Export limit exceeded: 402775 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402775 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-106065 | 1 Redhat | 1 Enterprise Linux | 2026-10-07 | 6.3 Medium |
| A heap-based buffer overflow was found in GIMP’s PCX export plug-in. For images with extremely large width and height, buffer allocation uses overflowing 32-bit width * height arithmetic while subsequent GEGL operations use the full extent, after integer overflow in size calculation | ||||
| CVE-2026-94662 | 2026-10-07 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Stored XSS. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.19. | ||||
| CVE-2026-91181 | 1 Mattermost | 2 Mattermost, Mattermost Server | 2026-10-07 | 6.5 Medium |
| Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated user holding only the read-only Data Retention Policy permission to obtain a private team's secret invite_id and email, and use it to join the team without authorization, via GET /api/v4/data_retention/policies/{policy_id}/teams.. Mattermost Advisory ID: MMSA-2026-00702 | ||||
| CVE-2026-95666 | 1 Mattermost | 2 Mattermost, Mattermost Server | 2026-10-07 | 4.3 Medium |
| Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length of the post ID array accepted by the bulk reactions endpoint which allows an authenticated user to cause excessive database load via a crafted request to {{POST /api/v4/posts/ids/reactions}}.. Mattermost Advisory ID: MMSA-2026-00771 | ||||
| CVE-2026-18074 | 2 Ibm, Redhat | 3 Financial Transaction Manager, Financial Transaction Manager Ftmfor Redhat Openshift, Openshift | 2026-10-07 | 8.2 High |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper authentication and missing authorization. | ||||
| CVE-2026-42617 | 1 Tuxera | 1 Ntfs-3g | 2026-10-07 | N/A |
| In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by extending a directory, e.g., by creating a file. | ||||
| CVE-2025-70522 | 2026-10-07 | N/A | ||
| The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint. | ||||
| CVE-2026-106565 | 1 Imagemagick | 1 Imagemagick | 2026-10-07 | 5.9 Medium |
| ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57. | ||||
| CVE-2026-92543 | 2026-10-07 | N/A | ||
| Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection. | ||||
| CVE-2026-18095 | 2 Ibm, Redhat | 3 Financial Transaction Manager, Financial Transaction Manager Ftmfor Redhat Openshift, Openshift | 2026-10-07 | 8.5 High |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow. | ||||
| CVE-2026-96259 | 1 Mattermost | 2 Mattermost, Mattermost Server | 2026-10-07 | 5.5 Medium |
| Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-connection filter to OAuth endpoint requests, which allows a System Administrator to make the server issue requests to internal network addresses and read the responses via the configured OAuth token and userinfo endpoints.. Mattermost Advisory ID: MMSA-2026-00776 | ||||
| CVE-2026-39600 | 2026-10-07 | 4.7 Medium | ||
| URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Mehul Gohil Aculect AI Companion aculect-ai-companion allows Phishing.This issue affects Aculect AI Companion: from n/a through 0.8.2. | ||||
| CVE-2026-106557 | 2026-10-07 | 7.7 High | ||
| Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package did not sufficiently validate TechDocs Markdown extension configuration. An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary, potentially exposing backend-host data or internal network resources. This issue is fixed in versions 1.14.6 and 1.15.4 when pymdown-extensions 10.21.3 or later is also used, normally through mkdocs-techdocs-core 1.7.0 or later. | ||||
| CVE-2026-76472 | 2026-10-07 | 8.8 High | ||
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-76472 are related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74. | ||||
| CVE-2026-76467 | 2026-10-07 | 7.5 High | ||
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76467 are related to issues concerning improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664. | ||||
| CVE-2026-76470 | 2026-10-07 | 8.8 High | ||
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76470 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-682. | ||||
| CVE-2026-76469 | 2026-10-07 | 7.4 High | ||
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76469 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-691. | ||||
| CVE-2026-96594 | 1 Gitea | 1 Gitea | 2026-10-07 | 6.1 Medium |
| The Gitea API endpoint `GET /api/v1/repos/{owner}/{repo}/media/{filepath}` wrote files of up to 1 KiB that are stored directly in Git, not in LFS, to the response without the content type and disposition headers Gitea uses for user content. An HTML file committed to a repository was therefore rendered by the browser on the Gitea origin. A user who can push to a repository could run JavaScript in the session of a victim who opens the media URL and act with the victim's permissions. | ||||
| CVE-2026-76468 | 2026-10-07 | 8.2 High | ||
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76468 are related to improper input validation that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20. | ||||
| CVE-2026-76464 | 2026-10-07 | 9.6 Critical | ||
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by this CVE-2026-76464 are related to buffer management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-119. | ||||