Export limit exceeded: 382357 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (382357 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-18828 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-25 | 5.4 Medium |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow. | ||||
| CVE-2026-79655 | 1 Redhat | 1 Enterprise Linux | 2026-08-25 | 7.8 High |
| A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By crafting a malicious tar archive, an attacker can exploit a path traversal issue during tar extraction, where symlink and hardlink targets are not properly validated. This enables the attacker to write files to arbitrary locations on the system with the privileges of the sos clean process, which often runs as root. | ||||
| CVE-2026-18822 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-25 | 4.4 Medium |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to uncontrolled resource consumption when parsing directory records. | ||||
| CVE-2026-18716 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-25 | 7.9 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read. | ||||
| CVE-2026-18670 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-25 | 8.2 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service and potentially disclose sensitive information due to an integer underflow. | ||||
| CVE-2026-17436 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-25 | 8.8 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow. | ||||
| CVE-2026-17425 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-25 | 7.5 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack buffer overflow. | ||||
| CVE-2026-17424 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-25 | 4.8 Medium |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restrictions due to improper limitation of a pathname to a restricted directory. | ||||
| CVE-2026-17423 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-25 | 7.7 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds read. | ||||
| CVE-2026-17422 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-25 | 9.3 Critical |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow. | ||||
| CVE-2026-17195 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-25 | 6.5 Medium |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of-bounds write. | ||||
| CVE-2026-79662 | 2 Ech0, Lin-snow | 2 Ech0, Ech0 | 2026-08-25 | 8 High |
| Ech0 through 4.5.6 contains an OAuth redirect URI validation vulnerability in parseAndValidateClientRedirect (internal/service/auth/auth.go) that compares only the scheme and host of the client-supplied redirect_uri against the admin-configured allowlist, ignoring path, query, and fragment components. The redirect_uri is embedded into the signed state JWT at login time without validation. An attacker can craft a redirect_uri whose host matches an allowed origin but whose path is attacker-influenced; after the OAuth exchange the victim is redirected to that path with a one-time exchange code in the query string. If the code leaks (e.g., via Referer, analytics, or an open redirect on that host), the attacker can trade it at the public POST /api/auth/exchange endpoint for the victim's access and refresh tokens. Fixed in 4.7.3. | ||||
| CVE-2026-79663 | 2 Ech0, Lin-snow | 2 Ech0, Ech0 | 2026-08-25 | 4.8 Medium |
| Ech0 before 4.7.3 contains a stored cross-site scripting vulnerability in the public RSS feed where tag names and markdown content are rendered without HTML escaping. Attackers with admin privileges can inject malicious tag names or raw HTML in echo content that executes as JavaScript in RSS readers that render HTML-type summaries, affecting anonymous subscribers and other users. | ||||
| CVE-2026-79671 | 2 Ech0, Lin-snow | 2 Ech0, Ech0 | 2026-08-25 | 5.5 Medium |
| Ech0 through 4.2.1 contains a server-side request forgery vulnerability in the validateWebhookURL function (webhook_setting_service.go), which only validates literal IP addresses via net.ParseIP() and fails to reject hostnames that DNS-resolve to private or internal IPs (e.g., 169.254.169.254.nip.io). An attacker with admin privileges can create a webhook with such a hostname to bypass validation and cause the server to make requests to internal services, cloud metadata endpoints, and private network resources. The issue is fixed in 4.4.3. | ||||
| CVE-2026-79673 | 2 Ech0, Lin-snow | 2 Ech0, Ech0 | 2026-08-25 | 6.5 Medium |
| Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:read scope, a read-only scope, but allows write operations including password changes. An attacker with an admin's profile:read access token can change the admin's password and login to obtain an unrestricted session token that bypasses all scope enforcement. | ||||
| CVE-2026-17170 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-25 | 7.5 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper validation of an allocation size. | ||||
| CVE-2026-17168 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-25 | 8.5 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow. | ||||
| CVE-2026-17165 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-25 | 7.5 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference. | ||||
| CVE-2026-17159 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-25 | 7.5 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer overflow. | ||||
| CVE-2026-17160 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-25 | 9.8 Critical |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation. | ||||