Export limit exceeded: 403622 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403622 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-101149 | 1 Arista | 1 Cloudvision Portal | 2026-10-09 | 4.1 Medium |
| Insufficient validation of OIDC SSO provider configuration could allow a user with specific high privileges to direct requests to arbitrary destinations. | ||||
| CVE-2026-101150 | 1 Arista | 1 Cloudvision Portal | 2026-10-09 | 4.1 Medium |
| Insufficient validation of OIDC bearer token configuration could allow a user with specific high privileges to direct requests to arbitrary destinations. | ||||
| CVE-2026-101151 | 1 Arista | 1 Cloudvision Portal | 2026-10-09 | 4.3 Medium |
| Insufficient validation of request in login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, redirects the user's browser to an arbitrary external site upon completion of the authentication process. | ||||
| CVE-2026-101152 | 1 Arista | 1 Cloudvision Portal | 2026-10-09 | 8 High |
| Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision. | ||||
| CVE-2026-101154 | 1 Arista | 1 Cloudvision Portal | 2026-10-09 | 7.2 High |
| An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Network Provisioning Image Repository. | ||||
| CVE-2026-101155 | 1 Arista | 1 Cloudvision Portal | 2026-10-09 | 9.1 Critical |
| An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Software Management Studio Software Repository. | ||||
| CVE-2026-106445 | 1 Handlebarsjs | 1 Handlebars | 2026-10-09 | N/A |
| Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor is an own property of Function.prototype. When an attacker can render a controlled template with allowProtoMethodsByDefault enabled and an accessible function in the template context, the template can traverse from that function through its prototype to Function.prototype and then obtain the Function constructor through the own-property bypass. This permits attacker-controlled JavaScript to execute with the server application's privileges. This issue is fixed in version 4.7.10. | ||||
| CVE-2026-106446 | 1 Handlebarsjs | 1 Handlebars | 2026-10-09 | 9.8 Critical |
| Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile() accept pre-parsed AST objects while validating only selected PathExpression, NumberLiteral, and BooleanLiteral values. This issue bypasses the AST validation introduced in version 4.7.9 for CVE-2026-33937. An attacker who can supply an object instead of a template string can place JavaScript expressions in unchecked values such as Program.blockParams.length, a non-PathExpression parameter depth, a non-string StringLiteral.value, or a non-string PathExpression.original. The compiler emits those values into generated JavaScript, causing code execution in the server process when compile output renders or wherever precompile output is loaded. Applications that pass only template strings are not affected. This issue is fixed in version 4.7.10. | ||||
| CVE-2026-19029 | 1 Hdfgroup | 1 Hdf5 | 2026-10-09 | N/A |
| A heap-based buffer over-read in H5Z__filter_scaleoffset() in src/H5Zscaleoffset.c in HDF5 through 2.2.0 lets an attacker cause a denial of service (application crash) with a crafted HDF5 file. When the stored minimum bits equal the full precision of the datatype, the decoder copies d_nelmts * size bytes from the compressed chunk without checking that the chunk holds that many bytes. Both values come from attacker-controlled scale-offset filter parameters in the dataset's filter pipeline message. | ||||
| CVE-2026-106550 | 1 Mozilla | 1 Convict | 2026-10-09 | 7.5 High |
| Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete prototype‑pollution protections in config.set(). An attacker controlling the configuration key can write arbitrary properties to constructor.<key>, which walk() resolves to the global Object function. This allows overwriting core JavaScript methods such as Object.assign, leading to persistent process-wide failures and requiring a restart. The issue bypasses existing filters that only block constructor.prototype.* and __proto__.*. Exploitation requires an endpoint that forwards attacker-controlled keys into config.set(). | ||||
| CVE-2026-106547 | 1 Hdfgroup | 1 Hdf5 | 2026-10-09 | N/A |
| A heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c in HDF5 before 2.2.0 lets a remote attacker cause an application crash and possibly execute arbitrary code with a crafted HDF5 file. When a dataset's unallocated chunks are read, H5D__fill_init() fills the fill-value buffer from datatype and dataspace metadata in the file. If that metadata is inconsistent with the buffer's allocated size, the write goes past the end of the buffer. The attacker can control the content written through the fill value stored in the file. | ||||
| CVE-2026-65142 | 1 Nvidia | 1 Nvidia Model Optimizer | 2026-10-09 | 7.8 High |
| NVIDIA Model-Optimizer contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-107121 | 1 Redhat | 4 Build Keycloak, Build Of Keycloak, Red Hat Single Sign On and 1 more | 2026-10-09 | 6.5 Medium |
| A flaw was found in the SMTP email configuration handling of the keycloak-services component. When the STARTTLS option is enabled, Keycloak fails to strictly enforce an encrypted connection, allowing it to fall back to unencrypted communication if the encryption request is tampered with. An attacker who can intercept network traffic can exploit this to capture sensitive email credentials and message content in plain text. | ||||
| CVE-2026-58068 | 1 Veeam | 1 Veeam Agent For Windows | 2026-10-09 | N/A |
| This vulnerability in Veeam Agent for Microsoft Windows allows any local user to terminate arbitrary processes on the system. | ||||
| CVE-2025-64391 | 1 Veeam | 1 Veeam Agent For Windows | 2026-10-09 | N/A |
| This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it. | ||||
| CVE-2026-103416 | 1 Eclipse | 1 Threadx Netx Duo | 2026-10-09 | N/A |
| Out-of-bounds write via the TLS 1.3 handshake message cache in NetX Duo in Eclipse ThreadX NetX Duo 6.5.1.202602 allows a handshake message larger than the cache writes past it and on into the rest of the session control block, which holds pointers. A malicious or compromised server can make a TLS 1.3 client produce such a message before certificate authentication completes, so no server certificate is needed to reach it. | ||||
| CVE-2026-4264 | 1 Beetienda | 1 Ecommerce Platform | 2026-10-09 | N/A |
| Reflected Cross-Site Scripting (XSS) on the BeeTienda e-commerce platform, specifically in the latest demo version. The incident occurs due to a lack of proper sanitization of user input data in the 'search' parameter of the product list endpoint. When malicious payloads are transmitted via the 'search' parameter, they are displayed insecurely in the HTML response, allowing for the arbitrary execution of JavaScript code in the victim's browser. | ||||
| CVE-2025-14123 | 2026-10-09 | 6.8 Medium | ||
| The Redux Framework plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.5.11. This is due to the plugin saving arbitrary meta keys under a registered option name without sufficient capability checks or key allowlist / restrictions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set an arbitrary role (e.g., Administrator) when performing a profile update if a plugin or theme using this framework has added at least one user profile field that leverages Redux_Users::set_profile/set_section/set_field. | ||||
| CVE-2026-87110 | 1 Mongodb | 1 Ops Manager | 2026-10-09 | 5.3 Medium |
| An unauthenticated user with network access to the Ops Manager web port can repeatedly request monitoring endpoints that perform costly work without rate limiting. This can temporarily slow other traffic served by the same process while requests continue. | ||||
| CVE-2026-87109 | 1 Mongodb | 1 Ops Manager | 2026-10-09 | 5.3 Medium |
| An authenticated Ops Manager organization member can retrieve another member's pending authenticator enrollment seed through user-listing endpoints while that member's enrollment is unconfirmed. This results in disclosure of secret authentication material to another member of the same organization or project. | ||||