Export limit exceeded: 404138 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 404138 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404138 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-98253 | 1 Linux | 1 Linux Kernel | 2026-10-09 | 7.8 High |
| In the Linux kernel, the following vulnerability has been resolved: RDMA/ucma: Serialize join and leave on copy_to_user failure rdma_join_multicast() queues RoCE work that later reads the ucma_multicast through event->param.ud.private_data, then list_add()s the CMA multicast at the head of id_priv->mc_list. rdma_leave_multicast() matches only by sockaddr and destroys the first hit. ucma_process_join() used to drop ctx->mutex after a successful join and retake it only if copy_to_user() failed. Two concurrent JOIN_MCAST calls with the same address can therefore insert a second CMA entry before the first thread's leave. leave then cancels the newer work and the older worker still dereferences the ucma_multicast that the first thread frees. Keep ctx->mutex held from rdma_join_multicast() through copy_to_user() and, on -EFAULT, through rdma_leave_multicast() so leave cannot miss this join. Do not leave if join itself failed: that path never published this address on mc_list, and a leave-by-addr would destroy an earlier successful join. | ||||
| CVE-2026-20535 | 2 Mediatek, Mediatek, Inc. | 25 Mt6878, Mt6878 Firmware, Mt6881 and 22 more | 2026-10-09 | 6.7 Medium |
| In aidl, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11185216; Issue ID: MSV-9039. | ||||
| CVE-2026-20536 | 2 Mediatek, Mediatek, Inc. | 27 Mt6878, Mt6878 Firmware, Mt6881 and 24 more | 2026-10-09 | 6.7 Medium |
| In aidl, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11242428; Issue ID: MSV-9038. | ||||
| CVE-2026-106405 | 1 Google | 2 Android, Chrome | 2026-10-09 | 6 Medium |
| Race condition in CustomTabs in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Medium) | ||||
| CVE-2026-106407 | 1 Google | 1 Chrome | 2026-10-09 | 6.5 Medium |
| Incorrect authorization in GetUserMedia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106408 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-10-09 | 6.5 Medium |
| Protection mechanism failure in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-78406 | 1 Ibm | 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more | 2026-10-09 | 9.8 Critical |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data. | ||||
| CVE-2026-19498 | 1 Ibm | 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more | 2026-10-09 | 5.9 Medium |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to cause a denial of service due to uncontrolled recursion. | ||||
| CVE-2026-102490 | 3 Docker, Linux, Zammad | 3 Docker, Linux Kernel, Zammad | 2026-10-09 | 7.8 High |
| Zammad packages built with packager.io (DEB and RPM) could have allowed a local attacker who already had file system write privileges as the unprivileged zammad service account to escalate to full root privileges on the host. Service processes began running as root and executed files that were owned and writable by the zammad account before dropping their identity to that account. An attacker holding that foothold could have escalated within seconds, because the affected services were restarted automatically whenever they stopped; no administrator interaction was required. Only installations from the DEB and RPM packages were affected — installations from source or the official container images were not. All released packaged versions were affected. | ||||
| CVE-2026-84209 | 1 Ibm | 1 Guardium Data Protection | 2026-10-09 | 8.1 High |
| IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. | ||||
| CVE-2026-18740 | 1 Ibm | 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more | 2026-10-09 | 8.8 High |
| IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to perform unauthorized actions due to argument injection. | ||||
| CVE-2026-11318 | 1 Zuler Technology | 1 Deskin | 2026-10-09 | 7.8 High |
| Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service without authentication. Attackers can invoke the privileged installer method to run an attacker-supplied installer, achieving full root compromise of the macOS host. | ||||
| CVE-2026-107831 | 1 Banq | 1 Jivejdon | 2026-10-09 | 4.3 Medium |
| Jivejdon through 5.0 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing actions by abusing GET endpoints lacking anti-CSRF tokens. Attackers can lure authenticated users to crafted links targeting /account/protected/delAll, /account/protected/sub/delSub, or /message/updateAction to delete private messages and subscriptions or rename threads. | ||||
| CVE-2026-107715 | 1 Sparklemotion | 1 Mechanize | 2026-10-09 | 6.8 Medium |
| The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize sends caller-supplied credential headers to a different host after an HTTP redirect. Mechanize#request_headers= is reapplied by Mechanize::HTTP::Agent#request_add_headers even after Mechanize::HTTP::Agent#response_redirect strips per-request headers, and the protected header lists omit Proxy-Authorization and Cookie2. An attacker who controls a redirect target can capture bearer tokens or session cookies supplied through request_headers= or the per-request headers argument, while Mechanize#cookie_jar and Mechanize::HTTP::AuthStore are not affected. This issue is fixed in version 2.14.1. | ||||
| CVE-2026-105827 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.3 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105826 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.3 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105825 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.3 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105824 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.9 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105823 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 4.0 Medium |
| This CVE ID has been rejected as a duplicate. | ||||
| CVE-2026-105405 | 1 Imagemagick | 1 Imagemagick | 2026-10-09 | 5.9 Medium |
| This CVE ID has been rejected as a duplicate. | ||||