Export limit exceeded: 368529 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (368529 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-11873 | 1 Redhat | 3 Certificate System, Dogtag Certificate System, Enterprise Linux | 2026-09-04 | 6.5 Medium |
| An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating a log-amplification resource exhaustion vector (disk growth and I/O contention) without requiring authentication. | ||||
| CVE-2026-53682 | 1 Redhat | 3 Certificate System, Dogtag Certificate System, Enterprise Linux | 2026-09-04 | 5.3 Medium |
| An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal, client certificate, or session. | ||||
| CVE-2026-85178 | 1 Helicone | 1 Helicone | 2026-09-04 | 7.7 High |
| Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier. Attackers with admin or owner privileges in any organization can retrieve decrypted upstream provider credentials for other tenants, including plaintext OpenAI, Anthropic, and Bedrock API keys. | ||||
| CVE-2026-75036 | 1 Suse | 1 Fleet | 2026-09-04 | N/A |
| A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repository referenced by a `GitRepo` resource can cause the Fleet controller to: - Disclose cluster metadata available to the templating context. - Reveal information about hosts reachable from the controller's network position. Because the disclosure channel is name resolution, it may remain effective in environments where outbound traffic is otherwise restricted. The disclosed information is limited to values exposed to the Fleet templating context and to name resolution results. Integrity and availability of managed clusters are not affected. This issue affects Fleet: from 0.12.0 before 0.12.19, from 0.13.0 before 0.13.15, from 0.14.0 before 0.14.10, from 0.15.0 before 0.15.6, and from 0.16.0 before 0.16.1. | ||||
| CVE-2026-82525 | 1 Exterro | 1 Ftk Imager | 2026-09-04 | 5.5 Medium |
| Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedding malicious external entity references and attacker-controlled XSLT stylesheets within a Report.xml file inside a UFDR ZIP evidence item. Attackers can craft a malicious UFDR archive that, when previewed by an examiner, causes the XML parser to resolve file:// external entity references and execute msxsl:script within the external stylesheet to exfiltrate the resolved file contents to an attacker-controlled endpoint via a generated image URL. | ||||
| CVE-2026-55658 | 1 1hive | 1 Gardens-v2 | 2026-09-04 | 7.7 High |
| Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In 3e595f3 and prior, when a streaming proposal is funded, the cluster of streaming contracts moves real pool funds into the proposal's StreamingEscrow to back the Superfluid constant flow agreement (the CFA deposit, plus a 0.5 percent margin). cancelProposal then zeroes the escrow's GDA member units but never reclaims that parked balance, and the permissionless claim() forwards the escrow's entire balance, including the pool funded buffer, to the beneficiary. The beneficiary is chosen by the proposal submitter and defaults to the submitter. The only path that returns escrow funds to the pool is drainToStrategy, which is onlyStrategy and is reached solely from the dispute reject ruling, never from cancel or natural completion. At time of publication, there are no publicly known patches. | ||||
| CVE-2026-57445 | 1 1hive | 1 Gardens-v2 | 2026-09-04 | N/A |
| Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In dfba919e218e20d52db9f7b2e8d292d45a46c91b and prior, normal beneficiary payout paths in StreamingEscrow preserve depositAmount() while an active stream needs an escrow reserve. However, the approve-side dispute resolution path drains the whole available escrow balance to the proposal beneficiary. At time of publication, there are no publicly known patches. | ||||
| CVE-2026-53720 | 1 Jetperch | 1 Pymonocypher | 2026-09-04 | N/A |
| pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does not check the nb_blocks size. If the caller does not provide a sufficiently large buffer based on the API contract, then argon2i_32 will write past the end of the buffer and possibly corrupt the heap. This issue has been patched in version 4.0.2.8. | ||||
| CVE-2026-81281 | 2 Silverks, Wordpress | 2 Graphene, Wordpress | 2026-09-04 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions. | ||||
| CVE-2026-81282 | 2 Villatheme, Wordpress | 2 Product Variations Swatches For Woocommerce, Wordpress | 2026-09-04 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions. | ||||
| CVE-2026-81292 | 2 Ido Kobelkowsky, Wordpress | 2 Simple Payment, Wordpress | 2026-09-04 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions. | ||||
| CVE-2026-81300 | 2 Silverplugins217, Wordpress | 2 Calculation For Contact Form 7, Wordpress | 2026-09-04 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions. | ||||
| CVE-2026-81776 | 2 Advanpix, Wordpress | 2 Wp Quicklatex, Wordpress | 2026-09-04 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions. | ||||
| CVE-2026-84238 | 2 Wordpress, Yith | 2 Wordpress, Yith Request A Quote For Woocommerce Premium | 2026-09-04 | 9.8 Critical |
| Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions. | ||||
| CVE-2026-84765 | 2 John Havlik, Wordpress | 2 Breadcrumb Navxt, Wordpress | 2026-09-04 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions. | ||||
| CVE-2026-84767 | 2 Nexcess, Wordpress | 2 Bookit, Wordpress | 2026-09-04 | 5.3 Medium |
| Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions. | ||||
| CVE-2026-84773 | 2 Wordpress, 作者 | 2 Wordpress, Shane Bishop:ewww Image Optimizer | 2026-09-04 | 7.2 High |
| Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions. | ||||
| CVE-2026-84776 | 2 Malcare, Wordpress | 2 Malcare Security, Wordpress | 2026-09-04 | 7.5 High |
| Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions. | ||||
| CVE-2026-84778 | 2 Migrateguru, Wordpress | 2 Migrate Guru – Site Migration & Cloning, Wordpress | 2026-09-04 | 7.5 High |
| Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration & Cloning <= 6.65 versions. | ||||
| CVE-2026-84779 | 2 Sheikh Heera, Wordpress | 2 Agentimus – Ai Seo, Llms.txt & Mcp For Ai Agents, Wordpress | 2026-09-04 | 8.1 High |
| Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt & MCP for AI Agents <= 1.51.0 versions. | ||||