Export limit exceeded: 383343 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (383343 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-20520 | 1 Mediatek | 1 Mediatek Chipset | 2026-10-05 | 7.5 High |
| In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778988; Issue ID: MSV-8897. | ||||
| CVE-2026-20522 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 8.4 High |
| In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249050; Issue ID: MSV-9172. | ||||
| CVE-2026-20523 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 8.4 High |
| In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249062; Issue ID: MSV-9171. | ||||
| CVE-2026-63267 | 1 The Document Foundation | 1 Libreoffice | 2026-10-05 | N/A |
| LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make a request to a host of the document's choosing. In fixed versions external data links are updated under the same link update control as other links in a spreadsheet. | ||||
| CVE-2026-94669 | 2026-10-05 | 5.3 Medium | ||
| Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13. | ||||
| CVE-2026-59788 | 1 Zabbix | 1 Zabbix | 2026-10-05 | N/A |
| The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in the browser. This means a crafted media type configuration, deliverable as an import file, runs arbitrary JavaScript as the Super Admin who grants consent. | ||||
| CVE-2026-59787 | 1 Zabbix | 1 Zabbix | 2026-10-05 | N/A |
| The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity. | ||||
| CVE-2026-59786 | 1 Zabbix | 1 Zabbix | 2026-10-05 | N/A |
| Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity. | ||||
| CVE-2026-59785 | 1 Zabbix | 1 Zabbix | 2026-10-05 | N/A |
| Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them uncover it. | ||||
| CVE-2026-59783 | 1 Zabbix | 1 Zabbix | 2026-10-05 | N/A |
| The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database. | ||||
| CVE-2026-59782 | 1 Zabbix | 1 Zabbix | 2026-10-05 | N/A |
| The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator. | ||||
| CVE-2026-105287 | 1 Feelec-yishu | 1 Feelcrm-os | 2026-10-05 | 6.3 Medium |
| A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpoint. This manipulation of the argument groups[] causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2025-58222 | 1 Wordpress | 1 Wordpress | 2026-10-05 | 5.3 Medium |
| Missing Authorization vulnerability in Dynamic Web Lab Team Manager wp-team-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team Manager: from n/a through 2.6.8. | ||||
| CVE-2026-19395 | 1 Qt | 1 Qt For Mcus | 2026-10-05 | N/A |
| In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty values. The check fails and reports an error, and the default error handler halts the device. | ||||
| CVE-2026-20541 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 5.3 Medium |
| In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8911. | ||||
| CVE-2026-20543 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-10-05 | 5.5 Medium |
| In Modem, there is a possible information disclosure due to a logic error. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01645293; Issue ID: MSV-6761. | ||||
| CVE-2026-39783 | 2026-10-05 | 4.3 Medium | ||
| Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a through 3.8.7. | ||||
| CVE-2026-103684 | 2026-10-05 | 5.3 Medium | ||
| Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through 4.1.25. | ||||
| CVE-2026-105073 | 2026-10-05 | 5.3 Medium | ||
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Arraytics WP Event Solution wp-event-solution allows Retrieve Embedded Sensitive Data.This issue affects WP Event Solution: from n/a through 4.1.25. | ||||
| CVE-2026-63270 | 2026-10-05 | N/A | ||
| URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-12426 did not cover every place a document can supply a URL. XForms instance data and the Calc csv and sql data providers still reached the expansion. In fixed versions these places refuse URLs with internal schemes when the URL comes from the document. | ||||