Export limit exceeded: 380204 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (380204 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-68517 1 Nicolargo 1 Glances 2026-08-18 6.5 Medium
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list containing the wildcard to retain cors_credentials and expose authenticated REST API data to an untrusted website visited by a previously authenticated user. This issue is fixed in 4.5.6.
CVE-2026-66792 1 Redhat 4 Acm, Multicluster Globalhub, Openshift and 1 more 2026-08-18 9.9 Critical
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to unauthorized access and control over cluster resources.
CVE-2026-66667 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions.
CVE-2026-66645 2026-08-18 6.5 Medium
Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
CVE-2026-66643 2026-08-18 6.5 Medium
Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.
CVE-2026-66641 2026-08-18 6.5 Medium
Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions.
CVE-2026-66639 2026-08-18 6.5 Medium
Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions.
CVE-2026-66636 2026-08-18 6.5 Medium
Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.
CVE-2026-66634 2026-08-18 4.3 Medium
Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.
CVE-2026-66621 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions.
CVE-2026-65974 1 Frappe 1 Erpnext 2026-08-18 9.9 Critical
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forcing restrict_globals, allowing server-side template injection and remote code execution. This issue is fixed in versions 15.111.0 and 16.22.0.
CVE-2026-64865 1 Quantumnous 1 New-api 2026-08-18 N/A
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_modules can race relay billing because controller/user.go calls User.Update and updateUserCache performs a full RedisHSetObj write to user:.Quota, overwriting concurrent HINCRBY deductions and allowing an authenticated user to keep cached quota artificially high. This issue is fixed in version 1.0.0-rc.16.
CVE-2026-59909 1 Dell 1 Objectscale 2026-08-18 7.1 High
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
CVE-2026-59902 1 Netty 1 Netty 2026-08-18 7.5 High
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing unauthenticated peers to exhaust memory with large SCTP fragments. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.
CVE-2026-56090 1 Dell 1 Objectscale 2026-08-18 7.3 High
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
CVE-2026-55674 1 Discourse 1 Discourse 2026-08-18 9.3 Critical
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id (or dark_scheme_id) cookie to inject arbitrary HTML into a Discourse page. Because the cookie value was rendered into a color scheme tag without escaping, the attacker could break out of the attribute and inject a tag that bypassed Discourse's nonce-based Content Security Policy, resulting in arbitrary JavaScript execution in visitors' browsers. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
CVE-2026-40506 1 Openemr 1 Openemr 2026-08-18 6.5 Medium
OpenEMR before 8.2.0 contains a path traversal vulnerability in the standard_tables_manage.php interface where the db GET parameter is passed without validation to temp_dir_cleanup(), which joins the value to the PHP temporary directory path and recursively deletes the resulting directory. Attackers can supply a traversal sequence in the db parameter to resolve outside the intended temporary directory, and by chaining this with an open redirect in dicom_frame.php, an unauthenticated attacker can deliver a crafted URL that triggers arbitrary recursive directory deletion within an authenticated Superuser's session.
CVE-2026-32468 2026-08-18 7.5 High
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
CVE-2026-32463 2026-08-18 9.9 Critical
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
CVE-2026-28569 2026-08-18 7.1 High
Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.