Export limit exceeded: 404256 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404256 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-108754 | 2026-10-11 | 3.3 Low | ||
| GPT-Load through 1.4.11 contains a cleartext logging vulnerability that exposes client proxy keys because the Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter. Attackers with read access to console logs or ./data/logs/app.log can recover proxy keys from Gemini-style requests and use them against the corresponding group. | ||||
| CVE-2026-108753 | 1 Agnai | 1 Agnai | 2026-10-11 | 9.4 Critical |
| Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability in self-host.docker-compose.yml, which sets a fixed admin password and public JWT secret. Unauthenticated attackers can log in as admin or sign their own JWT with admin: true to impersonate users, reset passwords, and change server configuration. | ||||
| CVE-2026-108752 | 1 Jupyter | 1 Jupyterhub | 2026-10-11 | 4.2 Medium |
| JupyterHub through 6.0.1 contains an identifier collision vulnerability that allows authenticated users to overwrite another user's named-server OAuth client by registering a hyphenated username. Attackers holding a name like alice-prod can overwrite the client for alice's server prod, breaking OAuth login and revoking tokens by stopping their own server. | ||||
| CVE-2026-108751 | 2026-10-11 | 4.4 Medium | ||
| MoAI-ADK through 3.1.2 contains an improper link resolution vulnerability in the moai init template deployer that allows malicious repositories to overwrite files outside the project via a symlinked .moai-tmp staging path. Attackers can commit a symlink such as .claude/settings.json.moai-tmp so atomicWriteFile truncates and overwrites victim-writable files with MoAI template content. | ||||
| CVE-2026-108750 | 1 Opendocman | 1 Opendocman | 2026-10-11 | 4.3 Medium |
| OpenDocMan 2.4.0 through 2.10.0 contains a decompression bomb vulnerability that allows authenticated users to exhaust PHP memory by uploading crafted office documents. Attackers can upload a small ODT, DOCX, or XLSX file whose XML entries decompress to hundreds of megabytes, crashing PHP workers and degrading availability. | ||||
| CVE-2026-108749 | 2026-10-11 | 3.7 Low | ||
| docling-serve 1.14.0 through 1.36.0 contains a missing authentication vulnerability that allows unauthenticated attackers to access /v1/memory/stats and /v1/memory/counts because they omit the require_auth dependency. Attackers can bypass the configured DOCLING_SERVE_API_KEY to read process and cgroup memory telemetry, object type histograms, and force repeated gc.collect() heap enumeration. | ||||
| CVE-2026-108748 | 2026-10-11 | 5.3 Medium | ||
| Quarkus LangChain4j 1.9.0 through 1.14.1 contains a missing release of memory vulnerability in the chat-scopes WebSocket /_chat/routes endpoint that allows unauthenticated remote clients to exhaust server memory. Attackers can send repeated CONNECT frames reusing one chatId, leaving orphaned scopes in activeScopes until the JVM exits and degrading availability. | ||||
| CVE-2026-108747 | 2026-10-11 | 4.2 Medium | ||
| Lightdash through 2.556.0 contains an authorization bypass vulnerability that allows authenticated organization members to delete other users' personal access tokens by supplying their UUID. Attackers can send DELETE requests to the personal-access-tokens route with a victim's token UUID, even across organizations, to revoke it and break API integrations. | ||||
| CVE-2026-108746 | 2026-10-11 | 8.8 High | ||
| Vearch 3.5.2 through 3.5.9 contains an incorrect authorization vulnerability in Role.HasPermissionForResources that ignores stored ReadOnly or None privilege levels for resources listed in a role. Authenticated non-root users can upsert and delete documents with read-only access, or call PUT /roles to grant their role WriteRead privileges, escalating toward cluster administrator access. | ||||
| CVE-2026-108745 | 2026-10-11 | 3.1 Low | ||
| CloudBeaver through 25.3.5 contains a missing authorization vulnerability in WebSQLResultServlet that allows any web session holder to read other users' LOB export files from a shared folder. Attackers can guess table and column names and enumerate second-resolution timestamps to download victims' LOB values, including data from connections they cannot query. | ||||
| CVE-2026-108744 | 2026-10-11 | 7 High | ||
