Export limit exceeded: 386362 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (386362 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-19475 | 1 Grafana | 4 Grafana, Microsoft Sql Server Datasource, Mysql Datasource and 1 more | 2026-09-03 | 6.5 Medium |
| An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected. | ||||
| CVE-2026-84848 | 2026-09-03 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions. | ||||
| CVE-2026-84847 | 2026-09-03 | 7.5 High | ||
| Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions. | ||||
| CVE-2026-84812 | 2026-09-03 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions. | ||||
| CVE-2026-84778 | 2026-09-03 | 7.5 High | ||
| Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration & Cloning <= 6.65 versions. | ||||
| CVE-2026-84776 | 2026-09-03 | 7.5 High | ||
| Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions. | ||||
| CVE-2026-84769 | 2026-09-03 | 6.5 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions. | ||||
| CVE-2026-84767 | 2026-09-03 | 5.3 Medium | ||
| Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions. | ||||
| CVE-2026-84758 | 2026-09-03 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions. | ||||
| CVE-2026-84754 | 2026-09-03 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions. | ||||
| CVE-2026-84753 | 2026-09-03 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. | ||||
| CVE-2026-81776 | 2026-09-03 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions. | ||||
| CVE-2026-81282 | 2026-09-03 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions. | ||||
| CVE-2026-81281 | 2026-09-03 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions. | ||||
| CVE-2026-51689 | 1 Totolink | 1 T6 | 2026-09-03 | 9.1 Critical |
| Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmware-upgrade workflow changes via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||||
| CVE-2026-84963 | 1 Mongodb | 1 C Driver | 2026-09-03 | 5.3 Medium |
| An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing operation still reports success and returns no error. An unauthenticated party who can supply the input processed by an application that uses this component may cause that application to hold data that does not match what was submitted, which may result in unintended alteration of data. | ||||
| CVE-2026-84962 | 1 Mongodb | 1 Libmongocrypt | 2026-09-03 | 4.2 Medium |
| An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-level access into cloud key control and defeating client-side encryption. | ||||
| CVE-2026-71963 | 1 Nousresearch | 1 Hermes-agent | 2026-09-03 | 8.8 High |
| Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying a malicious repository with a crafted .git/config that sets core.fsmonitor to an attacker-controlled command. When a user opens the malicious repository and sends any message, the agent triggers a git status index refresh which executes the injected command in the user's process context, exposing the full environment including configured provider API keys. | ||||
| CVE-2026-50554 | 1 Enchant97 | 1 Note-mark | 2026-09-03 | 5.3 Medium |
| Note Mark is an open-source note-taking application. Prior to version 0.19.5, GET /api/books/{bookID}/notes is an unauthenticated endpoint that accepts a "deleted" query parameter. When the request is ?deleted=true, the service runs the query with Unscoped() (bypassing GORM's soft-delete scope) but keeps the read-authorization clause as "owner_id = ? OR is_public = ?". As a result, any unauthenticated caller can enumerate the metadata of soft-deleted ("trashed") notes belonging to any public book — notes the owner explicitly deleted and expected to be removed from public view. This issue has been patched in version 0.19.5. | ||||
| CVE-2026-82927 | 1 Samsung Open Source | 1 Mtower | 2026-09-03 | 5.5 Medium |
| Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e. | ||||
