Export limit exceeded: 395517 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (395517 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-54645 | 1 Cubecart | 1 V6 | 2026-09-18 | 4.8 Medium |
| CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, description_short, and spec_copy rich-text fields from $GLOBALS['RAW']['POST'] and removes only script elements before the values are stored and rendered through Smarty templates. An administrator with product-editing rights can store event-handler attributes, SVG content, or javascript: URIs that bypass this filter, causing persistent JavaScript execution when a storefront visitor or another administrator views the product content and enabling session exposure or unauthorized browser-context actions. This issue is fixed in version 6.7.5. | ||||
| CVE-2026-93435 | 1 Noderedis | 1 Redis-parser | 2026-09-18 | 7.5 High |
| redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nested arrays. Attackers can send crafted RESP byte streams with repeated array headers that exhaust the V8 call stack, causing an uncaught RangeError that terminates the Node.js process without triggering error handling callbacks. | ||||
| CVE-2026-93450 | 1 Go-openapi | 1 Swag | 2026-09-18 | 7.5 High |
| go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documents to services accepting OpenAPI specifications, causing fatal stack overflow that terminates the process and all in-flight requests. | ||||
| CVE-2026-93454 | 1 Webkul | 1 Aureus Erp | 2026-09-18 | 5.4 Medium |
| Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record. | ||||
| CVE-2026-93455 | 1 Batiste | 1 Django-page-cms | 2026-09-18 | 6.5 Medium |
| django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and stored media paths. Attackers with low-privilege staff credentials can enumerate content identifiers and access unpublished drafts, page listings, and file paths without proper authorization checks. | ||||
| CVE-2026-93456 | 1 Batiste | 1 Django-page-cms | 2026-09-18 | 8.2 High |
| django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing unescaped content that renders to all visitors, enabling stored cross-site scripting attacks. | ||||
| CVE-2026-93467 | 1 Hgiga | 3 Oaklouds-custom Page-2.0, Oaklouds-custom Page-3.0, Oaklouds-custom Page-4.0 | 2026-09-18 | 9.8 Critical |
| The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content. | ||||
| CVE-2026-93468 | 1 Hgiga | 2 Oaklouds-bulletin V3-2.0, Oaklouds-bulletin V3-3.0 | 2026-09-18 | 7.5 High |
| The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read arbitrary system files. | ||||
| CVE-2026-56988 | 1 Google | 1 Android | 2026-09-18 | 6.4 Medium |
| In multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56986 | 1 Google | 1 Android | 2026-09-18 | 8.4 High |
| In multiple files, there is a possible out-of-bounds read due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56970 | 1 Google | 1 Android | 2026-09-18 | 8.4 High |
| In multiple locations, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56972 | 1 Google | 1 Android | 2026-09-18 | 6.7 Medium |
| In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56973 | 1 Google | 1 Android | 2026-09-18 | 6.7 Medium |
| In multiple locations, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56974 | 1 Google | 1 Android | 2026-09-18 | 8.8 High |
| In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. | ||||
| CVE-2026-56975 | 1 Google | 1 Android | 2026-09-18 | 6.5 Medium |
| In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56978 | 1 Google | 1 Android | 2026-09-18 | 8.4 High |
| In get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56979 | 1 Google | 1 Android | 2026-09-18 | 6.7 Medium |
| In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56982 | 1 Google | 1 Android | 2026-09-18 | 7.8 High |
| In VPU, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-56985 | 1 Google | 1 Android | 2026-09-18 | 8.4 High |
| In multiple files, there is a possible way to obtain signatures due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-72762 | 1 N8n | 1 N8n | 2026-09-18 | 8.8 High |
| n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without validation. An authenticated user able to run workflows can supply a crafted format value to write arbitrary files outside the node's working directory on the n8n instance. | ||||