Export limit exceeded: 399204 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 399204 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399204 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-101082 | 1 Pmweb | 1 Pmweb | 2026-09-28 | 5.3 Medium |
| A weakness has been identified in PMWeb 7.x/8.x/2025.x. This issue affects some unknown processing of the file downloader.aspx. This manipulation of the argument FullFileName/FileName causes path traversal. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-88772 | 1 Citrix | 3 Netscaler Adc, Netscaler Application Delivery Controller, Netscaler Gateway | 2026-09-28 | 8.1 High |
| Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service | ||||
| CVE-2026-58464 | 2026-09-28 | N/A | ||
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||||
| CVE-2026-58463 | 2026-09-28 | N/A | ||
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||||
| CVE-2026-69459 | 1 Microsoft | 18 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 15 more | 2026-09-28 | 7.8 High |
| Heap-based buffer overflow in Windows Power Dependency Coordinator allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69460 | 1 Microsoft | 18 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 15 more | 2026-09-28 | 7.1 High |
| Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-97165 | 1 Svenbluege.de | 1 Event Gallery For Joomla | 2026-09-28 | N/A |
| Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” parameter is base64-decoded and written to the “Back” link without being validated. | ||||
| CVE-2026-100749 | 1 Svenbluege.de | 1 Event Gallery For Joomla | 2026-09-28 | N/A |
| Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned file entries and shopping carts that are older than 30 days will be deleted. | ||||
| CVE-2026-100747 | 1 Svenbluege.de | 1 Event Gallery For Joomla | 2026-09-28 | N/A |
| Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a third-party site can upload files to an event and overwrite existing files with the same name. | ||||
| CVE-2026-97164 | 1 Svenbluege.de | 1 Event Gallery For Joomla | 2026-09-28 | N/A |
| Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extension < 6.5.0 - Using the `images` parameter of the `cache.process` task, you can recursively delete any directories that the web server is authorized to write to. | ||||
| CVE-2026-100748 | 1 Svenbluege.de | 1 Event Gallery For Joomla | 2026-09-28 | N/A |
| Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0 | ||||
| CVE-2026-100866 | 1 O2sh | 1 Onefetch | 2026-09-28 | 3.3 Low |
| onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fields to manipulate terminal output, rewrite window titles, hide text, or trigger emulator-specific behavior when victims run onefetch. | ||||
| CVE-2026-100867 | 1 Spaceship-prompt | 1 Spaceship-prompt | 2026-09-28 | 3.3 Low |
| spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before rendering them in the zsh prompt. Attackers can embed ANSI/OSC escape sequences in version fields of package manifests to manipulate terminal output, rewrite window titles, or spoof displayed text when victims enter the directory. | ||||
| CVE-2026-100868 | 2 Kaleidos, Penpot | 3 Penpot, Mcp, Penpot | 2026-09-28 | 6.3 Medium |
| Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to impersonate the Penpot browser plugin, intercept task payloads, and return forged results to the MCP client. | ||||
| CVE-2026-101032 | 1 Denisidoro | 1 Navi | 2026-09-28 | 7 High |
| navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into shell commands. Attackers can inject shell metacharacters through crafted file names in suggestion command directories to execute arbitrary commands with victim privileges. | ||||
| CVE-2026-101033 | 1 Tombursch | 1 Kitchenowl | 2026-09-28 | 4.3 Medium |
| KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operations. Authenticated attackers can enumerate category IDs from other households to read their category names, budgets, and colors, breaking household isolation. | ||||
| CVE-2026-88771 | 1 Citrix | 3 Netscaler Adc, Netscaler Application Delivery Controller, Netscaler Gateway | 2026-09-28 | 9.8 Critical |
| Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands. | ||||
| CVE-2026-88773 | 1 Citrix | 3 Netscaler Adc, Netscaler Application Delivery Controller, Netscaler Gateway | 2026-09-28 | 10.0 Critical |
| Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23. | ||||
| CVE-2026-88775 | 1 Citrix | 3 Netscaler Adc, Netscaler Application Delivery Controller, Netscaler Gateway | 2026-09-28 | 9.8 Critical |
| Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service | ||||
| CVE-2026-96279 | 2 Flatpak, Redhat | 2 Flatpak, Enterprise Linux | 2026-09-28 | 6.5 Medium |
| A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary host file contents. For system-wide installs running as root, this includes sensitive files such as /etc/shadow. | ||||
