Export limit exceeded: 386752 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (386752 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-85453 | 1 Themoos | 1 Core-moos | 2026-09-04 | 6.1 Medium |
| MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set variable values containing script payloads that execute in the browser of operators viewing the web interface. | ||||
| CVE-2026-85454 | 1 Themoos | 1 Core-moos | 2026-09-04 | 6.1 Medium |
| MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer. Attackers controlling the serial line can send a full-length telegram to trigger the off-by-one write, corrupting the stack and potentially enabling code execution. | ||||
| CVE-2026-85455 | 1 Themoos | 1 Core-moos | 2026-09-04 | 8.2 High |
| MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted short packet to read memory before authentication. | ||||
| CVE-2026-85456 | 1 Moos-ivp | 1 Moos-ivp | 2026-09-04 | 5.5 Medium |
| MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowing attackers to write files outside the split directory. Attackers can supply crafted alog files with backslash sequences in variable names to escape the output directory and append to arbitrary files on Windows systems. | ||||
| CVE-2026-19306 | 1 Ibm | 1 Langflow Oss | 2026-09-04 | 7.7 High |
| IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other tenants' upload directories) — by supplying absolute paths or traversal sequences in the files parameter of an authenticated build request. The file contents were embedded as text attachments in the language model prompt and transmitted to the configured model endpoint, resulting in confidential data exfiltration. This bypassed the LANGFLOW_RESTRICT_LOCAL_FILE_ACCESS=true containment boundary, which was enforced for other file-reading components but not for the Chat Input to Message attachment pipeline. | ||||
| CVE-2026-85146 | 1 Lightstar | 1 Smartit Desktop Manager | 2026-09-04 | 9.8 Critical |
| SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code. | ||||
| CVE-2026-85147 | 1 Lightstar | 1 Smartit Desktop Manager | 2026-09-04 | 7.5 High |
| SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication. | ||||
| CVE-2026-85148 | 1 Lightstar | 1 Smartit Desktop Manager | 2026-09-04 | 9.8 Critical |
| SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts. | ||||
| CVE-2026-85149 | 1 Lightstar | 1 Smartit Desktop Manager | 2026-09-04 | 5.3 Medium |
| SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host. | ||||
| CVE-2026-11613 | 2 Divi Engine, Wordpress | 2 Divi Ajax Filter, Wordpress | 2026-09-04 | 9.8 Critical |
| The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. This vulnerability is only exploitable when the loop_templates parameter is set to 'custom-template'. | ||||
| CVE-2026-66840 | 1 Xing | 1 Xing Cptrans-me-x | 2026-09-04 | N/A |
| XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked. | ||||
| CVE-2026-69657 | 1 Xing | 1 Xing Cptrans-me-x | 2026-09-04 | N/A |
| XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device. | ||||
| CVE-2026-19645 | 1 Ibm | 1 Mq Agent | 2026-09-04 | 6.5 Medium |
| IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended periods — rangingfrom tens of seconds to over ten minutes per request. When multiple such requests are sentconcurrently, the agent worker pool becomes exhausted, causing all other IBM MQ Console users toexperience degraded performance or complete unavailability of the AI Agent feature. | ||||
| CVE-2026-70403 | 1 Xing | 1 Xing Cptrans-me-x | 2026-09-04 | N/A |
| XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device. | ||||
| CVE-2026-15354 | 2 Mauro Cassani, Wordpress | 2 Acpt (premium), Wordpress | 2026-09-04 | 9.8 Critical |
| The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling `wp_update_user()`. This makes it possible for unauthenticated attackers to overwrite any WordPress user's email address and password, including an administrator's, and take over the account. Successful exploitation requires a public ACPT user form that permits anonymous submissions. | ||||
| CVE-2026-80181 | 1 Apache | 1 Allura | 2026-09-04 | N/A |
| Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue. | ||||
| CVE-2026-6217 | 1 Pik Online Software | 1 Pik Online Portal | 2026-09-04 | 6.3 Medium |
| Use of a One-Way hash without a salt vulnerability in Pik Online Software Solutions Inc. Pik Online Portal allows Cryptanalysis. This issue affects Pik Online Portal: through 3.5.1. | ||||
| CVE-2026-81302 | 1 Jalinfotec | 3 Pallet Control, Palletcontrol, Palletcontrol Cloud | 2026-09-04 | N/A |
| PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affected product. | ||||
| CVE-2026-81665 | 2 Corosync, Redhat | 4 Corosync, Enterprise Linux, Openshift and 1 more | 2026-09-04 | 7.5 High |
| A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control. | ||||
| CVE-2026-81666 | 2 Corosync, Redhat | 4 Corosync, Enterprise Linux, Openshift and 1 more | 2026-09-04 | 6.5 Medium |
| An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems due to an integer overflow in the calculation of the expected message length, allowing a crafted network packet to trigger an out-of-bounds memory access that crashes the Corosync daemon. This results in a denial of service for the affected cluster node. The overflow does not occur on 64-bit systems, where the length calculation is correctly performed in 64-bit arithmetic. | ||||