Export limit exceeded: 400819 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400819 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400819 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-51860 | 1 Dataelement | 1 Bisheng | 2026-10-01 | 7.5 High |
| bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Directory Traversal in src/backend/bisheng/linsight/domain/task_exec.py. | ||||
| CVE-2026-102628 | 2026-10-01 | 9.3 Critical | ||
| The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the entire server environment, including all .env configuration variables, in plaintext. Fixed on or before 2026-09-02. | ||||
| CVE-2026-100251 | 2026-10-01 | 6.5 Medium | ||
| Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance metadata or to source TCP connections from the Wormhole relay's IP. | ||||
| CVE-2026-102671 | 2026-10-01 | 5.3 Medium | ||
| The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default. | ||||
| CVE-2026-102670 | 2026-10-01 | 4.3 Medium | ||
| Joyland AI app explicitly permits cleartext HTTP traffic on Android 9+ where the default is to block it. | ||||
| CVE-2026-102669 | 2026-10-01 | 5.3 Medium | ||
| Joyland AI app does not verify hostnames, allowing a malicious host to connect or intercept chat messages. | ||||
| CVE-2026-102668 | 2026-10-01 | 5.3 Medium | ||
| The Joyland AI app accepts any TLS certificates from any server without validation. | ||||
| CVE-2026-102667 | 2026-10-01 | 8.3 High | ||
| Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, or access app-internal storage. If the installed app has been granted permissions previously, the attacker can access the entire file system, camera, microphone, and GPS tracking. | ||||
| CVE-2026-82358 | 2026-10-01 | 6.5 Medium | ||
| RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation 'src/co_sdo_server.c' that fails to properly validate write permissions when processing download-segment frames. An unauthenticated attacker on the CAN bus can initiate an SDO upload for a read-only Object Dictionary (OD) entry, which sets a data pointer to the read-only object, then send download-segment frames to write to that memory location. The download-segment handler does not verify that a download session is active, allowing any CANopen node to overwrite read-only OD entries using two SDO frames. Note that CANopen protocol operates over CAN bus and does not provide built-in authentication mechanisms. Fixed in 1.1.1. | ||||
| CVE-2026-102666 | 2026-10-01 | 6.5 Medium | ||
| The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content to any user, group of users, or all users of the app at once. | ||||
| CVE-2026-82357 | 2026-10-01 | 6.5 Medium | ||
| RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object defined by the user application may not have all required subindexes for object 0x1018. An unauthenticated, remote attacker with access to the CAN bus, through a compromised node for instance, can initiate the LSS protocol on a device with a misconfigured identity object and potentially crash the device. Fixed in 1.1.1. | ||||
| CVE-2026-88408 | 1 Falkordb | 1 Falkordb | 2026-10-01 | 6.5 Medium |
| FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function (/ops/op_aggregate.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. | ||||
| CVE-2026-62084 | 1 Jeff Starr | 1 User Submitted Posts | 2026-10-01 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS. This issue affects User Submitted Posts: from n/a through 20260810. | ||||
| CVE-2026-103445 | 1 Wikimedia | 1 Mediawiki-page Forms Extension | 2026-10-01 | N/A |
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43. | ||||
| CVE-2026-103437 | 1 Wikimedia | 1 Mediawiki-readinglists Extension | 2026-10-01 | N/A |
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS. This issue affects MediaWiki ReadingLists extension: 1.46 and 1.45. | ||||
| CVE-2026-103438 | 1 Wikimedia | 1 Mediawiki-wikistories Extension | 2026-10-01 | N/A |
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikistories extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki Wikistories extension: 1.46, 1.45, and 1.43. | ||||
| CVE-2026-102397 | 2 Supsystic, Wordpress-extensions | 2 Ultimate Maps By Supsystic, Ultimate Maps By Supsystic | 2026-10-01 | 6.5 Medium |
| Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions. | ||||
| CVE-2026-94171 | 2 Villatheme, Wordpress-extensions | 2 Curcy, Curcy | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions. | ||||
| CVE-2026-97256 | 2 Greg–siteorigin, Wordpress-extensions | 2 Page Builder By Siteorigin, Page Builder By Siteorigin | 2026-10-01 | 7.2 High |
| Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions. | ||||
| CVE-2026-97265 | 2 Crocoblock. Jetimpex Inc., Wordpress-extensions | 2 Jetengine, Jetengine | 2026-10-01 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.8.15.3. | ||||