Export limit exceeded: 386752 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (386752 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-27347 | 2 Crocoblock, Wordpress | 2 Jetpopup, Wordpress | 2026-09-04 | 5.3 Medium |
| Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JetPopup: from n/a through 2.0.20.2. | ||||
| CVE-2026-18957 | 1 Menulux | 1 Menulux Portal | 2026-09-04 | 5.4 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS. This issue affects Menulux Portal: before 20260903211448. | ||||
| CVE-2026-19043 | 1 Menulux | 1 Menulux Portal | 2026-09-04 | 4.3 Medium |
| Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Menulux Portal: before 20260903211448. | ||||
| CVE-2026-19051 | 1 Menulux | 1 Menulux Portal | 2026-09-04 | 7.1 High |
| Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: before 20260903211448. | ||||
| CVE-2026-19080 | 1 Menulux | 1 Menulux Portal | 2026-09-04 | 7.5 High |
| Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448. | ||||
| CVE-2026-18198 | 1 Tac Information | 1 Goldenhorn Oneit | 2026-09-04 | 8.8 High |
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection. This issue affects GOLDENHORN ONEIT: before Göbeklitepe. | ||||
| CVE-2026-85649 | 1 Chewkeanho | 1 Software-actualizer | 2026-09-04 | 7.9 High |
| (Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh. The installer invokes mkpasswd to generate yescrypt password hashes but does not check the command's return value and unconditionally accepts the result. If mkpasswd fails to generate a yescrypt hash, for example because an incompatible mkpasswd implementation or an environment without yescrypt support is used, the resulting password hash variable can be empty and the build proceeds. The resulting image can therefore contain empty password fields for the root and alpha accounts, potentially permitting passwordless authentication depending on the authentication configuration. | ||||
| CVE-2026-52691 | 1 Apache | 1 Griffin Hive Metastore Module | 2026-09-04 | N/A |
| ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module. This issue affects Apache Griffin Hive Metastore Module: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | ||||
| CVE-2026-77818 | 1 Yordam | 1 Library Information And Document Automation Program | 2026-09-04 | 6.1 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Content Spoofing. This issue affects Library Information and Document Automation Program: from v22.1 before v22.2. | ||||
| CVE-2026-79419 | 2026-09-04 | N/A | ||
| A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao/Imagens.aspx endpoint, allowing an unauthenticated attacker to inject arbitrary JavaScript code that is reflected and executed in the context of a victim's browser. | ||||
| CVE-2026-71223 | 1 Redhat | 1 Gfs2-utils | 2026-09-04 | 7.0 High |
| An integer overflow vulnerability was found in gfs2-utils. The resource group allocation size computation on 32-bit platforms causes an undersized buffer allocation followed by heap out-of-bounds writes when processing crafted GFS2 filesystem images. This vulnerability does not affect 64-bit builds. | ||||
| CVE-2026-19649 | 1 Ibm | 2 App Connect Enterprise, Integration Bus For Zos | 2026-09-04 | 6.2 Medium |
| IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of database credentials. | ||||
| CVE-2026-8447 | 1 Ibm | 1 Langflow Oss | 2026-09-04 | 6.1 Medium |
| IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface. | ||||
| CVE-2026-85700 | 1 Onyx | 1 Onyx | 2026-09-04 | 6.5 Medium |
| Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authenticated user to read admin-defined API keys. Attackers with basic authentication can call GET /tool/{tool_id} or GET /tool endpoints to retrieve plaintext authorization headers and third-party API credentials, then use them to directly access upstream APIs. | ||||
| CVE-2026-85590 | 2 Phpmyfaq, Thorsten | 2 Phpmyfaq, Phpmyfaq | 2026-09-04 | N/A |
| phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability in its two-factor authentication (TOTP) disable functionality. The removeTwofactorConfig() handler (reachable via POST /api/user/remove-twofactor) verifies only that the user is logged in and that a valid CSRF token is supplied, then disables TOTP without requiring password re-entry or a current TOTP code. The same downgrade is also reachable inline via PUT /api/user/data/update, which accepts a plain twofactor_enabled form field under the same session+CSRF-only guard. An attacker who has hijacked a user's session can silently strip two-factor protection from any account, including administrator accounts, after which password-only authentication succeeds. | ||||
| CVE-2026-85580 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2026-09-04 | 6.5 Medium |
| SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read the protected publishAccess.json file by requesting case-variant paths like PublishAccess.json to disclose sensitive publish-access configuration and metadata. | ||||
| CVE-2026-85403 | 1 Code-projects | 1 Doctor Appointment System | 2026-09-04 | 7.3 High |
| A flaw has been found in code-projects Doctor Appointment System 1.0. This issue affects some unknown processing of the file /contactus.php. This manipulation of the argument firstname causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. | ||||
| CVE-2026-85397 | 1 Code-projects | 1 Hospital Information System | 2026-09-04 | 7.3 High |
| A vulnerability was determined in code-projects Hospital Information System 1.0. This impacts the function findBySearch of the file addReq.php. This manipulation of the argument Search causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | ||||
| CVE-2026-85379 | 1 Light0011 | 1 Cms | 2026-09-04 | 7.3 High |
| A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects the function ChapterModel::searchChapter of the file App/Home/Controller/ChapterController.class.php of the component Query Builder. The manipulation of the argument content results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-85223 | 1 D-link | 1 Dns-340l | 2026-09-04 | 9.9 Critical |
| A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used. | ||||