Export limit exceeded: 391657 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (391657 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-40476 | 1 Webonyx | 1 Graphql-php | 2026-09-14 | 7.5 High |
| graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation rule performs O(n²) pairwise comparisons of fields sharing the same response name. An attacker can send a query with thousands of repeated identical fields, causing excessive CPU usage during validation before execution begins. This is not mitigated by existing QueryDepth or QueryComplexity rules. This issue has been fixed in version 15.31.5. | ||||
| CVE-2026-19816 | 2 Packagekit, Redhat | 2 Packagekit, Enterprise Linux | 2026-09-14 | 7.1 High |
| A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend. | ||||
| CVE-2026-19624 | 2026-09-14 | 7.8 High | ||
| A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security association is established, resulting in local privilege escalation. This is the same bug class as CVE-2018-10900 (NetworkManager-vpnc). | ||||
| CVE-2026-19543 | 1 Ibm | 1 Common Licensing | 2026-09-14 | 6.2 Medium |
| IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can modify requests to bypass validation controls and submit unauthorized values, potentially resulting in unintended application behavior. | ||||
| CVE-2026-19542 | 1 Gnu | 1 Glibc | 2026-09-14 | 5.6 Medium |
| Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree. Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete. The written value is a pointer into a tree node and is not directly attacker controlled. No affected application in common distributions has been identified. | ||||
| CVE-2026-19499 | 1 Gnu | 1 Glibc | 2026-09-14 | 7.7 High |
| Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller. At the time of publication, no network-facing application impact is known. | ||||
| CVE-2026-18515 | 1 Ibm | 1 I | 2026-09-14 | 4.3 Medium |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile could already do that by itself. | ||||
| CVE-2026-18251 | 1 Ibm | 1 I | 2026-09-14 | 4.3 Medium |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of the WebSocket origin. | ||||
| CVE-2026-18119 | 2026-09-14 | N/A | ||
| Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CSS via a DOM sink, permitting stored cross-site scripting. An editor-level user could execute script in an administrator's session and escalate privileges. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 7.0 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N. Thanks Nguyen Manh Thuan for reporting. | ||||
| CVE-2026-18065 | 1 Ibm | 1 I | 2026-09-14 | 5.3 Medium |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information through session IP binding bypass in Navigator for i. | ||||
| CVE-2026-17416 | 1 Ibm | 1 App Connect Enterprise | 2026-09-14 | 7.8 High |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization. | ||||
| CVE-2026-17156 | 1 Ibm | 1 App Connect Enterprise | 2026-09-14 | 7.8 High |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization. | ||||
| CVE-2026-17133 | 1 Ibm | 1 App Connect Enterprise | 2026-09-14 | 7.8 High |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | ||||
| CVE-2026-16466 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-14 | 8.8 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection. | ||||
| CVE-2026-16435 | 1 Ibm | 1 Websphere Application Server | 2026-09-14 | 5.9 Medium |
| IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features. | ||||
| CVE-2026-16335 | 1 Ibm | 1 Datastage On Cloud Pak For Data | 2026-09-14 | 8.1 High |
| IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability. | ||||
| CVE-2026-16190 | 1 Ibm | 1 Websphere Application Server | 2026-09-14 | 3.1 Low |
| IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability. | ||||
| CVE-2026-16189 | 1 Ibm | 1 Websphere Application Server | 2026-09-14 | 4.8 Medium |
| IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log. | ||||
| CVE-2026-16186 | 1 Ibm | 1 Websphere Application Server | 2026-09-14 | 5.4 Medium |
| IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability. | ||||
| CVE-2026-15955 | 1 Ibm | 1 Db2 | 2026-09-14 | 7.5 High |
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths. | ||||