| pbi-cli 3.10.1 through 3.12.0 contains an OS command injection vulnerability in desktop_sync.py that passes unquoted .pbip paths to cmd /c start when reopening projects. Attackers can lure victims into opening a Power BI project from a space-free path containing & to run commands with victim privileges during report write or reload. | ||||
| CVE-2026-108742 | 2026-10-11 | 4.3 Medium | ||
| CloudBeaver through 25.3.5 contains a missing authorization vulnerability in the initConnection GraphQL mutation that lets view-only shared-project members persist credentials without datasource-edit permission. Attackers can set saveCredentials and sharedCredentials flags with chosen authProperties so other users connect to the shared connection under the attacker's database identity. | ||||
| CVE-2026-108741 | 2026-10-11 | 3.1 Low | ||
| Shepherd (shepherd-ai) through 0.3.1 contains a server-side request forgery guard bypass in the citation-checker extra because the public_url guard validates a resolved address but fetch re-resolves the hostname at connect time. Attackers who plant a crafted reference URL in a checked document and control its DNS can rebind it to internal addresses, sending GET requests to internal HTTP(S) services and capturing responses in evidence files. | ||||
| CVE-2026-108740 | 2026-10-11 | 8.3 High | ||
| GoatCounter through 2.7.0 contains a mass assignment privilege escalation vulnerability in the userPrefSave handler that allows logged-in users to modify protected account fields via form-encoded requests. Attackers with read-only access can POST user.access[all]=* and user.email_verified=true to /user/pref, bypassing readonly tags to gain superuser or admin access. | ||||
| CVE-2026-108739 | 2026-10-11 | 7.5 High | ||
| OpenAgents Workspace backend through launcher-v1.0.17 contains an information disclosure vulnerability that allows unauthenticated attackers to list all workspaces via GET /v1/workspaces. Attackers can read the unmasked browserfabric_api_key in each workspace's settings map, along with workspace ids, slugs, creator emails and member lists. | ||||
| CVE-2026-108738 | 1 Traccar | 1 Traccar | 2026-10-11 | 4.2 Medium |
| Traccar 5.7 through 6.16.0 contains a cross-site request forgery vulnerability that allows attackers to log victims into attacker-controlled accounts because the OpenID Connect callback never validates the OAuth state parameter. Attackers can induce a victim's browser to load /api/session/openid/callback with their own authorization code, causing data the victim enters, such as registered devices, to land in the attacker's account. | ||||
| CVE-2026-108737 | 1 Traccar | 1 Traccar | 2026-10-11 | 6.8 Medium |
| Traccar through 6.16.0 contains a weak password recovery vulnerability that allows attackers to reuse password reset tokens as session credentials because TokenManager does not bind tokens to a purpose. Attackers holding a leaked reset link can obtain a full session via /api/session or change passwords via /api/password/update, retaining access for seven days even after the victim resets their password. | ||||
| CVE-2026-108736 | 2026-10-11 | 3.7 Low | ||
| Speedtest Tracker through 1.15.0 contains an IP allowlist bypass vulnerability that allows unauthenticated remote attackers to evade ALLOWED_IPS and Prometheus allowlists by spoofing X-Forwarded-For headers. Because bootstrap/app.php trusts every peer as a proxy, attackers can supply an allowlisted address to read /prometheus metrics and reach protected web and API endpoints. | ||||
| CVE-2026-108735 | 1 Miniflux Project | 1 Miniflux | 2026-10-11 | 4.3 Medium |
| Miniflux 2.3.0 through 2.3.3 contains a server-side request forgery vulnerability that allows authenticated users to reach internal addresses by setting a feed's proxy_url. Attackers can point proxy_url at loopback or internal hosts, bypassing FETCHER_ALLOW_PRIVATE_NETWORKS checks to probe internal ports and send proxy-style requests to internal services. | ||||
| CVE-2026-108734 | 2026-10-11 | 4.3 Medium | ||
| Frappe CRM 1.49.0 through 1.87.0 contains a missing authorization vulnerability in crm.api.doc.get_linked_docs_of_document that allows authenticated users to read linked documents without permission checks. Attackers can name a lead, deal, comment or user they cannot read to obtain linked call log phone numbers, deal organizations and mention notification text. | ||||