Export limit exceeded: 403607 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403607 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403607 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-107798 | 1 Banq | 1 Jivejdon | 2026-10-09 | 5.4 Medium |
| jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter that inserts unvalidated URLs into anchor href attributes. Authenticated attackers can post messages with javascript: links or quote-breaking URLs to execute JavaScript when other users click or hover over rendered links. | ||||
| CVE-2026-107799 | 1 Banq | 1 Jivejdon | 2026-10-09 | 5.4 Medium |
| Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script by posting unsanitized forum message bodies. Message bodies are rendered by messageListBody.jsp with filter="false" and non-escaping default filters, executing script in the browser of every user viewing the thread. | ||||
| CVE-2026-107801 | 1 Banq | 1 Jivejdon | 2026-10-09 | 5.4 Medium |
| Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute JavaScript by uploading attachments with an attacker-supplied Content-Type. Attackers can upload a file declared as text/html, which UploadShowAction serves inline, and share its link to run JavaScript on the application's origin for viewing users. | ||||
| CVE-2026-107829 | 1 Banq | 1 Jivejdon | 2026-10-09 | 5.9 Medium |
| Jivejdon through 5.0 contains a weak password storage vulnerability that stores account passwords as unsalted MD5 digests via ToolsUtil.hash() in AccountDaoSql. Attackers who obtain the user table through database access or SQL injection can crack passwords with precomputed tables or GPU attacks. | ||||
| CVE-2026-107830 | 1 Banq | 1 Jivejdon | 2026-10-09 | 5.3 Medium |
| Jivejdon from commit e0306088 through commit ee67a65e lacks rate limiting on the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction, allowing unlimited SMS sending. Attackers can load newAccount.jsp to set session attributes, then repeatedly call the endpoint to harass arbitrary phone numbers and exhaust the operator's Tencent Cloud SMS balance. | ||||
| CVE-2026-107651 | 2 Eog, Redhat | 2 Eog, Enterprise Linux | 2026-10-09 | 5.5 Medium |
| A flaw was found in Eye of GNOME (eog). A heap-based buffer overflow exists in the PNG metadata reader due to improper state handling when parsing split metadata chunks. A remote attacker could exploit this flaw by enticing a user into opening a specially crafted PNG file, potentially leading to arbitrary code execution or a Denial of Service (DoS) via application crash. | ||||
| CVE-2026-105673 | 1 Tp-link | 1 Tapo C325wb V2 | 2026-10-09 | N/A |
| An unauthenticated denial-of-service vulnerability exists in Tapo C325WB v2 in the RTSP streaming service on TCP port 554 when the Camera Account feature is enabled. A crafted pair of RTSP-over-HTTP tunneling requests can cause memory corruption and crash the streaming daemon. Successful exploitation may allow an unauthenticated adjacent-network attacker to disrupt live video and related streaming functions until the affected service recovers or restarts. | ||||
| CVE-2026-105672 | 1 Tp-link | 1 Tapo C325wb V2 | 2026-10-09 | N/A |
| TP-Link Tapo C325WB V2 contains an unauthenticated authorization bypass vulnerability in the HTTPS JSON API dispatcher on TCP port 443. An attacker on the adjacent network can append an onboarding-scoped object to a JSON request to bypass session verification and invoke privileged actions without authentication. Successful exploitation may allow an unauthenticated adjacent-network attacker to access live video and audio, modify device settings, and obtain sensitive device information or secrets. | ||||
| CVE-2026-105674 | 1 Tp-link | 1 Tapo C325wb V2 | 2026-10-09 | N/A |
| TP-Link Tapo C325WB V2 generates the pre-shared key used by its local media streaming service with a time-seeded pseudo-random number generator, making the key predictable and recoverable. An unauthenticated attacker on the adjacent network can recover the key and authenticate to the media streaming service without valid user credentials. Successful exploitation may allow an unauthenticated adjacent-network attacker to access and take over live video and audio streams, compromising the confidentiality and integrity of camera media. | ||||
| CVE-2026-78659 | 1 Go Standard Library | 2 Net/http, Net/http2 | 2026-10-09 | N/A |
| When "Trailer" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a "Trailer" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently. | ||||
| CVE-2026-56866 | 1 Go Standard Library | 2 Net/http, Net/http/httputil | 2026-10-09 | 6.5 Medium |
| When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning. | ||||
| CVE-2026-94440 | 1 Go Standard Library | 2 Mime/multipart, Net/textproto | 2026-10-09 | N/A |
| Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes. | ||||
| CVE-2026-78660 | 1 Go Standard Library | 2 Net/http, Net/http2 | 2026-10-09 | N/A |
| Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling. | ||||
| CVE-2026-78669 | 1 Go Standard Library | 2 Net/http, Net/http2 | 2026-10-09 | 7.5 High |
| A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values. | ||||
| CVE-2026-97032 | 1 Go Standard Library | 2 Net/http, Net/http2 | 2026-10-09 | 5.9 Medium |
| HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server. | ||||
| CVE-2026-97075 | 2026-10-09 | 6.5 Medium | ||
| Missing Authorization vulnerability in WP Media WP Rocket wp-rocket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Rocket: from n/a before 3.23.5. | ||||
| CVE-2026-95263 | 1 Liufee | 1 Feehicms | 2026-10-09 | 7.2 High |
| Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update permission can change the password of the built-in super administrator account. The server does not enforce protection for this account, and the update scenario does not require the old password. | ||||
| CVE-2026-95264 | 1 Liufee | 1 Feehicms | 2026-10-09 | 6.5 Medium |
| Feehi CMS 2.1.1 is vulnerable to Directory Traversal. An authenticated backend user with article edit permission can delete arbitrary files writable by the PHP process. Article image metadata is used to construct a filesystem path and is passed to `unlink()` without path traversal or directory validation. | ||||
| CVE-2026-105642 | 1 Ghost | 1 Ghost | 2026-10-09 | 8.8 High |
| Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a vulnerability in its SVG handling. Any staff user, including Contributors, could create a bookmark card for an attacker-controlled website, resulting in arbitrary commands being run on the Ghost server. This issue is fixed in version 6.67.0. | ||||
| CVE-2026-105643 | 1 Ghost | 1 Ghost | 2026-10-09 | 7.3 High |
| Ghost is a Node.js content management system. From version 6.34.0 until 6.67.0, embed cards in the Ghost editor could bypass protections against stored cross-site scripting. Any staff user, including Contributors, could store scripts in post content that ran when another staff user opened the post in the editor, potentially compromising that user’s admin session. Self-hosted sites should leave the new security.embedPreviewUrl configuration option at its default value. This issue is fixed in version 6.67.0. | ||||