Export limit exceeded: 391727 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (391727 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-82780 | 2026-09-14 | 8.8 High | ||
| Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploaded by a remote authenticated attacker, an arbitrary command may be executed on the product. | ||||
| CVE-2026-82781 | 2026-09-14 | 5.4 Medium | ||
| Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
| CVE-2026-82784 | 2026-09-14 | 6.5 Medium | ||
| Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values and/or control the output. | ||||
| CVE-2026-82788 | 2026-09-14 | 6.1 Medium | ||
| Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
| CVE-2026-75943 | 2026-09-14 | 2.6 Low | ||
| A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcement. | ||||
| CVE-2026-91201 | 1 Arc53 | 1 Docsgpt | 2026-09-14 | 5.4 Medium |
| DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud storage connectors. | ||||
| CVE-2026-91200 | 1 Devspace | 1 Devspace | 2026-09-14 | 8.8 High |
| DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer workstation, enabling code execution. | ||||
| CVE-2026-91199 | 2026-09-14 | 5 Medium | ||
| Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without validating the scheme, host, or resolved address. Authenticated attackers can make the backend issue requests to loopback, private, and link-local addresses including cloud metadata services to read page titles and descriptions of internal resources. | ||||
| CVE-2026-91198 | 1 Growthbook | 1 Growthbook | 2026-09-14 | 5.3 Medium |
| GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge of a publicly shared report or experiment identifier can read internal data warehouse query text, schema, table names, filter values and datasource identifiers. | ||||
| CVE-2026-91197 | 2026-09-14 | 6.5 Medium | ||
| Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources. Attackers with process deployment privileges can embed DOCTYPE declarations with external entities in BPMN files to read arbitrary local files or trigger requests to internal network endpoints when diagram layout is computed. | ||||
| CVE-2026-11332 | 1 Redhat | 20 Acm, Ansible Automation Platform, Ansible Automation Platform Developer and 17 more | 2026-09-14 | 7.8 High |
| A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install. | ||||
| CVE-2026-77191 | 2026-09-14 | 2.6 Low | ||
| An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the full enforcement of its assigned ACL. | ||||
| CVE-2026-90828 | 1 Gnu | 1 Binutils | 2026-09-14 | 5.3 Medium |
| A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet. | ||||
| CVE-2026-31278 | 1 Supremainc | 1 Biostar 2 | 2026-09-14 | 7.7 High |
| An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request. | ||||
| CVE-2026-33956 | 1 Samsung | 1 Exynos 1330 Firmware | 2026-09-14 | 2.8 Low |
| An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Sending a malformed message to the test_msg sysfs entry causes an out-of-bounds write, leading to denial of service. | ||||
| CVE-2026-82764 | 2026-09-14 | N/A | ||
| Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed. | ||||
| CVE-2026-82767 | 2026-09-14 | 5.2 Medium | ||
| Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
| CVE-2026-82769 | 2026-09-14 | 5.4 Medium | ||
| Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
| CVE-2026-82768 | 2026-09-14 | 8.1 High | ||
| Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP. | ||||
| CVE-2026-82771 | 2026-09-14 | 5.4 Medium | ||
| Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | ||||
