Export limit exceeded: 401483 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 401483 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (401483 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-84311 | 2 Py-pdf, Pypdf Project | 2 Pypdf, Pypdf | 2026-10-05 | 3.3 Low |
| pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of reused form XObjects in which each form invokes a child multiple times, creating exponentially many traversal paths and causing long runtimes and large memory consumption. This issue is fixed in version 6.16.1. | ||||
| CVE-2026-84310 | 2 Py-pdf, Pypdf Project | 2 Pypdf, Pypdf | 2026-10-05 | 3.3 Low |
| pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines with large numbers of entries or deeply nested reused paths because the traversal lacked global entry-count and nesting-depth limits. This issue is fixed in version 6.16.1. | ||||
| CVE-2026-84309 | 2 Py-pdf, Pypdf Project | 2 Pypdf, Pypdf | 2026-10-05 | 5.5 Medium |
| pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a writing code path inserts a child, producing an infinite loop. This issue is fixed in version 6.16.0. | ||||
| CVE-2026-93316 | 2026-10-05 | N/A | ||
| If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident. | ||||
| CVE-2026-82398 | 2 Py-pdf, Pypdf Project | 2 Pypdf, Pypdf | 2026-10-05 | 5.3 Medium |
| pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without whitespace. The function repeatedly performs immutable bytes concatenation in a one-byte loop, causing quadratic processing cost for the long non-whitespace input. This issue is fixed in version 6.15.0. | ||||
| CVE-2026-71870 | 2 Py-pdf, Pypdf Project | 2 Pypdf, Pypdf | 2026-10-05 | 3.3 Low |
| pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a font /ToUnicode CMap during text extraction. This issue is fixed in 6.15.0. | ||||
| CVE-2026-73637 | 2 Apache, Redhat | 3 Apache Http Server, Http Server, Hummingbird | 2026-10-05 | 7.3 High |
| Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue. | ||||
| CVE-2026-79768 | 2 Apache, Redhat | 2 Http Server, Hummingbird | 2026-10-05 | 5.3 Medium |
| Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | ||||
| CVE-2026-101919 | 1 Redhat | 1 Multicluster Engine | 2026-10-05 | 8.8 High |
| A flaw was found in the HyperShift operator. The operator copies user-provided Kubernetes configuration (kubeconfig) secrets directly into the privileged control plane namespace without proper validation or sanitization. An authenticated user with cluster and secret creation permissions can exploit this vulnerability by supplying a configuration containing unauthorized executable plugins. When downstream controllers consume this configuration, an attacker can achieve arbitrary code execution within the control plane. | ||||
| CVE-2026-92046 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-10-05 | 8.8 High |
| Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | ||||
| CVE-2026-71852 | 2 Py-pdf, Pypdf Project | 2 Pypdf, Pypdf | 2026-10-05 | 3.3 Low |
| pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large CID font /W width ranges or excessive width entries during text extraction. This issue is fixed in 6.15.0. | ||||
| CVE-2026-37719 | 2026-10-05 | N/A | ||
| An issue in dormakaba evolo Service (all versions) allows a remote attacker to execute arbitrary code as SYSTEM via a .NET component. | ||||
| CVE-2026-104892 | 1 Makeplane | 1 Plane | 2026-10-05 | N/A |
| Plane is an open-source project management tool. Prior to 1.4.0, aPITokenLogMiddleware logs API keys in plaintext. This allows someone with low privileges to steal user API keys and further escalate their privileges. This issue is fixed in 1.4.0. | ||||
| CVE-2026-102428 | 1 Ordasoft.com | 1 Ordasoft Joomla Cck | 2026-10-05 | N/A |
| Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 - The order column for records was user provided and not properly validated, leading to a SQL injection vector. | ||||
| CVE-2026-102776 | 1 Svenbluege.de | 1 Event Gallery For Joomla | 2026-10-05 | N/A |
| Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks of the backend in Event Gallery extension < 6.6.0 - Eight tasks which the buttons of the back-end lists call did not check the form token: setting the default payment method, shipping method, image type set, order status and watermark; putting an event into the shop or taking it out; choosing the main image of an event and whether an image is shown only as the main image; and sorting the images of an event. A prepared page on another web site could trigger them in the name of a logged in administrator and change those settings and flags. Nothing can be deleted or read this way; orders are not affected. | ||||
| CVE-2026-102777 | 1 Svenbluege.de | 1 Event Gallery For Joomla | 2026-10-05 | N/A |
| Joomla Extension - svenbluege.de - Server-side request forgery in the Google Photos picker in Event Gallery extension < 6.6.0 - The Google Photos picker of the back-end upload page fetches the thumbnails of the picked images through the server, with the OAuth access token of the Google Photos account. The task took the address to fetch from the request without checking it and asked for no form token. A prepared page on another web site could therefore make the server send the access token of the account to any address, or fetch addresses inside the server's network, in the name of a logged in administrator; a back-end user with the permission "Manage" could do the same directly. The token is valid for about an hour and reaches what the picker session of the account reaches. | ||||
| CVE-2025-15643 | 2026-10-05 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Fernandez Adsmonetizer adsensei-b30 allows Reflected XSS.This issue affects Adsmonetizer: from n/a through 3.2.4. | ||||
| CVE-2026-57099 | 1 Microsoft | 3 .asp.netcore, .asp.netcore, Asp.net Core Odata | 2026-10-05 | 7.5 High |
| Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-56599 | 1 Hcltech | 1 Bigfix Service Management | 2026-10-05 | 2.2 Low |
| HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to exploit missing security attributes such as SameSite, HttpOnly, Secure, and restrictive Paths, enabling Cross-Site Request Forgery (CSRF), session hijacking via Cross-Site Scripting (XSS), and unauthorized access. | ||||
| CVE-2026-56589 | 1 Hcltech | 1 Bigfix Service Management | 2026-10-05 | 7.2 High |
| HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within the application that execute when a victim views the affected page, enabling session hijacking and the theft of sensitive data. | ||||