Export limit exceeded: 400886 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400886 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400886 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104425 | 2 Zcashfoundation, Zfnd | 2 Zebra, Zebra | 2026-10-02 | 5.3 Medium |
| ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block processing by pushing transactions with invalid Orchard proofs without being misbehavior-scored. Attackers can repeatedly push invalid proofs into the shared halo2 batch verifier, forcing honest block proofs onto the slow individual-verification path and slowing block processing roughly sevenfold. | ||||
| CVE-2026-104427 | 2 Zcashfoundation, Zfnd | 2 Zebra, Zebra | 2026-10-02 | 5.9 Medium |
| Zebra before 6.1.0 contains an incomplete cleanup vulnerability in the state write task that allows remote unauthenticated peers to stall node synchronization by poisoning parent_error_map. Attackers can deliver a coinbase-malleated block sharing a canonical block's hash before it propagates, causing the next canonical block to be rejected and stalling the node for roughly 2,000 blocks. | ||||
| CVE-2026-104428 | 2 Zcashfoundation, Zfnd | 2 Zebra, Zebra | 2026-10-02 | 5.3 Medium |
| The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation's Zebra node, panics on verbosity 2 for a side-chain block because the block's -1 confirmations sentinel is converted to u32 with .expect(), aborting the process. Remote unauthenticated attackers, directly or through lightwalletd, can repeat this call to keep the node in a crash loop. | ||||
| CVE-2026-95360 | 1 Google | 1 Chrome | 2026-10-02 | 5.3 Medium |
| Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-95361 | 1 Google | 1 Chrome | 2026-10-02 | 4.3 Medium |
| Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-95363 | 1 Google | 1 Chrome | 2026-10-02 | 5.4 Medium |
| UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-104733 | 2026-10-02 | N/A | ||
| User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism. | ||||
| CVE-2026-104434 | 2 Zcashfoundation, Zfnd | 2 Zebra, Zebra | 2026-10-02 | 6.5 Medium |
| ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort the zebrad process, repeatably keeping the node offline. | ||||
| CVE-2026-104435 | 2 Zcashfoundation, Zfnd | 2 Zebra, Zebra | 2026-10-02 | 7.4 High |
| Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network consensus split. | ||||
| CVE-2026-19652 | 2026-10-02 | 9.8 Critical | ||
| The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowed roles. This makes it possible for unauthenticated attackers to register a new account with the administrator role by submitting a locally computed bcrypt hash of `administrator` as `form_id`, and when `auto_login=on` is submitted, be immediately authenticated as that administrator in the same request, resulting in full site takeover. Exploitation requires a WordPress nonce, but that nonce is publicly emitted on any page rendering the Divi Membership registration form and is therefore obtainable by any unauthenticated visitor. | ||||
| CVE-2026-7064 | 1 Agentdeskai | 1 Browser-tools-mcp | 2026-10-02 | 7.3 High |
| A flaw has been found in AgentDeskAI browser-tools-mcp up to 1.2.0. This issue affects some unknown processing of the file browser-tools-server/browser-connector.ts. Executing a manipulation can lead to os command injection. The attack may be performed from remote. The exploit has been published and may be used. Upgrading to version 2.0.0 is capable of addressing this issue. It is recommended to upgrade the affected component. | ||||
| CVE-2026-104721 | 2026-10-02 | N/A | ||
| Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory. This issue affects Logback-classic: from 0.9.14 through 1.6.4. This vulnerability is similar to CVE-2026-19880 but involves other attack techniques. | ||||
| CVE-2026-95372 | 1 Google | 1 Chrome | 2026-10-02 | 8.3 High |
| Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-95373 | 1 Google | 1 Chrome | 2026-10-02 | 8.8 High |
| Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-96289 | 2026-10-02 | N/A | ||
| Uncontrolled Recursion vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | ||||
| CVE-2026-95385 | 1 Google | 1 Chrome | 2026-10-02 | 6.5 Medium |
| Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-95326 | 1 Google | 1 Chrome | 2026-10-02 | 8.4 High |
| Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-95285 | 1 Google | 1 Chrome | 2026-10-02 | 8.4 High |
| Missing authorization in WebView in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-95278 | 1 Google | 1 Chrome | 2026-10-02 | 8.4 High |
| Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-86035 | 1 Weblate | 1 Weblate | 2026-10-02 | 8.5 High |
| Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with - could be interpreted as Mercurial options instead of literal paths. An authenticated user with project-scoped component.edit permission could exploit this through a Mercurial-backed RESX component using the Update RESX files add-on. A later repository update could execute arbitrary commands with the privileges of the Weblate service account. This is a residual incomplete fix for CVE-2022-23915. This issue has been patched in version 2026.8. | ||||