Export limit exceeded: 399583 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399583 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-98030 | 1 Linux | 1 Linux Kernel | 2026-09-29 | 7 High |
| In the Linux kernel, the following vulnerability has been resolved: net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size bcm_sf2_cfp_rule_get_all() walks the whole cfp.unique bitmap into rule_locs[] without consulting nfc->rule_cnt, which is how many entries the caller had room for. ETHTOOL_GRXCLSRLALL requires no CAP_NET_ADMIN and the ioctl sizes the buffer from the rule_cnt userspace passes in, so once an admin has installed CFP rules any user can ask for fewer slots than there are rules and run off the end of the allocation. A rule_cnt of 0 leaves the buffer pointer NULL and the walk dereferences it. | ||||
| CVE-2026-98031 | 1 Linux | 1 Linux Kernel | 2026-09-29 | 5.5 Medium |
| In the Linux kernel, the following vulnerability has been resolved: nexthop: Initialize extack in remove_nh_grp_entry() remove_nh_grp_entry() prints the extack message when a listener fails to replace the reduced nexthop group. However, extack is not initialized and listeners are not required to set a message when returning an error. Neither netdevsim nor mlxsw do so when an allocation fails, resulting in the dereference of an uninitialized stack pointer. Fix by zero-initializing extack, as was done in commit 6347c5314cee ("nexthop: initialize extack in nh_res_bucket_migrate()"). | ||||
| CVE-2026-98032 | 1 Linux | 1 Linux Kernel | 2026-09-29 | 7.0 High |
| In the Linux kernel, the following vulnerability has been resolved: tracing: Fix subbuf resize races with trace_pipe_raw readers Concurrent subbuffer resizes may crash trace_pipe_raw readers or leak uninitialized memory to userspace due to stale size values. Modify ring_buffer_alloc_read_page() to handle the resizing of an existing buffer_data_read_page if necessary and add a new ring_buffer_read_page_size(). This new function enables ring-buffer buffer_data_read_page users to not call the racy ring_buffer_subbuf_size_get(). This makes the spare_size member of ftrace_buffer_info redundant. Finally, handle buffer_data_read_page/reader_page order discrepancy in ring_buffer_read_page(). On a mismatch simply copy manually the data to the buffer_data_read_page. | ||||
| CVE-2026-98033 | 1 Linux | 1 Linux Kernel | 2026-09-29 | 7.0 High |
| In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve inner map identity in callback frames Callback frame constructors initialize map-typed argument registers with __mark_reg_known_zero() and then restore map_ptr. This clears map_uid, which is the only field distinguishing inner maps that share an inner_map_meta template. When a timer callback invokes bpf_for_each_map_elem() on a second inner map, both the saved first map and the second map value can reach the nested callback as the same template with map_uid zero. bpf_timer_init() then accepts pairing the timer from the second map with the first map. The runtime records the first map in the timer without taking a reference. Freeing that map does not find the timer stored in the second map, so a later timer callback dereferences the freed map. Copy map_uid from the same caller register as map_ptr when constructing for-each, timer/workqueue, and task-work callback arguments. The existing identity check can then reject mismatched inner maps while allowing a callback value to be paired with its actual map. | ||||
| CVE-2026-78550 | 1 Okta | 1 Access Gateway | 2026-09-29 | 6.6 Medium |
| The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator SSH session. As a result, the unsanitized input is executed directly, leading to code execution with the privileges of the management console. | ||||
| CVE-2026-94400 | 1 Elastic | 1 Kibana | 2026-09-29 | 6.5 Medium |
| Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130) | ||||
| CVE-2026-69359 | 1 Microsoft | 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more | 2026-09-29 | 7.8 High |
| Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-102879 | 2026-09-29 | 5 Medium | ||
| ClaraVerse through 0.3.1 contains server-side request forgery protection bypasses in the download_file and scrape_web agent tools. Authenticated users can bypass hostname validation and IPv6 transition address filtering to make the server request internal services and cloud instance metadata endpoints. | ||||
| CVE-2026-102877 | 2026-09-29 | 4.4 Medium | ||
| Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL validation for webhooks and custom OAuth provider endpoints. Administrators controlling DNS can perform DNS rebinding attacks to make the Fider server send requests to internal services or cloud metadata endpoints. | ||||
| CVE-2026-102876 | 1 Surrealdb | 1 Surrealdb | 2026-09-29 | 8.1 High |
| SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS and Surreal-DB headers without validating access permissions. Attackers can authenticate as a user from one tenant while selecting another tenant's namespace and database to read, create, and modify records across tenant boundaries. | ||||
| CVE-2026-102875 | 1 Videolan | 1 Vlc | 2026-09-29 | 7.8 High |
| VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua script injection. | ||||
| CVE-2026-95336 | 1 Google | 1 Chrome | 2026-09-29 | 6.5 Medium |
| Information leak in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-95374 | 1 Google | 1 Chrome | 2026-09-29 | N/A |
| Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-53988 | 2026-09-29 | 10 Critical | ||
| Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests to force git clone and docker compose operations, enabling denial of service or, when combined with write access to the tracked git branch, container escape and full host compromise via attacker-controlled docker-compose.yml with privileged bind mounts. | ||||
| CVE-2026-79348 | 2026-09-29 | 4.3 Medium | ||
| KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate middleware but performs no ownership or role check, and the getReservation handler in packages/server/src/controllers/reservation.controller.ts returns the record retrieved by the client-supplied identifier without comparing reservation.customerId to the authenticated principal | ||||
| CVE-2026-69805 | 1 Microsoft | 4 Diagnostics Runtime, Microsoft.diagnostics.runtime, Visual Studio 2022 and 1 more | 2026-09-29 | 7.5 High |
| External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69854 | 1 Microsoft | 3 Azure Spring Cloud, Spring Cloud, Spring Cloud Azure | 2026-09-29 | 9 Critical |
| Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-67993 | 2026-09-29 | N/A | ||
| basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the static credentials callback. | ||||
| CVE-2026-67987 | 2026-09-29 | N/A | ||
| crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains polynomial-time regular expression denial-of-service conditions in think-tag response parsing on Ruby 3.1.x. A malicious or anomalous model response containing many unterminated <think> tags can cause excessive CPU consumption in two consecutive regular expressions and delay chat-completion processing | ||||
| CVE-2026-77504 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-29 | 8.8 High |
| Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | ||||