Export limit exceeded: 403467 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403467 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-102097 | 2 Accellion, Kiteworks | 2 Kiteworks, Kiteworks Email Protection Gateway | 2026-10-08 | 7.2 High |
| Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose contents were not sufficiently validated before being processed. A crafted submission could potentially allow arbitrary commands to be executed on the affected gateway. | ||||
| CVE-2026-102095 | 2 Accellion, Kiteworks | 2 Kiteworks, Kiteworks Email Protection Gateway | 2026-10-08 | 9.1 Critical |
| Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the message content it processed, without adequately restricting the fetch destination. A remote, unauthenticated sender could craft a message that caused the gateway to issue requests to internal services and cloud instance metadata endpoints and return the responses, potentially disclosing sensitive internal data and, depending on the internal service reached, affecting its state. | ||||
| CVE-2026-102094 | 2 Accellion, Kiteworks | 2 Kiteworks, Kiteworks Email Protection Gateway | 2026-10-08 | 7.2 High |
| Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not sufficiently restrict the code that the mail-processing pipeline could load from an imported rule configuration. An authenticated administrator with mail-rule configuration privileges could cause the gateway to load and execute code beyond the approved set of mail-processing components, potentially in the context of the mail-gateway service account. | ||||
| CVE-2026-102091 | 2 Accellion, Kiteworks | 2 Kiteworks, Secure Data Forms | 2026-10-08 | 7.5 High |
| Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other network-restricted resources. | ||||
| CVE-2026-102089 | 2 Accellion, Kiteworks | 2 Kiteworks, Kiteworks Email Protection Gateway | 2026-10-08 | 7.2 High |
| Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system. | ||||
| CVE-2026-107570 | 1 Mutt | 1 Mutt | 2026-10-08 | 2.5 Low |
| heap OOB write in convert_file_from_to() via a crafted Content-Type header allows attacker to OOB write when email is used as a template. | ||||
| CVE-2026-102322 | 1 Google | 1 Chrome | 2026-10-08 | 9.6 Critical |
| Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-87681 | 1 Brocade | 1 Fabric Os | 2026-10-08 | N/A |
| An Access Control Bypass vulnerability exists in the Role-Based Access Control (RBAC) validation engine of Brocade Fabric OS versions before 10.0.1. When processing certain management protocol operations, the RBAC engine incorrectly categorizes non-standard action opcodes during permission checks. This allows authenticated users with read-only management privileges to bypass access controls and execute restricted administrative operations. | ||||
| CVE-2026-17637 | 2 Ibm, Redhat | 4 Financial Transaction Manager, Financial Transaction Manager (ftm) for Redhat Openshift, Financial Transaction Manager Ftmfor Redhat Openshift and 1 more | 2026-10-08 | 8.8 High |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data. | ||||
| CVE-2026-106016 | 1 Mozilla | 1 Firefox | 2026-10-08 | 9.8 Critical |
| Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 157.0.1. | ||||
| CVE-2026-17643 | 2 Ibm, Redhat | 4 Financial Transaction Manager, Financial Transaction Manager (ftm) for Redhat Openshift, Financial Transaction Manager Ftmfor Redhat Openshift and 1 more | 2026-10-08 | 8.8 High |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and perform unauthorized actions due to insufficiently protected credentials. | ||||
| CVE-2026-76268 | 1 Splunk | 1 Splunk Enterprise | 2026-10-08 | 9.8 Critical |
| In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker-controlled operating-system commands. The vulnerability is possible because this interface does not require authentication for critical configuration operations. For more information see Sidecar configuration settings (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/splunk-sidecars/sidecar-configuration-settings) in the Splunk documentation. Splunk Enterprise versions 10.0.x and 9.4.x are not affected. | ||||
| CVE-2026-83430 | 1 Oracle | 2 E-business Suite, Product Workbench | 2026-10-08 | 8.1 High |
| Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Workbench accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Workbench accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). | ||||
| CVE-2026-83431 | 1 Oracle | 2 E-business Suite, Product Workbench | 2026-10-08 | 5.4 Medium |
| Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: WebUI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Product Workbench, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Product Workbench accessible data as well as unauthorized read access to a subset of Oracle Product Workbench accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N). | ||||
| CVE-2026-83434 | 1 Oracle | 2 E-business Suite, Product Workbench | 2026-10-08 | 8.1 High |
| Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Workbench accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Workbench accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). | ||||
| CVE-2026-76273 | 1 Splunk | 1 Splunk Enterprise | 2026-10-08 | 4.3 Medium |
| In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the run_collect capability could use the collect Search Processing Language (SPL) command to add attacker-controlled content to system-level messages on the Splunk platform instance. The vulnerability is possible because the collect command does not validate the index name before processing the value. For more information see collect (https://help.splunk.com/en/splunk-enterprise/search/spl-search-reference/10.4/search-commands/collect), Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities), and System endpoint descriptions (https://help.splunk.com/en/splunk-enterprise/rest-api-reference/10.4/system-endpoints/system-endpoint-descriptions) in the Splunk documentation. | ||||
| CVE-2026-17644 | 2 Ibm, Redhat | 4 Financial Transaction Manager, Financial Transaction Manager (ftm) for Redhat Openshift, Financial Transaction Manager Ftmfor Redhat Openshift and 1 more | 2026-10-08 | 8.8 High |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials. | ||||
| CVE-2026-76278 | 1 Splunk | 1 Splunk Enterprise | 2026-10-08 | 4.3 Medium |
| In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the edit_spl2_module_permissions capability could use the affected Representational State Transfer (REST) API to access permission grants for SPL2 modules that the user does not have permission to view. The vulnerability is possible because Splunk Enterprise does not verify that the user can read the requested app before the affected REST API returns SPL2 module permission grants. For more information see Module permissions (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/modules-statements-and-views/module-permissions) and Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modules) in the Splunk documentation. Splunk Enterprise versions 9.4.x are not affected. | ||||
| CVE-2026-106189 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-10-08 | 7.3 High |
| Code injection in ReaderMode in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-15822 | 1 Ibm | 4 Datapower Gateway 1050, Datapower Gateway 1060, Datapower Gateway 106cd and 1 more | 2026-10-08 | 7.5 High |
| IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to improper memoization of GraphQL fragment spreads. | ||||