Export limit exceeded: 366860 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 366860 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (366860 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-58301 | 1 Apache | 1 Shiro | 2026-08-31 | N/A |
| When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate a connection to an attacker-controlled URL and transmit attacker-controlled data. This vulnerability affects Apache Shiro versions 2.x through 3.0.0 only in deployments that use the Jakarta EE integration module. Mitigation: Upgrade to version 3.0.1 or later, which fixes the issue. + Alternatively, you can set the `org.apache.shiro.form-resubmit-host` (String) and `org.apache.shiro.form-resubmit-port` (Integer) system properties to restrict the host and port that Shiro will connect to when resubmitting a form. | ||||
| CVE-2026-52491 | 1 Libtiff | 1 Libtiff | 2026-08-31 | 8.4 High |
| An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component | ||||
| CVE-2026-38343 | 1 Ffmpeg | 1 Ffmpeg | 2026-08-31 | 6.5 Medium |
| An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file. | ||||
| CVE-2026-51672 | 1 Totolink | 1 T6 | 2026-08-31 | N/A |
| Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain the roaming enablement flag via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||||
| CVE-2026-51673 | 1 Totolink | 1 T6 | 2026-08-31 | N/A |
| Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter time synchronization settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||||
| CVE-2026-51675 | 1 Totolink | 1 T6 | 2026-08-31 | N/A |
| Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||||
| CVE-2026-71217 | 2 Iperf3 Project, Redhat | 2 Iperf3, Enterprise Linux | 2026-08-31 | 7.5 High |
| A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can result in a Denial of Service (DoS) on the affected iperf3 server. | ||||
| CVE-2026-82807 | 1 Ieungsoft | 1 Ultra Ramdisk Pro | 2026-08-31 | 8.8 High |
| A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown processing in the library URDSCSI.sys of the component Kernel Driver. This manipulation causes improper privilege management. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-78986 | 1 Google | 1 Chrome | 2026-08-31 | 3.1 Low |
| Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-79007 | 1 Google | 1 Chrome | 2026-08-31 | 3.1 Low |
| Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-51678 | 1 Totolink | 1 T6 | 2026-08-31 | N/A |
| Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter logging behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||||
| CVE-2026-51683 | 1 Totolink | 1 T6 | 2026-08-31 | N/A |
| Incorrect access control in the setLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter LAN network configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||||
| CVE-2026-51684 | 1 Totolink | 1 T6 | 2026-08-31 | N/A |
| Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the storage-related service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||||
| CVE-2026-51688 | 1 Totolink | 1 T6 | 2026-08-31 | N/A |
| Incorrect access control in the setWiFiSignalCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reduce wireless power or cause a Denial of Service (DoS) via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||||
| CVE-2026-51674 | 1 Totolink | 1 T6 | 2026-08-31 | N/A |
| Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced reboot tasks via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||||
| CVE-2026-51677 | 1 Totolink | 1 T6 | 2026-08-31 | N/A |
| Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change UPnP service state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||||
| CVE-2026-73125 | 1 Ebyte | 1 Ebyte Ne2-d11 Firmware | 2026-08-31 | 9.8 Critical |
| Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, modify device settings, or disrupt availability. | ||||
| CVE-2026-74872 | 1 Jahlives | 1 Openssl Encrypt | 2026-08-31 | 9.8 Critical |
| openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded. | ||||
| CVE-2026-74877 | 1 Jahlives | 1 Openssl Encrypt | 2026-08-31 | 8.8 High |
| openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a valid ML-DSA signature, bypassing the intended ownership restriction. | ||||
| CVE-2026-76179 | 1 Ebyte | 1 Ebyte Ne2-d11 Firmware | 2026-08-31 | 9.8 Critical |
| An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed session information to obtain and reuse a valid token. Successful exploitation could allow an attacker to impersonate an authenticated user and gain unauthorized access to device management functionality. | ||||