Export limit exceeded: 382981 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (382981 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100277 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 8.9 High |
| In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature | ||||
| CVE-2026-104910 | 1 Misp | 1 Misp | 2026-10-02 | N/A |
| MISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a given event, the system retrieved related event metadata directly from the correlation table without re-validating the caller's access rights against each related event. The correlation table stores a snapshot of the event's distribution level and sharing group at the time the correlation was created, and does not carry the published flag. As a result, events that the caller is not permitted to open—because they are unpublished, or because their distribution or sharing group has changed since the correlation was recorded—were still returned with their metadata (title, date, correlating value counts). Preconditions: - An authenticated user with access to at least one event in MISP. - The existence of correlation entries linking that event to other events the user should not be able to view. Impact: - Unauthorized disclosure of event metadata (titles, dates, correlation counts) for events the user has no right to access. - Potential reconnaissance of threat-intelligence event names and timelines across sharing groups. Affected: MISP versions prior to the fix commit (2ffa97f05). | ||||
| CVE-2026-84386 | 1 Fortinet | 1 Forticlientwindows | 2026-10-02 | 4.7 Medium |
| A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via via an exposed minifilter communication port. | ||||
| CVE-2026-104286 | 1 Fortinet | 1 Fortimail | 2026-10-02 | 9.8 Critical |
| An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. | ||||
| CVE-2026-94636 | 1 Apache | 1 Thrift | 2026-10-02 | N/A |
| Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity in input vulnerability in Apache Thrift py bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||
| CVE-2026-94648 | 1 Apache | 1 Thrift | 2026-10-02 | N/A |
| Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||
| CVE-2026-94653 | 1 Apache | 1 Thrift | 2026-10-02 | N/A |
| Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||
| CVE-2026-101104 | 2026-10-02 | 7.7 High | ||
| The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions. | ||||
| CVE-2026-100278 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 4.9 Medium |
| In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments | ||||
| CVE-2026-100279 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials | ||||
| CVE-2026-100280 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 3.1 Low |
| In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible | ||||
| CVE-2026-95385 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-10-02 | 6.5 Medium |
| Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-51857 | 2026-10-02 | 9.8 Critical | ||
| In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary. | ||||
| CVE-2026-51861 | 1 Dataelement | 1 Bisheng | 2026-10-02 | 9.8 Critical |
| bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Code Injection in src/backend/bisheng/api/v1/validate.py. | ||||
| CVE-2026-51867 | 2026-10-02 | 9.8 Critical | ||
| agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object. | ||||
| CVE-2026-51872 | 1 Stitionai | 1 Devika | 2026-10-02 | 9.8 Critical |
| Devika v1.0 is vulnerable to Code Injection via the Runner.run_code function in src/agents/runner/runner.py. | ||||
| CVE-2026-104419 | 2 Zcashfoundation, Zfnd | 2 Zebra, Zebra | 2026-10-02 | 4.8 Medium |
| Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that honest peers get banned, eroding its peer set and raising eclipse risk. | ||||
| CVE-2026-104422 | 2 Zcashfoundation, Zfnd | 2 Zebra, Zebra | 2026-10-02 | 7.5 High |
| The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Because V5 transaction IDs exclude the scriptSig, a malicious peer can repeatedly serve a canonical block whose coinbase claims height 1 while keeping the requested hash, delaying the node's discovery of the newest block. | ||||
| CVE-2026-104424 | 2 Zcashfoundation, Zfnd | 2 Zebra, Zebra | 2026-10-02 | 3.7 Low |
| Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template selector that omits header and transaction-count size from the block budget. Attackers can place valid selectable transactions in a victim miner's mempool to shape templates into oversized blocks, causing rejection and wasted proof-of-work. | ||||
| CVE-2026-104432 | 2 Zcashfoundation, Zfnd | 2 Zebra, Zebra | 2026-10-02 | 5.3 Medium |
| Zebra before 6.3.0 contains an improper exceptional condition check in ChainSync::obtain_tips that discards valid one-hash FindBlocks responses, falsely reporting close-to-tip status. Peers returning only the next block hash cause a zero-length sync sample, making the /ready endpoint return 200 OK while the node remains behind the tip. | ||||