script can read same-origin data and perform authenticated actions with the victim's privileges. This issue is fixed in version 8.7.0. | ||||