Export limit exceeded: 400470 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400470 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16524 | 1 Redhat | 7 Enterprise Linux, Enterprise Linux Eus, Openshift and 4 more | 2026-09-30 | 7.8 High |
| A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh. | ||||
| CVE-2026-83596 | 1 Redhat | 1 Enterprise Linux | 2026-09-30 | 8.8 High |
| A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling. | ||||
| CVE-2026-78376 | 1 Redhat | 1 Enterprise Linux | 2026-09-30 | 8.8 High |
| A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption. | ||||
| CVE-2026-89238 | 1 Apache | 1 Wss4j | 2026-09-30 | 9.1 Critical |
| WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. | ||||
| CVE-2026-47545 | 1 Nvidia | 6 Geforce, Nvs, Quadro and 3 more | 2026-09-30 | 7.8 High |
| NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-47552 | 1 Nvidia | 7 Geforce, Guest Driver, Nvs and 4 more | 2026-09-30 | 7.8 High |
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass an authorization check and modify privileged configuration. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-47563 | 1 Nvidia | 7 Geforce, Guest Driver, Nvs and 4 more | 2026-09-30 | 7.8 High |
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-47577 | 1 Nvidia | 5 Geforce, Nvs, Quadro and 2 more | 2026-09-30 | 7.8 High |
| NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an incorrect comparison. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-47578 | 1 Nvidia | 6 Geforce, Nvs, Quadro and 3 more | 2026-09-30 | 7.8 High |
| NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect buffer size calculation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-47583 | 1 Nvidia | 5 Geforce, Nvs, Quadro and 2 more | 2026-09-30 | 7.8 High |
| NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause type confusion. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-47585 | 1 Nvidia | 5 Geforce, Nvs, Quadro and 2 more | 2026-09-30 | 7.8 High |
| NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an integer underflow. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-76504 | 1 Cisco | 1 Catalyst Sd-wan Manager | 2026-09-30 | 9.8 Critical |
| A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user. | ||||
| CVE-2026-47097 | 1 Aja Video Systems | 1 Helo Plus | 2026-09-30 | 7.5 High |
| AJA HELO Plus firmware before 2.1.7 contains an information disclosure vulnerability that allows unauthenticated attackers to decrypt sensitive diagnostics bundles by exploiting a static AES passphrase embedded in obfuscated form within the firmware. Attackers can reverse engineer the publicly available firmware image to recover the shared passphrase and decrypt diagnostics export bundles retrieved from the unauthenticated diagnostics endpoint on any affected device, exposing highly sensitive server information. | ||||
| CVE-2026-47580 | 1 Nvidia | 5 Geforce, Nvs, Quadro and 2 more | 2026-09-30 | 7.3 High |
| NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause a missing authorization issue. A successful exploit of this vulnerability might lead to information disclosure and data tampering. | ||||
| CVE-2026-47582 | 1 Nvidia | 7 Geforce, Guest Driver, Nvs and 4 more | 2026-09-30 | 7 High |
| NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-47546 | 1 Nvidia | 5 Geforce, Nvs, Quadro and 2 more | 2026-09-30 | 6.7 Medium |
| NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-47581 | 1 Nvidia | 6 Geforce, Nvs, Quadro and 3 more | 2026-09-30 | 5.5 Medium |
| NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where a user could cause improper locking. A successful exploit of this vulnerability might lead to denial of service. | ||||
| CVE-2026-47584 | 1 Nvidia | 5 Geforce, Nvs, Quadro and 2 more | 2026-09-30 | 5.5 Medium |
| NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker with local access could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to denial of service. | ||||
| CVE-2026-47562 | 1 Nvidia | 7 Geforce, Guest Driver, Nvs and 4 more | 2026-09-30 | 4.4 Medium |
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could inject crafted text into the kernel log because the supplied version string is not properly sanitized. A successful exploit of this vulnerability might lead to denial of service and data tampering. | ||||
| CVE-2026-101058 | 1 Universal-tool-calling-protocol | 1 Python-utcp | 2026-09-30 | 6.9 Medium |
| python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manual point at the agent's own loopback interface when that manual is discovered from a remote, non-loopback origin. Because ensure_secure_url intentionally permits loopback HTTP for local development and native manuals bypassed the loopback check performed by the OpenAPI converter, an attacker who can serve a UTCP manual that a victim registers can cause the client to issue requests to services bound only to 127.0.0.1 on the victim host and have the response bodies returned to the caller (server-side request forgery). The http, sse and streamable_http protocols are all affected. Reach is limited to loopback, and exploitation further requires a loopback service that answers unauthenticated requests with useful data. Fixed in utcp-http 1.1.12, which rejects manuals fetched from a non-loopback origin that declare loopback tool URLs, keyed off the final post-redirect discovery URL. | ||||