Export limit exceeded: 391664 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (391664 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-90518 | 1 Phpgurukul | 1 Bank Locker Management System | 2026-09-14 | 6.3 Medium |
| A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. | ||||
| CVE-2026-90507 | 1 Vvbbnn00 | 1 Warp-clash-api | 2026-09-14 | 6.3 Medium |
| A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such manipulation of the argument key leads to improper access controls. The attack may be launched remotely. The exploit is publicly available and might be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer. | ||||
| CVE-2026-90502 | 1 Stilleshan | 1 Serverstatus | 2026-09-14 | 3.5 Low |
| A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/main.cpp of the component Stats Generation. Performing a manipulation of the argument custom results in cross site scripting. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-90497 | 1 Fengoffice | 1 Feng Office | 2026-09-14 | 3.5 Low |
| A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the function getTitle of the file application/views/task/add_task.php of the component Task Title Output. Executing a manipulation of the argument og_objects.name can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-90487 | 1 Xuxueli | 1 Xxl-job | 2026-09-14 | 4.3 Medium |
| A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobGroupController.java. The manipulation results in improper privilege management. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-89094 | 1 Forgejo | 1 Forgejo | 2026-09-14 | 9.9 Critical |
| Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled. | ||||
| CVE-2026-89087 | 1 Ocaml | 1 Cstruct | 2026-09-14 | 7.3 High |
| The cstruct package before 6.3.0 for OCaml mishandles indexes. | ||||
| CVE-2026-87736 | 1 Ocaml | 1 Mirage-crypto-ec | 2026-09-14 | 4.3 Medium |
| An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points. | ||||
| CVE-2026-87087 | 2026-09-14 | N/A | ||
| ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage. | ||||
| CVE-2026-82097 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-14 | 8.8 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability. | ||||
| CVE-2026-82019 | 2026-09-14 | 4.2 Medium | ||
| TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a publisher's domain by sending crafted postMessage payloads without origin validation. Attackers can cause a victim to visit an attacker-controlled page that sends malicious postMessage events to a publisher page running the ad script, enabling session hijacking and unauthorized DOM manipulation. | ||||
| CVE-2026-81051 | 1 Dell | 1 Thinos | 2026-09-14 | 6.6 Medium |
| Dell ThinOS 10, versions prior to 2605_10.2616, contain a Security Version Number Mutable to Older Versions vulnerability. A low privileged attacker with physical access could potentially exploit this vulnerability, leading to Protection mechanism bypass. | ||||
| CVE-2026-61910 | 1 Cyrusimap | 1 Cyrus Imap | 2026-09-14 | 3.5 Low |
| An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This could allow the sharee to change the shared mailbox to perform the archived, snoozed, or other role, which might cause mail mail to be written to the shared mailbox, sharing more content than intended. (This is likely to be an unusual situation, made more unusual because if the target already has an non-shared mailbox with that role, role duplication suppression will prevent the update.) | ||||
| CVE-2026-61909 | 1 Cyrusimap | 1 Cyrus Imap | 2026-09-14 | 3.5 Low |
| An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT. | ||||
| CVE-2026-61907 | 1 Cyrusimap | 1 Cyrus Imap | 2026-09-14 | 4.3 Medium |
| An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox. | ||||
| CVE-2026-59570 | 2026-09-14 | 7.5 High | ||
| On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture. | ||||
| CVE-2026-59569 | 2026-09-14 | 8.1 High | ||
| An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls. | ||||
| CVE-2026-57825 | 1 Ocaml | 1 Opam | 2026-09-14 | 5.7 Medium |
| In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files. | ||||
| CVE-2026-57132 | 2026-09-14 | 8.2 High | ||
| PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to /api/v1/agents/{id}/invoke without CALL_SERVER_TOKEN authentication. Deployments that use the application's advertised opt-out can expose registered agents and their connected tools or private context to unauthenticated invocation. The vulnerability is fixed in 4.6.62. | ||||
| CVE-2026-57129 | 2026-09-14 | 7.5 High | ||
| PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts file-mention values and falls back from workspace-relative resolution to Path(file_path) without traversal, symlink, or workspace-boundary validation. Prompt input from users, bots, or workflows can therefore read arbitrary files accessible to the process, including credentials, keys, environment files, source code, and system configuration. This issue is fixed in praisonaiagents 1.6.59. | ||||