Export limit exceeded: 30000 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403803 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403803 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-84209 | 1 Ibm | 1 Guardium Data Protection | 2026-10-09 | 8.1 High |
| IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. | ||||
| CVE-2026-18740 | 1 Ibm | 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more | 2026-10-09 | 8.8 High |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to perform unauthorized actions due to argument injection. | ||||
| CVE-2026-11318 | 1 Zuler Technology | 1 Deskin | 2026-10-09 | 7.8 High |
| Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service without authentication. Attackers can invoke the privileged installer method to run an attacker-supplied installer, achieving full root compromise of the macOS host. | ||||
| CVE-2026-107831 | 1 Banq | 1 Jivejdon | 2026-10-09 | 4.3 Medium |
| Jivejdon through 5.0 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing actions by abusing GET endpoints lacking anti-CSRF tokens. Attackers can lure authenticated users to crafted links targeting /account/protected/delAll, /account/protected/sub/delSub, or /message/updateAction to delete private messages and subscriptions or rename threads. | ||||
| CVE-2026-107715 | 1 Sparklemotion | 1 Mechanize | 2026-10-09 | 6.8 Medium |
| The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize sends caller-supplied credential headers to a different host after an HTTP redirect. Mechanize#request_headers= is reapplied by Mechanize::HTTP::Agent#request_add_headers even after Mechanize::HTTP::Agent#response_redirect strips per-request headers, and the protected header lists omit Proxy-Authorization and Cookie2. An attacker who controls a redirect target can capture bearer tokens or session cookies supplied through request_headers= or the per-request headers argument, while Mechanize#cookie_jar and Mechanize::HTTP::AuthStore are not affected. This issue is fixed in version 2.14.1. | ||||
| CVE-2026-105827 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.3 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105826 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.3 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105825 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.3 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105824 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.9 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105823 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 4.0 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105405 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.9 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105404 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.3 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105403 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 6.2 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105402 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.3 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105401 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.3 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-11936 | 1 Ibm | 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more | 2026-10-09 | 4.9 Medium |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 local management interface in certain configurations is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | ||||
| CVE-2026-105400 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 3.3 Low |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105399 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.3 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105398 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.1 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105275 | 1 Satel | 1 Satel Netco Design | 2026-10-09 | 4.3 Medium |
| Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data import functionality. An authenticated user with Viewer privileges could access file paths outside the intended directory and use observable application responses to determine whether files exist on the host system. | ||||