Export limit exceeded: 403584 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403584 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-25273 | 1 Qualcomm | 103 Congo, Congo Firmware, Cq8845s and 100 more | 2026-10-09 | 6.7 Medium |
| Memory Corruption when processing camera operations due to out-of-bounds write during driver updates. | ||||
| CVE-2026-25272 | 1 Qualcomm | 311 Cologne, Cologne Firmware, Cq2390m and 308 more | 2026-10-09 | 6.7 Medium |
| Memory Corruption when processing camera CRE driver operations with improper handling of buffer limits during hardware update preparation. | ||||
| CVE-2026-25270 | 1 Qualcomm | 407 Cologne, Cologne Firmware, Congo and 404 more | 2026-10-09 | 6.7 Medium |
| Memory corruption when processing command buffer requests with invalid length parameters in the Android Camera driver. | ||||
| CVE-2026-25269 | 1 Qualcomm | 313 Cologne, Cologne Firmware, Cq2390m and 310 more | 2026-10-09 | 6.7 Medium |
| Memory corruption when processing camera requests with excessive batch and IO buffer configurations exceeds allocated memory size. | ||||
| CVE-2026-25267 | 1 Qualcomm | 333 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, 9205 Lte Modem and 330 more | 2026-10-09 | 7.8 High |
| Memory corruption when non-secure loader rewrites page tables before secure memory initialization. | ||||
| CVE-2026-25263 | 1 Qualcomm | 333 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, 9205 Lte Modem and 330 more | 2026-10-09 | 6.6 Medium |
| Memory corruption while processing IOCTL command called from user space to the kernel with invalid parameters. | ||||
| CVE-2026-108105 | 1 Open5gs | 1 Open5gs | 2026-10-09 | 5.9 Medium |
| Open5GS through 2.8.0 contains a reachable assertion vulnerability in mme_gn_handle_sgsn_context_request() that allows remote unauthenticated attackers to crash the MME via malformed SGSN Address IEs. Attackers sending GTPv1-C traffic from a configured SGSN address with a known UE IMSI or P-TMSI can supply an invalid address length to terminate open5gs-mmed, denying service to all subscribers. | ||||
| CVE-2026-108103 | 1 Open5gs | 1 Open5gs | 2026-10-09 | 5.3 Medium |
| Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_dropped_dl_traffic_threshold() that allows remote unauthenticated attackers to read past IE buffers via short IEs. Attackers can send PFCP Session Establishment or Modification Requests to the UPF on UDP port 8805 with DLPA and DLBY flags set, potentially crashing the UPF. | ||||
| CVE-2026-108102 | 1 Open5gs | 1 Open5gs | 2026-10-09 | 5.3 Medium |
| Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_volume_measurement() in lib/pfcp/types.c that allows remote unauthenticated attackers to read past IE buffers. Attackers can send a PFCP Session Report Request to the SMF on UDP port 8805 with a short, all-flags Volume Measurement IE, reading up to 48 bytes and potentially crashing the SMF. | ||||
| CVE-2026-108101 | 1 Hortusfox | 1 Hortusfox | 2026-10-09 | 7.5 High |
| HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under public/attachments/. Attackers can upload HTML or SVG files via /plants/attachments/add for stored cross-site scripting, or PHP files where .htaccess is unenforced to execute code. | ||||
| CVE-2026-108100 | 1 Hortusfox | 1 Hortusfox | 2026-10-09 | 6.5 Medium |
| HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes. | ||||
| CVE-2026-96890 | 1 Github | 1 Enterprise Server | 2026-10-09 | 8.8 High |
| A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed a repository contributor to cause the appliance to issue requests to attacker-controlled internal hosts, which could be chained to achieve remote code execution on the appliance. The secret scanning validator for GCP service account credentials trusted the token endpoint embedded in a committed credential and issued a request to it without restricting the destination. Exploitation required an authenticated user with permission to push to a repository on an instance with GitHub Advanced Security and secret scanning validity checks enabled, a non-default configuration. This vulnerability affected GitHub Enterprise Server 3.20, 3.21, and 3.22 and was fixed in versions 3.20.9, 3.21.7, and 3.22.2. This vulnerability was reported through the GitHub Bug Bounty program. | ||||
| CVE-2026-107781 | 1 Dromara | 1 Skyeye | 2026-10-09 | 7.4 High |
| Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side request forgery and missing authorization vulnerability in the OnlyOffice save callback editUploadOfficeFileById. Unauthenticated attackers can supply arbitrary url and key parameters to make the server fetch internal URLs and overwrite any user's stored file, then read results via queryFileToShowById. | ||||
| CVE-2026-105278 | 2026-10-09 | 9.8 Critical | ||
| The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use. An attacker with network access to the management interface can authenticate using this credential and gain full administrative control of the application. | ||||
| CVE-2026-94067 | 2026-10-09 | 8.1 High | ||
| Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fuelthemes The Voux thevoux-wp allows PHP Local File Inclusion.This issue affects The Voux: from n/a through 6.9.5. | ||||
| CVE-2026-94066 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SpabRice Pond pond allows Reflected XSS.This issue affects Pond: from n/a through 2.6.1. | ||||
| CVE-2026-94063 | 2026-10-09 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Education Center education allows Reflected XSS.This issue affects Education Center: from n/a through 3.6.12. | ||||
| CVE-2026-94065 | 2026-10-09 | 8.8 High | ||
| Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio colorit allows Object Injection.This issue affects ColorFolio: from n/a through 1.3. | ||||
| CVE-2026-94064 | 2026-10-09 | 8.8 High | ||
| Deserialization of Untrusted Data vulnerability in BuddhaThemes Neo | Barber Shop WordPress Theme neocut allows Object Injection.This issue affects Neo | Barber Shop WordPress Theme: from n/a through 3.5. | ||||
| CVE-2026-96395 | 1 Canva | 1 Affinity | 2026-10-09 | 3.6 Low |
| The Affinity by Canva app for macOS before 3.3.1 (October 2026 release) did not perform adequate bounds checking when generating QuickLook thumbnails and previews of Affinity document files, leading to an out-of-bounds heap read. A threat actor could craft an Affinity document that, when displayed or previewed by a user in Finder, could disclose the contents of adjacent heap memory, including memory addresses, in the rendered thumbnail or preview image. | ||||