Export limit exceeded: 402612 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402612 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402612 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402612 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16335 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-10-06 | 8.1 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability. | ||||
| CVE-2026-16338 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-10-06 | 9.9 Critical |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths. | ||||
| CVE-2026-81447 | 1 Dell | 6 Dell Openmanage Server Administrator Managed Node For Rhel 8.10, Dell Openmanage Server Administrator Managed Node For Rhel 9.4, Dell Openmanage Server Administrator Managed Node For Sles 15 and 3 more | 2026-10-06 | 6.8 Medium |
| Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. | ||||
| CVE-2026-16428 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-10-06 | 8.8 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine. | ||||
| CVE-2026-25262 | 1 Qualcomm | 17 Mdm9207, Mdm9207 Firmware, Mdm9645 and 14 more | 2026-10-06 | 6.9 Medium |
| Memory corruption while processing a crafted ELF file in the Primary Bootloader. | ||||
| CVE-2026-25255 | 1 Qualcomm | 3 Package Manager, Snapdragon, Software Center | 2026-10-06 | 8.8 High |
| Exposed dangerous function lead to privilege escalation via gRPC server. | ||||
| CVE-2026-73547 | 1 Envoyproxy | 1 Envoy | 2026-10-06 | 7.5 High |
| Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ext_authz filter assumes that a request contains a :path pseudoheader when applying query_parameters_to_set or query_parameters_to_remove from an authorization response. A path-less CONNECT request makes request_headers_->Path() return null, and Filter::onComplete dereferences that pointer while parsing the query string. An unauthenticated downstream client can crash the Envoy process when the filter and authorization response use query-parameter mutation. The relevant scope boundary is that the deployment must accept path-less CONNECT and configure ext_authz query-parameter mutation. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. | ||||
| CVE-2026-16432 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-10-06 | 7.7 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection. | ||||
| CVE-2026-16466 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-10-06 | 8.8 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection. | ||||
| CVE-2026-16673 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-10-06 | 8.8 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property. | ||||
| CVE-2026-94408 | 1 Elastic | 1 Elasticsearch | 2026-10-06 | 4.9 Medium |
| Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | ||||
| CVE-2026-42876 | 1 External-secrets | 1 External-secrets | 2026-10-06 | 4.9 Medium |
| External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.1, a user who only has permission to create ExternalSecret resources can cause the operator to create a Secret that Kubernetes will automatically populate with a long-lived token for the specified service account. This effectively allows the user to impersonate any service account in the namespace without needing direct create permissions on TokenRequest or Secrets of that type. This vulnerability is fixed in 2.4.1. | ||||
| CVE-2026-98165 | 1 Linux | 1 Linux Kernel | 2026-10-06 | N/A |
| In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: restrict BAR0 fallback read to SR-IOV VFs only The BAR0 fallback read path was introduced as a workaround for SR-IOV VFs where the VRAM aperture is not available during early init. Restrict this workaround to only SR-IOV VFs where it's needed. (cherry picked from commit d8a0affd207c813bd063fa2c27786f449eaf92b8) | ||||
| CVE-2026-98054 | 1 Linux | 1 Linux Kernel | 2026-10-06 | 5.5 Medium |
| In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Fix unbalanced module reference count strace_open() invokes try_module_get() which on success takes the module reference. If any follow up operation causes strace_open() to fail, the refcount shall be put down. | ||||
| CVE-2026-81478 | 1 Dell | 6 Dell Openmanage Server Administrator Managed Node For Rhel 8.10, Dell Openmanage Server Administrator Managed Node For Rhel 9.4, Dell Openmanage Server Administrator Managed Node For Sles 15 and 3 more | 2026-10-06 | 8.1 High |
| Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | ||||
| CVE-2026-66635 | 2 10web, Wordpress | 2 Sliderby10web, Wordpress | 2026-10-06 | 7.4 High |
| Cross-Site Request Forgery (CSRF) vulnerability in 10Web Slider by 10Web slider-wd allows Cross Site Request Forgery.This issue affects Slider by 10Web: from n/a through 1.2.63. | ||||
| CVE-2026-66616 | 2 10web, Wordpress | 2 Form Maker By 10web, Wordpress | 2026-10-06 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Maker by 10Web form-maker allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.49. | ||||
| CVE-2026-32576 | 2026-10-06 | 6.5 Medium | ||
| Authorization Bypass Through User-Controlled Key vulnerability in ZWEISCHNEIDER Faktur Pro for WooCommerce woorechnung allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Faktur Pro for WooCommerce: from n/a through 3.2.2. | ||||
| CVE-2026-98053 | 1 Linux | 1 Linux Kernel | 2026-10-06 | 5.5 Medium |
| In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Refactor and fix init_config access Existing code accesses enties found in ->init_configs array through indexes that are part of ->config_ids array. Those two are limited by: ->num_init_configs and ->num_config_ids respectively. Using ID larger or equal to ->num_init_configs leads to out-of-bounds access: avs_path_module_send_init_configs() loop: (...) &acomp->tplg->init_configs[ids[i]] ^ out-of-bounds candidate Rather than adding another if-statement, refactor the code. There is no need to store the IDs, have a list of pointers to actual config-entries instead. As the verification of ->init_config entries does not differ from verification of other types that are part of the topology.c file, simply reuse the code. | ||||
| CVE-2026-81477 | 1 Dell | 6 Dell Openmanage Server Administrator Managed Node For Rhel 8.10, Dell Openmanage Server Administrator Managed Node For Rhel 9.4, Dell Openmanage Server Administrator Managed Node For Sles 15 and 3 more | 2026-10-06 | 7.2 High |
| Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. | ||||