Export limit exceeded: 401436 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (401436 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-105767 | 2026-10-05 | 3.3 Low | ||
| Improper Neutralization of Special Elements used in an OS Command in the integrate-platform-docs composite GitHub Action of Chainguard Academy (edu) from commit 7375a80caabcc31c33ec90f29687ed78c13d16ff before commit fb0efb2537d326ab18c07d620875b8ed2a4b39f3 allows an actor who controls the project_id or storage_bucket inputs to execute arbitrary shell commands on the GitHub Actions runner, because the inputs are interpolated directly into Bash gcloud storage cp commands in several steps via ${{ inputs.* }} expressions. The only in-repository caller passed repository secrets and ran only on trusted triggers, so no untrusted input was known to reach the vulnerable steps. | ||||
| CVE-2026-105686 | 2026-10-05 | N/A | ||
| Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the chunked media upload RPC validates that a chunk index is in range but neither rejects an already stored index nor replaces its previous object. An authenticated user can repeatedly upload the same valid index, causing each successful request to allocate another temporary object and increasing stored bytes beyond the upload session's declared logical size. Assembly detects the inconsistent chunk count only after allocation. This issue is fixed in version 2.18.0. | ||||
| CVE-2026-105766 | 2026-10-05 | 3.1 Low | ||
| Use of the backend-facing $scheme variable in the trailing-slash directory redirect in nginx.conf of Chainguard Academy (edu) from commit 0b75ff98057f69b044a3e7194e428066ac5ad0d4 before commit 93dc0e50739c225f5aee2e803800a47fc0feb906 allows an on-path network attacker to read or modify documentation content served to a victim via an HTTPS request for a slashless directory path, because TLS terminates at the load balancer in front of Nginx and the resulting 301 response redirects the client to a plaintext http:// URL. Browsers that ship the HSTS preload list are not affected, because the .dev top-level domain is preloaded; clients that do not enforce HSTS, such as command-line HTTP clients and scripts that follow redirects, are affected. | ||||
| CVE-2026-55270 | 1 Google | 1 Android | 2026-10-05 | 7.8 High |
| In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-58865 | 1 Google | 1 Android | 2026-10-05 | 7.5 High |
| In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-28625 | 1 Google | 1 Android | 2026-10-05 | N/A |
| In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-28641 | 1 Google | 1 Android | 2026-10-05 | N/A |
| In shouldDisableUninstallButton of ApplicationActionButtonsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-28648 | 1 Google | 1 Android | 2026-10-05 | N/A |
| In Settings, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-105392 | 1 Lybbn | 1 Django-vue-lyadmin | 2026-10-05 | 7.3 High |
| A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment." | ||||
| CVE-2026-105684 | 2026-10-05 | 4.3 Medium | ||
| Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-comment-threads, get-comment-thread, and get-comments RPC commands use check-comment-permissions! but do not apply the share link's pages restriction. A holder of a page-scoped share link can retrieve comment threads and full comment bodies from other pages in the same file, including commenter names, email addresses, photos, and page identifiers. The disclosed page identifiers can also be used with affected page-reading functionality to access unshared design content. This issue is fixed in version 2.18.0. | ||||
| CVE-2026-92067 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 8.8 High |
| Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-92068 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 5.4 Medium |
| Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-92069 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 5.4 Medium |
| Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-92070 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 4.3 Medium |
| Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-92071 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 9.6 Critical |
| Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-89039 | 2026-10-05 | 6.5 Medium | ||
| A caller who can invoke the convert_playwright_script prompt in mcp-k6 can pass a bare file path as the playwright_script argument and receive the contents of any file readable by the user running the server, including SSH keys and cloud credentials in that user's home directory (path traversal). The working-directory restriction applied to '@'-prefixed paths can also be bypassed with a symbolic link inside the working directory that points outside it. | ||||
| CVE-2026-78861 | 2026-10-05 | N/A | ||
| An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via a hardcoded 512-bit RSA Private Key | ||||
| CVE-2026-92072 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 8 High |
| Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-92073 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 8.8 High |
| Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-92074 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 8.8 High |
| Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||