Export limit exceeded: 400211 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400211 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-102263 | 1 Mwasikz | 1 Robo-cafe-rms | 2026-09-29 | 4.7 Medium |
| A vulnerability has been found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The affected element is an unknown function of the file manage-food.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-102248 | 1 Rebuild | 1 Rebuild | 2026-09-29 | 7.3 High |
| A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-100574 | 1 Openclaw | 1 Openclaw | 2026-09-29 | 5.9 Medium |
| OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-host DNS checks. For fetches that use the trusted-host DNS recheck, a trusted hostname that resolves to an unspecified address (0.0.0.0 or ::) bypasses the SSRF destination validation. An attacker who can influence DNS for an allowed hostname can therefore cause a guarded fetch to reach a service bound only to loopback and disclose its response; the practical impact depends on the reachable service and the data it returns. Fixed in 2026.8.1. | ||||
| CVE-2026-100570 | 1 Openclaw | 1 Openclaw | 2026-09-29 | 7.8 High |
| OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an operator starts OpenClaw in attacker-controlled workspace content and then runs the Gmail setup flow, that value is inherited when gcloud is launched, and the gcloud launcher passes it as arguments to the trusted Python interpreter. A crafted CLOUDSDK_PYTHON_ARGS value can therefore cause Python to execute attacker-supplied code with the OpenClaw host user's permissions, allowing credentials to be read, files to be modified, or other processes to be started. This issue is fixed in version 2026.8.1; as a workaround, run Gmail setup only from trusted workspaces and clear inherited CLOUDSDK_* variables beforehand. | ||||
| CVE-2026-100566 | 1 Openclaw | 1 Line | 2026-09-29 | 6.5 Medium |
| OpenClaw LINE versions before 2026.8.1 contain an access control vulnerability where group allowlist mode silently inherits DM allowFrom values when groupAllowFrom is not explicitly configured. Attackers with group participation can trigger the agent despite configured group allowlist restrictions when DM access is broader than intended group access. | ||||
| CVE-2026-100561 | 1 Openclaw | 1 Openclaw | 2026-09-29 | 8 High |
| OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval policy: the policy could trust a command-running wrapper without inspecting the command carried in its arguments. After an operator allowlisted or permanently approved a benign wrapper invocation, a later agent turn could substitute an arbitrary inner command and execute it with the OpenClaw process's host privileges without a further approval prompt. Exploitation requires the relevant wrapper to resolve on the host and a prior operator decision allowing that wrapper. Transparent shell carriers and opaque utilities such as process monitors, tracers, namespace tools, and proxy wrappers were affected through related trust-resolution gaps. Fixed in 2026.8.1. | ||||
| CVE-2026-96418 | 1 Wireshark | 1 Wireshark | 2026-09-29 | 5.5 Medium |
| TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-96417 | 1 Wireshark | 1 Wireshark | 2026-09-29 | 5.5 Medium |
| RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-95394 | 1 Wireshark | 1 Wireshark | 2026-09-29 | 4.7 Medium |
| Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-101266 | 1 Pretix | 1 Pretix | 2026-09-29 | N/A |
| A logic flaw in the checkout flow allows users to bypass validations performed during the check-in by skipping entire check-in steps. | ||||
| CVE-2026-101267 | 1 Pretix | 1 Pretix | 2026-09-29 | N/A |
| A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue. | ||||
| CVE-2026-101268 | 1 Pretix | 1 Pretix | 2026-09-29 | N/A |
| If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account. If the victim does not notice this, this might lead to their order details being stored into the attacker's account. The attack only works when the event is available on a different domain than the organizer page. | ||||
| CVE-2026-101269 | 1 Pretix | 1 Pretix | 2026-09-29 | N/A |
| The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users. Since API-uploaded files are refered to by randomly generated UUIDs and only exist for a day, there is virtually no risk, but it renders the added protection mechanism useless. | ||||
| CVE-2026-101270 | 1 Pretix | 1 Pretix | 2026-09-29 | N/A |
| Malicious HTML content could be injected into the help texts of various fields with organizer permissions. | ||||
| CVE-2026-101271 | 1 Pretix | 1 Pretix | 2026-09-29 | N/A |
| OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled. | ||||
| CVE-2026-93402 | 1 Rsyslog | 1 Rsyslog | 2026-09-29 | 3.1 Low |
| A flaw was found in rsyslog. When using the imdtls input module configured for name or fingerprint authentication, permitted-peer identity checks are not enforced after a successful DTLS handshake. A remote attacker possessing a valid certificate signed by the listener's trusted Certificate Authority could bypass peer restrictions and inject unauthorized syslog records into the input stream. | ||||
| CVE-2026-65129 | 2 Linux, Nvidia | 3 Linux Kernel, Infra Controller, Infrastructure Controller | 2026-09-29 | 6.7 Medium |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service. | ||||
| CVE-2026-100748 | 1 Svenbluege.de | 1 Event Gallery For Joomla | 2026-09-29 | N/A |
| Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0 | ||||
| CVE-2026-97164 | 1 Svenbluege.de | 1 Event Gallery For Joomla | 2026-09-29 | N/A |
| Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extension < 6.5.0 - Using the `images` parameter of the `cache.process` task, you can recursively delete any directories that the web server is authorized to write to. | ||||
| CVE-2026-67364 | 1 Balbooa.com | 1 Balbooa.com Balbooa Forms Extension For Joomla | 2026-09-29 | N/A |
| Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting an unauthenticated attacker inject arbitrary PHP that executes server-side. The CSRF token needed to reach the endpoint is itself disclosed anonymously via a separate task, so it provides no real protection. Exploitability requires the form to have a custom-PHP handler configured (a documented builder feature) referencing that shortcode, and no reCAPTCHA on the submit button. | ||||