Export limit exceeded: 372876 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372876 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-47615 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 7.5 High |
| NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure. | ||||
| CVE-2026-47616 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 7.5 High |
| NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. | ||||
| CVE-2026-47617 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 7.5 High |
| NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure. | ||||
| CVE-2026-47618 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 7.5 High |
| NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. | ||||
| CVE-2026-47619 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 6.6 Medium |
| NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-47620 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 6.5 Medium |
| NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service. | ||||
| CVE-2026-47621 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 6.5 Medium |
| NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to denial of service and data tampering. | ||||
| CVE-2026-47622 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 5.3 Medium |
| NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure. | ||||
| CVE-2026-47623 | 1 Nvidia | 1 Dynamo | 2026-08-05 | 8.2 High |
| NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering. | ||||
| CVE-2026-69703 | 1 Maximeamini | 1 Atals-livre | 2026-08-05 | 9.8 Critical |
| Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke destructive admin actions such as record deletion by requesting controller endpoints with GET parameters like supp, because the PHP header() redirect is never followed by an exit or die call, allowing all subsequent code including database operations to execute regardless of session state. | ||||
| CVE-2026-69704 | 1 Maximeamini | 1 Atals-livre | 2026-08-05 | 6.5 Medium |
| Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET parameter to the supp() deletion helper function. Attackers can inject malicious SQL syntax via the vulnerable GET parameter to perform unauthorized database operations including data deletion and extraction. | ||||
| CVE-2026-66300 | 1 Snomed International | 1 Snowstorm | 2026-08-05 | 5 Medium |
| SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. An attacker can inject arbitrary JavaScript which will execute upon a target user navigating to a crafted, malicious link. Fixed in 10.12.2 and 10.9.3. | ||||
| CVE-2017-20241 | 1 Keysight | 1 Ixchariot | 2026-08-05 | 9.8 Critical |
| Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code. | ||||
| CVE-2017-20242 | 1 Keysight | 1 Ixchariot | 2026-08-05 | 9.8 Critical |
| Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code. | ||||
| CVE-2026-49435 | 1 Keysight | 5 Hawkeye, Ixbypass, Ixchariot and 2 more | 2026-08-05 | 9.8 Critical |
| Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges. | ||||
| CVE-2026-70620 | 1 Odysseus-dev | 1 Odysseus | 2026-08-05 | 6.8 Medium |
| Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network resources by supplying arbitrary URLs to the embedding endpoint configuration without scheme, host, IP range, or DNS rebind validation. Attackers can submit loopback addresses, RFC 1918 ranges, or link-local addresses through the embedding endpoint API to partially read responses from cloud instance metadata services, internal APIs, and other hosts reachable from the server. | ||||
| CVE-2026-70619 | 1 Odysseus-dev | 1 Odysseus | 2026-08-05 | 8.8 High |
| Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session authentication but omit the admin authorization guard. Attackers can supply an attacker-controlled URL to overwrite the embedding backend persisted in the endpoint configuration file and process environment, causing all subsequent embedding operations including chat messages, RAG queries, memory entries, and vault text to be transmitted in plaintext to the attacker-controlled destination, or delete the endpoint configuration to deny embedding service to all users. | ||||
| CVE-2026-18907 | 1 Tecno Mobile | 1 Hi Browser | 2026-08-05 | N/A |
| Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename. | ||||
| CVE-2026-9273 | 2 Stellarwp, Wordpress | 2 Membership Plugin – Kadence Memberships, Wordpress | 2026-08-05 | 9.3 Critical |
| The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0. This is due to the legacy lost-password handler rc_process_lost_password_form() consuming the attacker-controlled rc_redirect POST parameter into two unvalidated sinks in legacy/includes/forms.php: wp_redirect( esc_url( $_POST['rc_redirect'] ) . ... ) at line 243, and add_query_arg( array( 'key' => $key, 'login' => ... ), $_POST['rc_redirect'] ) inside rc_send_password_reset_email() at line 306. The nonce required to reach the handler is broadcast by the public [login_form] shortcode at line 207 to any anonymous visitor. This makes it possible for unauthenticated attackers to issue a password-reset request for any account (including administrators) whose reset email body points the victim at an attacker-controlled host carrying a valid reset key/login. When the victim clicks the link, the reset key leaks to the attacker, who can replay it against the legitimate site to complete account takeover. | ||||
| CVE-2026-66839 | 1 Integrated Systems Technologies, Inc. | 1 Netkids Imark | 2026-08-05 | N/A |
| NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges. | ||||