Export limit exceeded: 403660 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403660 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-107391 | 1 Borewit | 1 Music-metadata | 2026-10-08 | 6.2 Medium |
| music-metadata is a metadata parser for audio and video media files. In the public development revision introduced after 11.14.0, a development-branch regression in the MP4 stsd sample-description parser allows an attacker-controlled sample-entry size of zero to prevent the StsdAtom.get cursor from advancing while an attacker-controlled entry_count keeps the synchronous loop running. A crafted MP4-family input can block the Node.js event loop and grow the sample-description table until the process is terminated or exhausts memory. The vulnerable change was present on the public master branch but was not included in music-metadata 11.14.0 or any earlier npm release, and version 11.16.0 contains the fix. This issue is fixed in version 11.16.0. | ||||
| CVE-2026-107397 | 1 Indico | 1 Indico | 2026-10-08 | 4.4 Medium |
| Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, users who can create content, including speakers who can create minutes, can store crafted HTML in event minutes. When concurrent edits are made to the same minutes, the minute editor conflict UI can execute attacker-controlled script in the viewer's browser in the Indico origin. This issue is fixed in version 3.3.13. | ||||
| CVE-2026-107376 | 1 Webonyx | 1 Graphql-php | 2026-10-08 | 8.2 High |
| webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote attacker can submit deeply nested selection sets, object or list values, or list types that exhaust the PHP process stack during pre-validation parsing, before query validation and complexity controls run. The resulting SIGSEGV can terminate PHP-FPM workers or long-running Swoole, RoadRunner, ReactPHP, or CLI processes and cannot be caught by application-level exception handling. This issue is fixed in version 15.32.3. | ||||
| CVE-2026-107393 | 1 Freescout Helpdesk | 1 Freescout | 2026-10-08 | 6.1 Medium |
| FreeScout is a self-hosted help desk and shared mailbox. Prior to 1.8.235, when APP_CLOUDFLARE_IS_USED is enabled, FreeScout trusts an unvalidated CF-Connecting-IP header during failed login attempts and stores the spoofed value in the activity log. LogsMonitor inserts the value into an administrator alert email without HTML escaping, allowing injected HTML to execute when an administrator opens the email. This issue is fixed in version 1.8.235. | ||||
| CVE-2026-107394 | 1 Indico | 1 Indico | 2026-10-08 | 6.8 Medium |
| Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, the previous fix for CVE-2026-25738 did not cover an edge case, allowing an event organizer to submit a crafted URL that points to a prohibited local target but is accepted as valid by Indico. The organizer can read data returned by the target through affected Indico features. This issue is fixed in version 3.3.13. | ||||
| CVE-2026-75875 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 9.8 Critical |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to path traversal. | ||||
| CVE-2026-80381 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 9.8 Critical |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute unauthorized SQL statements due to SQL injection. | ||||
| CVE-2026-82895 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow. | ||||
| CVE-2026-82900 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to delete arbitrary files due to improper limitation of a pathname to a restricted directory. | ||||
| CVE-2026-81932 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.6 High |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | ||||
| CVE-2026-84032 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 5.6 Medium |
| IBM Guardium Data Protection 12.2.2 could allow a remote attacker to conduct a man-in-the-middle attack due to improper certificate validation. | ||||
| CVE-2026-84035 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow. | ||||
| CVE-2026-84057 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | ||||
| CVE-2026-84058 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOGIN packet decoder. A remote attacker who can send a specially crafted TDS PRELOGIN packet to a network monitored by an IBM Guardium Collector may cause a denial of service or potentially execute arbitrary code on the Collector appliance. | ||||
| CVE-2026-84198 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow. | ||||
| CVE-2026-84209 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. | ||||
| CVE-2026-84230 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 7.5 High |
| IBM Guardium Data Protection 12.2.2 could allow a remote attacker to cause a denial of service due to a race condition resulting from concurrent unsynchronized writes to a shared map. | ||||
| CVE-2026-84246 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow. | ||||
| CVE-2026-84247 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability. | ||||
| CVE-2026-84249 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 9.8 Critical |
| IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary management operations due to missing authentication for critical function. | ||||