Export limit exceeded: 396397 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 396397 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (396397 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-83801 | 1 Nautobot | 1 Nautobot | 2026-09-22 | 5.4 Medium |
| Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.37 and 3.1.8, a user with extras.add_relationship or extras.change_relationship permission can store HTML or JavaScript in a Relationship description, and a user with dcim.add_modulefamily or dcim.change_modulefamily permission can store it in a Module Family name. Nautobot assigns these values to form field help_text rendered by render_field.html through Django's |safe filter without adequate neutralization. The stored content executes in the authenticated browser session of any user, including an administrator or superuser, who opens an affected create or edit form. This can enable actions as the victim, session or token theft, and further privilege escalation. This issue is fixed in versions 2.4.37 and 3.1.8. | ||||
| CVE-2026-77322 | 1 Emiago | 1 Sipgo | 2026-09-22 | 7.5 High |
| SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a wsutil.Reader without setting MaxFrameSize, allowing NextFrame to accept a client-controlled header.Length before ParseMaxMessageLength is applied. An unauthenticated WS or WSS peer can send a frame header declaring an extremely large payload, causing an oversized allocation or a makeslice length panic before the payload is read and crashing or exhausting memory in the server process. This issue is fixed in version 1.4.3. | ||||
| CVE-2026-18169 | 1 Ibm | 1 Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-22 | 9.9 Critical |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. | ||||
| CVE-2026-93558 | 2 Io.netty, Redhat | 22 Netty-codec-http, Amq Broker, Amq Broker 7 and 19 more | 2026-09-22 | 7.5 High |
| A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the application can respond. This leads to an unbounded growth of a per-connection queue, consuming excessive memory. Eventually, this can cause the Java Virtual Machine (JVM) to exhaust its heap, resulting in a Denial of Service (DoS) for the affected server. | ||||
| CVE-2026-18170 | 1 Ibm | 1 Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-22 | 6.5 Medium |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without limits or throttling. | ||||
| CVE-2026-93488 | 2 Io.netty, Redhat | 21 Netty-codec-http, Amq Broker, Amq Clients and 18 more | 2026-09-22 | 7.5 High |
| A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it. A remote peer can open a SPDY connection and send a large number of SYN_STREAM frames with FLAG_FIN=0, causing unbounded heap and direct memory allocation that can lead to JVM OutOfMemoryError and a denial of service. | ||||
| CVE-2026-18163 | 1 Ibm | 1 Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-22 | 9.8 Critical |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data. | ||||
| CVE-2026-18162 | 1 Ibm | 1 Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-22 | 9.8 Critical |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor. | ||||
| CVE-2026-18161 | 1 Ibm | 1 Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-22 | 4.3 Medium |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to falsify transaction audit logs due to improper validation of a client-supplied HTTP header. | ||||
| CVE-2026-18156 | 1 Ibm | 1 Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-22 | 6.5 Medium |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to bypass security controls by forging user identities due to improper authorization. | ||||
| CVE-2026-18154 | 1 Ibm | 1 Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-22 | 8 High |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or predictable cryptographic key. | ||||
| CVE-2026-18153 | 1 Ibm | 1 Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-22 | 5.4 Medium |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and initialization vectors. | ||||
| CVE-2026-18152 | 1 Ibm | 1 Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-22 | 7.4 High |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge validly-signed messages due to improper verification of cryptographic signatures. | ||||
| CVE-2026-18137 | 1 Ibm | 1 Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-22 | 8.1 High |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements used in an ESQL command. | ||||
| CVE-2026-18134 | 1 Ibm | 1 Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-22 | 7.5 High |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information. | ||||
| CVE-2026-95819 | 1 Anirbandutta9 | 1 College-notes-gallery | 2026-09-22 | 7.3 High |
| A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this vulnerability is an unknown functionality of the file login.php. Such manipulation of the argument user/pass leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-75432 | 2026-09-22 | N/A | ||
| An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components | ||||
| CVE-2026-88414 | 2026-09-22 | N/A | ||
| MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the PageAction.verify endpoint (GET /ms/mdiy/page/verify.do). | ||||
| CVE-2026-88341 | 2026-09-22 | N/A | ||
| A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num_buffers=0) that triggers an assertion failure in yr_arena_get_ptr(), causing the application to terminate. | ||||
| CVE-2026-88350 | 2026-09-22 | N/A | ||
| An integer overflow vulnerability exists in MPack 1.1.1 in mpack_node_cstr_alloc() and mpack_node_utf8_cstr_alloc(). | ||||