Export limit exceeded: 392040 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (392040 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-82432 | 2026-09-14 | 8.1 High | ||
| Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalance operation accepts configuration overrides and stripped a small set of keys from them, but never re-ran that validation, so a caller authorised to rebalance a topology could introduce a blobstore map entry naming a blob whose ACL does not grant them access. Supervisors localise whatever key the map names, placing the blob's contents into the topology's working directory. The same advisory covers `listBlobs`, which performed no authorization check and passed no subject, unlike the neighbouring `getBlobMeta` and `beginBlobDownload` operations. It therefore returned every key in the blobstore to any caller able to reach the Nimbus Thrift port, which provides the key names that make the above practical. On its own the disclosure is metadata only. Mitigation Upgrade to 3.1.0, where rebalance configuration overrides are validated exactly as submission-time configuration is, against the rebalancing caller, and where `listBlobs` applies the configured authorization. Users who cannot upgrade immediately should restrict rebalance rights to trusted principals, keeping in mind that membership of a topology's `topology.users` or `topology.groups` confers them. Credit The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm. | ||||
| CVE-2026-75792 | 1 Ibm | 1 Sterling Secure Proxy | 2026-09-14 | 4.3 Medium |
| IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to view administrative user interface components due to client-side authorization bypass. | ||||
| CVE-2026-90510 | 1 Dromara | 1 Orion-visor | 2026-09-14 | 8.3 High |
| A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java. The manipulation leads to use of hard-coded cryptographic key . The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-90516 | 1 Sourcecodester | 1 School Registration And Fee System | 2026-09-14 | 7.3 High |
| A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing a manipulation of the argument period results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. | ||||
| CVE-2026-78415 | 1 Ibm | 1 Sterling Secure Proxy | 2026-09-14 | 5.4 Medium |
| IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing and phishing attacks due to improper neutralization of user-supplied HTML markup. | ||||
| CVE-2026-7884 | 1 Ibm | 1 Cognos Analytics | 2026-09-14 | 5.4 Medium |
| IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their given name and surname to include malicious JavaScript code. When an administrator later accesses the user account management panel and views that user's permissions, the malicious JavaScript code is executed. This could result in the cookies from the administrator being compromised. | ||||
| CVE-2026-90816 | 1 Ffmpeg | 1 Ffmpeg | 2026-09-14 | 4.3 Medium |
| A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial of service. The attack is possible to be carried out remotely. Upgrading to version 8.1 and 9.0 is able to mitigate this issue. The patch is named 64fafd63f0b4. Upgrading the affected component is recommended. | ||||
| CVE-2026-67398 | 1 Webpros | 1 Whmcs | 2026-09-14 | N/A |
| Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions. | ||||
| CVE-2026-65331 | 1 Apple | 5 Ios And Ipados, Ipados, Iphone Os and 2 more | 2026-09-14 | 4.3 Medium |
| This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash. | ||||
| CVE-2026-64760 | 1 Apple | 3 Ios And Ipados, Ipados, Iphone Os | 2026-09-14 | 5.5 Medium |
| An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to leak sensitive kernel state. | ||||
| CVE-2026-43794 | 1 Apple | 5 Ios And Ipados, Ipados, Iphone Os and 2 more | 2026-09-14 | 8.8 High |
| A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption. | ||||
| CVE-2026-65346 | 1 Apple | 4 Ios And Ipados, Ipados, Iphone Os and 1 more | 2026-09-14 | 8.8 High |
| An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to arbitrary code execution. | ||||
| CVE-2026-65351 | 1 Apple | 5 Ios And Ipados, Ipados, Iphone Os and 2 more | 2026-09-14 | 4.3 Medium |
| This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash. | ||||
| CVE-2026-64782 | 1 Apple | 5 Ios And Ipados, Ipados, Iphone Os and 2 more | 2026-09-14 | 3.1 Low |
| A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash. | ||||
| CVE-2026-65347 | 1 Apple | 4 Ios And Ipados, Ipados, Iphone Os and 1 more | 2026-09-14 | 6.5 Medium |
| The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to a denial-of-service. | ||||
| CVE-2026-43760 | 1 Apple | 1 Macos | 2026-09-14 | 8.6 High |
| An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may be able to access user-sensitive data. | ||||
| CVE-2026-43795 | 1 Apple | 5 Ios And Ipados, Ipados, Iphone Os and 2 more | 2026-09-14 | 4.3 Medium |
| The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash. | ||||
| CVE-2026-65330 | 1 Apple | 4 Ios And Ipados, Ipados, Iphone Os and 1 more | 2026-09-14 | 6.5 Medium |
| The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory. | ||||
| CVE-2026-65340 | 1 Apple | 5 Ios And Ipados, Ipados, Iphone Os and 2 more | 2026-09-14 | 4.3 Medium |
| This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash. | ||||
| CVE-2026-65337 | 1 Apple | 5 Ios And Ipados, Ipados, Iphone Os and 2 more | 2026-09-14 | 4.3 Medium |
| This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash. | ||||
