Export limit exceeded: 403663 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403663 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403663 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104075 | 1 Tvu Networks | 1 Tvu Receiver / Transceiver | 2026-10-09 | 9.8 Critical |
| TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerability in the web management login endpoint POST /tvu/Login that allows remote unauthenticated attackers to obtain an administrative session by submitting an empty or absent UserName parameter. Attackers can send a crafted HTTP request directly, bypassing client-side JavaScript validation, to receive a valid session cookie regardless of the password value and gain full administrative control of the device's web management interface. | ||||
| CVE-2026-106126 | 1 Tenable | 1 Identity Exposure | 2026-10-09 | 9.9 Critical |
| A command injection vulnerability in the Active Directory Events Listener of Tenable Identity Exposure (SaaS) allows an authenticated, low-privileged attacker to execute arbitrary commands as SYSTEM on the PDCe. | ||||
| CVE-2026-107779 | 1 Dromara | 1 Skyeye | 2026-10-09 | 9.8 Critical |
| Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers can POST GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL jobs with attacker-supplied glueSource to /jobinfo/addAndStart, executing commands on the executor host or stopping and deleting jobs. | ||||
| CVE-2026-107780 | 1 Dromara | 1 Skyeye | 2026-10-09 | 9.8 Critical |
| Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/TtsController/textToSpeech endpoint via the format parameter. Attackers can inject a single quote into format to break out of the PowerShell string and execute commands as the Skyeye service account on Windows. | ||||
| CVE-2026-107782 | 1 Winsiderss | 1 System Informer | 2026-10-09 | 7.8 High |
| System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Microsoft-signed host like rundll32.exe, connect to SiSvcApiPort, and call PhSvcApiCreateService to execute code as SYSTEM. | ||||
| CVE-2026-107399 | 1 Sparklemotion | 1 Mechanize | 2026-10-09 | 6.8 Medium |
| The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize applies no origin trust boundary in Mechanize::HTTP::Agent#response_follow_meta_refresh when Mechanize#follow_meta_refresh is enabled. A page containing a meta refresh to another origin causes headers configured through Mechanize#request_headers= to be reapplied to the refresh request, allowing an attacker who controls content in the crawl to capture bearer tokens or session cookies. The default configuration is not affected because follow_meta_refresh is false, and the exposure is limited to caller-supplied default headers. This issue is fixed in version 2.14.1. | ||||
| CVE-2026-105269 | 1 Satel | 1 Satel Netco Design | 2026-10-09 | 6.8 Medium |
| Satel Netco Design versions prior to v2.1.7 contains a stored cross site scripting vulnerability. An authenticated user with Network Operator privileges could store untrusted content that is rendered without adequate neutralization. Successful exploitation could allow script execution in another user's browser when the affected content is viewed. | ||||
| CVE-2025-71428 | 1 Banq | 1 Jivejdon | 2026-10-09 | 4.9 Medium |
| Jivejdon through 5.0 contains a sql injection vulnerability in AccountDaoSql.getAccountByNameLike() that allows authenticated administrators to inject SQL via the username parameter. Attackers with the Admin role can submit crafted input to /admin/user/userListAction to read database contents, including other accounts' password hashes. | ||||
| CVE-2026-107792 | 1 Banq | 1 Jivejdon | 2026-10-09 | 4.3 Medium |
| Jivejdon from commit d58a36b0 through commit ee67a65e contains a missing authorization vulnerability in UpdateThreadToForumAction that allows authenticated users to move other users' threads. Attackers can send crafted threadId and forumId values to /message/threadToForum/save to relocate any reply-less thread into an arbitrary forum. | ||||
| CVE-2026-107796 | 1 Banq | 1 Jivejdon | 2026-10-09 | 6.1 Medium |
