Export limit exceeded: 396868 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (396868 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-93307 | 1 O-ran-sc | 1 Smo Oam | 2026-09-23 | 4.3 Medium |
| A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector. Such manipulation of the argument additionalFields.padding leads to uncontrolled memory allocation. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through a bug report but has not responded yet. | ||||
| CVE-2026-91775 | 1 Limesurvey | 1 Limesurvey | 2026-09-23 | N/A |
| LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface. | ||||
| CVE-2026-88832 | 1 Redhat | 1 Hummingbird | 2026-09-23 | 7.3 High |
| BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images. | ||||
| CVE-2026-19267 | 1 Ibm | 1 Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-23 | 6.2 Medium |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions. | ||||
| CVE-2026-78579 | 1 Okta | 1 Access Gateway | 2026-09-23 | 6.8 Medium |
| The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP datastore configuration. The raw values are substituted directly into the filter string and passed to the LDAP search operation, resulting in modification of the intended query logic. | ||||
| CVE-2026-18505 | 1 Ibm | 1 Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-23 | 5.4 Medium |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated `Host` header to redirect authenticated operators to attacker-controlled sites, enabling credential phishing. | ||||
| CVE-2026-18180 | 1 Ibm | 1 Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-23 | 6.5 Medium |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to SQL injection. | ||||
| CVE-2026-93618 | 2026-09-23 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetTricks allows Stored XSS. This issue affects JetTricks: from n/a through 2.0.1. | ||||
| CVE-2026-96656 | 1 Plex | 1 Media Server | 2026-09-23 | 7.2 High |
| Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The preference TranscoderH264Options is appended verbatim to x264's option string on every transcode. At startup, all .so files are run without signature, execute bit, or symbol checks. | ||||
| CVE-2026-95593 | 2026-09-23 | 7.6 High | ||
| Editor SQL Injection in Ultimeter <= 3.0.8 versions. | ||||
| CVE-2026-95525 | 2026-09-23 | 6.5 Medium | ||
| Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions. | ||||
| CVE-2026-95514 | 2026-09-23 | 5.3 Medium | ||
| Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions. | ||||
| CVE-2026-94684 | 2026-09-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 versions. | ||||
| CVE-2026-94680 | 2026-09-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. | ||||
| CVE-2026-94679 | 2026-09-23 | 5.4 Medium | ||
| Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions. | ||||
| CVE-2026-94500 | 2026-09-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions. | ||||
| CVE-2026-94487 | 2026-09-23 | 8.1 High | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Capabilities <= 2.50.1 versions. | ||||
| CVE-2026-94461 | 2026-09-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions. | ||||
| CVE-2026-94391 | 2026-09-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions. | ||||
| CVE-2026-94176 | 2026-09-23 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions. | ||||