Export limit exceeded: 10227 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 398887 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (398887 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-92289 1 Lemonldap-ng 1 Portal 2026-09-28 9.1 Critical
Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret. With oidcRPMetaDataOptionsRequirePKCE set to 2, the authorization endpoint issues a code even when the request carries no code_challenge, and token() admits the exchange as long as a challenge was stored or an authentication method was returned for the caller. checkEndPointAuthenticationCredentials() skips the secret comparison for a Relying Party marked public and still returns the method deduced from the request, so any Basic or form credential satisfies the secret branch. validatePKCEChallenge() then passes, because neither a challenge nor a verifier is present. An attacker who intercepts an authorization code issued to a public Relying Party can exchange it for the user's access, ID and refresh tokens by replaying the client_id with an arbitrary secret, which is the attack PKCE prevents. Dynamic client registration creates every Relying Party in this mode.
CVE-2026-101041 1 Circl 1 Vulnerability-lookup 2026-09-28 N/A
The account recovery (password reset) functionality in the vulnerability-lookup web application contains a time-of-check-to-time-of-use (TOCTOU) race condition in the consumption of single-use recovery tokens. The original implementation verified the token nonce against the stored digest and then consumed (cleared) it in separate database operations. Two concurrent HTTP requests presenting the same valid recovery token could both pass the verification check before either transaction committed, allowing both to set their own password on the target account. The last transaction to commit overwrites the first, enabling an attacker who possesses a valid recovery token to replace the legitimate user's password with one of their choosing. A secondary defect in the same endpoint (confirm_account) allowed a valid recovery link to be used to set an empty or trivially short password (e.g., three characters). The view handler performed only a manual equality comparison between the two password fields and never invoked the form's validation logic, bypassing the intended minimum-length and complexity constraints. The affected component is the user account recovery endpoint (/user/confirm_account/<token>) and the associated token verification and consumption logic in the User model (website/models/user.py) and the view layer (website/web/views/user.py).
CVE-2026-89303 1 Wordpress-extensions 1 Post Voting System 2026-09-28 6.4 Medium
The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.
CVE-2026-93000 1 Wordpress-extensions 1 Sps-suite 2026-09-28 6.8 Medium
The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.
CVE-2026-89300 1 Wordpress-extensions 1 Wp Verify Api 2026-09-28 5.3 Medium
The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate limited either.
CVE-2026-84744 1 Wordpress-extensions 1 Wpforms Lite 2026-09-28 6.5 Medium
The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts.
CVE-2026-86838 1 Wordpress-extensions 1 Bookly 2026-09-28 5.3 Medium
The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step.
CVE-2026-82969 1 Bimser Solution Software 1 Eba Plus Document And Workflow Management System 2026-09-28 5.4 Medium
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Stored XSS. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.
CVE-2026-85134 1 Bimser Solution Software 1 Eba Plus Document And Workflow Management System 2026-09-28 8.8 High
Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Upload a Web Shell to a Web Server. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.
CVE-2026-82915 1 Bimser Solution Software 1 Eba Plus Document And Workflow Management System 2026-09-28 6.5 Medium
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Path Traversal. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.
CVE-2026-87752 1 Rolantis Information Technologies 1 Agentis 2026-09-28 6.1 Medium
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Rolantis Information Technologies Tourism Industry and Trade Co. Ltd. Agentis allows XSS Targeting HTML Attributes. This issue affects Agentis: from 4.44 before 4.6.
CVE-2026-18825 1 Antono 1 Connect-cors 2026-09-28 N/A
An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verification and perform a cross domain authenticated request.
CVE-2026-82326 1 Enocta Educational 1 Enocta Platform 2026-09-28 4.1 Medium
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows XSS Targeting HTML Attributes. This issue affects Enocta Platform: through 2026-09-28.
CVE-2026-86595 1 Iron Mountain Archiving Services Inc. 1 Envision 2026-09-28 8.8 High
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue affects enVision: before 260655.
CVE-2026-80359 1 Dell 1 Boot Optimized Server Storage (boss) 2026-09-28 6.8 Medium
Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.
CVE-2026-101333 1 Redhat 4 Build Keycloak, Build Of Keycloak, Red Hat Single Sign On and 1 more 2026-09-28 3.7 Low
A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker can send requests to the identity broker login endpoint using arbitrary provider aliases, causing the system to create an unlimited number of metric time series. This can lead to excessive memory consumption and degrade the performance of both the server and its monitoring tools.
CVE-2026-96538 1 Enterprisedb 1 Warehousepg 2026-09-28 N/A
WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are executable by any authenticated database role with no GRANT required, because the REVOKE that contrib/adminpack applies to the equivalent functions was never carried over to WHPG core when their catalog entries were repointed to the ungated adminpack-derived implementations as part of Greenplum's merge to a PostgreSQL 12 base. A non-superuser can use pg_file_write, pg_file_rename, and pg_file_unlink to create, overwrite (append), rename, and delete files under the data and log directories, and can use pg_logdir_ls() to enumerate log file names. Because postgresql.auto.conf resides in the data directory, a non-superuser can append configuration directives such as shared_preload_libraries or archive_command to it, resulting in arbitrary code execution as the postgres operating system user on the next server restart or configuration reload. WarehousePG 6.x is not affected, as the equivalent functions there enforce a superuser check internally.
CVE-2026-93348 1 Unslothai 2 Unsloth, Unsloth-zoo 2026-09-28 8.1 High
Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code injection vulnerability in the model-loading compile path where the get_transformers_model_type() function in hf_utils.py collects model_type values from nested model configurations without enforcing a character allowlist, allowing newlines and arbitrary Python source to survive normalization. Attackers can embed a newline in a nested model_type value within a malicious model's config.json to terminate the generated import statement and execute arbitrary Python code via exec() in unsloth_compile_transformers(), achieving remote code execution as the loading user when the model is loaded for training or inference.
CVE-2026-48100 1 Polybase 1 Payy 2026-09-28 N/A
Payy is an Ethereum L2 zk-rollup for privacy preserving and regulatory compliant transactions. Prior to version 1.3.0, agg_agg forwards the compacted message stream from its inner proofs into a public messages: [Field; 1000] array, but it never checks that the unused tail of the outer array is zero. A registered prover can build a valid agg_final proof for an approved rollup block while inserting an extra burn message after the real messages. RollupV1.verifyRollup() then parses that public input as a normal burn and transfers USDC from the rollup contract to the attacker. This is a severe circuit soundness failure: the proof system accepts a public statement whose messages array is not fully derived from the verified inner proofs. On the current deployment, verifyRollup() is restricted to the existing allowlisted prover, so a fresh public caller cannot submit the invalid proof directly. That gate limits who can reach L1 today; it does not make the circuit statement sound. The issue becomes permissionless under the prover model described in the Payy whitepaper. Section 3.3.2 states: "To join as a prover, the prover is required to submit a small stake", and Section 3.3.1 states that if a prover fails to submit, "other nodes can submit the block proof instead." In that model, an attacker only needs to become a registered prover and use public validator approval data for an already approved block. This issue has been patched in version 1.3.0.
CVE-2026-101910 1 Beaugunderson 1 Ip-address 2026-09-28 N/A
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, the Address6 isPrivate classifier in src/ipv6.ts does not recognize the NAT64 local-use range 64:ff9b:1::/48. Applications that combine isPrivate, isLoopback, and isLinkLocal for a trust-boundary decision can treat an internal IPv4 destination encoded through that range as external. Exploitation depends on a server network using an operator-selected NAT64 prefix within the local-use range. A successful bypass can cross the intended network trust boundary. This issue is fixed in version 10.5.1.