| Jivejdon from commit 5489372d through commit ee67a65e contains a reflected cross-site scripting vulnerability in application/query/taggedThreadList.jsp that allows unauthenticated attackers to inject script via unencoded tagID and count parameters. Attackers can craft a link with a script-closing payload in tagID or count, triggered when start exceeds zero, to execute JavaScript in victims' browsers. | ||||
| CVE-2026-107798 | 1 Banq | 1 Jivejdon | 2026-10-09 | 5.4 Medium |
| jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter that inserts unvalidated URLs into anchor href attributes. Authenticated attackers can post messages with javascript: links or quote-breaking URLs to execute JavaScript when other users click or hover over rendered links. | ||||
| CVE-2026-107799 | 1 Banq | 1 Jivejdon | 2026-10-09 | 5.4 Medium |
| Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script by posting unsanitized forum message bodies. Message bodies are rendered by messageListBody.jsp with filter="false" and non-escaping default filters, executing script in the browser of every user viewing the thread. | ||||
| CVE-2026-107801 | 1 Banq | 1 Jivejdon | 2026-10-09 | 5.4 Medium |
| Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute JavaScript by uploading attachments with an attacker-supplied Content-Type. Attackers can upload a file declared as text/html, which UploadShowAction serves inline, and share its link to run JavaScript on the application's origin for viewing users. | ||||
| CVE-2026-107829 | 1 Banq | 1 Jivejdon | 2026-10-09 | 5.9 Medium |
| Jivejdon through 5.0 contains a weak password storage vulnerability that stores account passwords as unsalted MD5 digests via ToolsUtil.hash() in AccountDaoSql. Attackers who obtain the user table through database access or SQL injection can crack passwords with precomputed tables or GPU attacks. | ||||
| CVE-2026-107830 | 1 Banq | 1 Jivejdon | 2026-10-09 | 5.3 Medium |
| Jivejdon from commit e0306088 through commit ee67a65e lacks rate limiting on the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction, allowing unlimited SMS sending. Attackers can load newAccount.jsp to set session attributes, then repeatedly call the endpoint to harass arbitrary phone numbers and exhaust the operator's Tencent Cloud SMS balance. | ||||
| CVE-2026-107651 | 2 Eog, Redhat | 2 Eog, Enterprise Linux | 2026-10-09 | 5.5 Medium |
| A flaw was found in Eye of GNOME (eog). A heap-based buffer overflow exists in the PNG metadata reader due to improper state handling when parsing split metadata chunks. A remote attacker could exploit this flaw by enticing a user into opening a specially crafted PNG file, potentially leading to arbitrary code execution or a Denial of Service (DoS) via application crash. | ||||
| CVE-2026-105672 | 1 Tp-link | 1 Tapo C325wb V2 | 2026-10-09 | N/A |
| TP-Link Tapo C325WB V2 contains an unauthenticated authorization bypass vulnerability in the HTTPS JSON API dispatcher on TCP port 443. An attacker on the adjacent network can append an onboarding-scoped object to a JSON request to bypass session verification and invoke privileged actions without authentication. Successful exploitation may allow an unauthenticated adjacent-network attacker to access live video and audio, modify device settings, and obtain sensitive device information or secrets. | ||||
| CVE-2026-105674 | 1 Tp-link | 1 Tapo C325wb V2 | 2026-10-09 | N/A |
| TP-Link Tapo C325WB V2 generates the pre-shared key used by its local media streaming service with a time-seeded pseudo-random number generator, making the key predictable and recoverable. An unauthenticated attacker on the adjacent network can recover the key and authenticate to the media streaming service without valid user credentials. Successful exploitation may allow an unauthenticated adjacent-network attacker to access and take over live video and audio streams, compromising the confidentiality and integrity of camera media. | ||||
| CVE-2026-97032 | 1 Go Standard Library | 2 Net/http, Net/http2 | 2026-10-09 | 5.9 Medium |
| HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server. | ||||
| CVE-2026-95263 | 1 Liufee | 1 Feehicms | 2026-10-09 | 7.2 High |
| Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update permission can change the password of the built-in super administrator account. The server does not enforce protection for this account, and the update scenario does not require the old password. | ||||