Export limit exceeded: 400494 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400494 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400494 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65125 | 2 Linux, Nvidia | 3 Linux Kernel, Infra Controller, Infrastructure Controller | 2026-09-29 | 6.6 Medium |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service. | ||||
| CVE-2026-65126 | 2 Linux, Nvidia | 3 Linux Kernel, Infra Controller, Infrastructure Controller | 2026-09-29 | 5 Medium |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-57443 | 1 Issdandavis | 1 Scbe-aethermoore | 2026-09-29 | 7.5 High |
| SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the `POST /api/ops/check-email` endpoint without any authentication. Any remote attacker can call this endpoint and trigger execution of the `email_reader.py` subprocess, which connects to configured ProtonMail or Gmail accounts via IMAP and returns email metadata (sender, subject, body snippet) in the JSON response. The server binds to `0.0.0.0:8100` by default with CORS set to `allow_origins=["*"]`, making it reachable from any network or browser origin. Version 4.2.1 patches the issue. | ||||
| CVE-2026-102807 | 1 Openclaw | 1 Openclaw | 2026-09-29 | 5.3 Medium |
| OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped operators to execute MCP App tools requiring operator.write scope. Attackers with operator.read tokens can obtain a standalone ticket from mcp.app.view and redeem it at the MCP app view endpoint to invoke state-changing tools without proper authorization checks. | ||||
| CVE-2026-102697 | 1 Ollama | 1 Ollama | 2026-09-29 | 7.8 High |
| Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell syntax. Attackers who can influence model output through prompt injection can execute additional shell commands by appending control operators like semicolons or logical operators to approved commands, bypassing the session approval requirement. | ||||
| CVE-2026-102634 | 1 Lmsys | 1 Sglang | 2026-09-29 | 7.5 High |
| SGLang through 0.5.20 in prefill/decode disaggregation mode fails to validate duplicate bootstrap_room fields in /generate requests with Mooncake KV transfer backend. Unauthenticated attackers can send concurrent requests with identical bootstrap_room values to crash scheduler processes or hang other users' requests until transfer timeout. | ||||
| CVE-2026-102367 | 1 Gz-yami | 1 Mall4j | 2026-09-29 | 5.4 Medium |
| mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to validate the enabled flag when issuing new sessions. Disabled user accounts can indefinitely renew their sessions through the POST /token/refresh endpoint, retaining access that account disabling was intended to remove. | ||||
| CVE-2026-102364 | 1 Gz-yami | 1 Mall4j | 2026-09-29 | 5.4 Medium |
| mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office users by reusing their session tokens. Attackers can register on the public storefront and use their customer session token to access admin endpoints lacking @PreAuthorize permission checks, including menu listings, file uploads, and configuration endpoints. | ||||
| CVE-2026-102363 | 1 Gz-yami | 1 Mall4j | 2026-09-29 | 3.7 Low |
| mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an order number parameter. Attackers can access carrier names, waybill numbers, and complete logistics trails for any order without authentication or ownership verification. | ||||
| CVE-2026-102297 | 1 Zoneminder | 1 Zoneminder | 2026-09-29 | 4.3 Medium |
| ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API to list frame records from monitors they are denied access to, disclosing event and frame metadata across monitor boundaries. | ||||
| CVE-2026-102244 | 1 Modsetter | 1 Surfsense | 2026-09-29 | 4.3 Medium |
| A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown function of the file surfsense_backend/app/routes/editor_routes.py of the component Document Export Feature. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.0.36.3 is recommended to address this issue. The patch is named 2faff7b3823322a9cb6797973e6caf089386c354. The affected component should be upgraded. | ||||
| CVE-2026-102240 | 1 Netcore | 1 Nap930 | 2026-09-29 | 10 Critical |
| A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-101858 | 1 Raspap | 1 Raspap-webgui | 2026-09-29 | 4.7 Medium |
| A flaw has been found in RaspAP raspap-webgui up to 3.5.5. Affected is the function WiFiManager::writeWpaSupplicant of the file src/RaspAP/Networking/Hotspot/WiFiManager.php of the component SSID Processing. This manipulation of the argument ssid causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-101280 | 1 Trusted Domain Project | 1 Opendmarc | 2026-09-29 | 7.3 High |
| A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-101277 | 1 Trusted Domain Project | 1 Opendkim | 2026-09-29 | 6.5 Medium |
| A security flaw has been discovered in Trusted Domain Project OpenDKIM up to 2.11.0. The impacted element is the function dkim_process_set of the file dkim.c of the component Tag Tokenizer. Performing a manipulation results in use of less trusted source. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2022-51019 | 1 Akaunting | 1 Akaunting | 2026-09-29 | 8.8 High |
| Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation and update flow where the alias parameter is passed unvalidated to shell command execution. Authenticated users with admin panel access can inject shell metacharacters into the alias parameter to execute arbitrary commands on the server. | ||||
| CVE-2026-65127 | 2 Linux, Nvidia | 3 Linux Kernel, Infra Controller, Infrastructure Controller | 2026-09-29 | 4.1 Medium |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive system information due to uncleared debug information. A successful exploit of this vulnerability might lead to information disclosure. | ||||
| CVE-2026-65128 | 2 Linux, Nvidia | 3 Linux Kernel, Infra Controller, Infrastructure Controller | 2026-09-29 | 8.8 High |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-63006 | 1 Zammad | 1 Zammad | 2026-09-29 | N/A |
| Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, attacker-controlled HTML in inbound emails or tickets could bypass the image URL sanitizer using path traversal sequences. When an authenticated agent views the content, the browser resolves the URL to a protected API endpoint and sends the request with the agent's session cookie, enabling side effects such as forced logout without any user interaction. This issue is fixed in version 7.1.2. | ||||
| CVE-2026-101091 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2026-09-29 | 7.1 High |
| SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with non-read-only SQL statements that execute automatically during background indexing, rendering, or export operations without authentication. | ||||