Search Results (102922 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-106560 1 Backstage 2 Backstage, Plugin-scaffolder-backend-module-confluence-to-markdown 2026-10-09 7.1 High
Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown package is affected by improper repository path validation in a scaffolder backend module. An authenticated user who can execute an affected template and control its repository file location may cause generated content to be written outside the task workspace, within locations writable by the Backstage backend process. This issue is fixed in version 0.3.25.
CVE-2026-62251 1 Sipcapture 1 Homer 2026-10-09 8.1 High
Homer is open source telecom observability software. Prior to version 11.0.283, the `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used throughout the rest of the codebase. Any authenticated user can execute arbitrary SQL statements against all data accessible through the FlightSQL service. Version 11.0.283 patches the issue.
CVE-2026-76484 1 Cisco 1 Cisco License On-prem 2026-10-09 8.8 High
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76484 are related to issues with insufficient protection against code injection that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-94.
CVE-2026-76463 1 Cisco 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more 2026-10-09 8.8 High
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76463 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
CVE-2026-76468 1 Cisco 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more 2026-10-09 8.2 High
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76468 are related to improper input validation that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20.
CVE-2026-76469 1 Cisco 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more 2026-10-09 7.4 High
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76469 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-691.
CVE-2026-76470 1 Cisco 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more 2026-10-09 8.8 High
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76470 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-682.
CVE-2026-76467 1 Cisco 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more 2026-10-09 7.5 High
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76467 are related to issues concerning improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
CVE-2026-76472 1 Cisco 4 Campus Gateway Software, Meraki Mr Wireless Access Point Software, Meraki Mv Firmware and 1 more 2026-10-09 8.8 High
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-76472 are related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74.
CVE-2026-106557 1 Backstage 2 Backstage, Plugin-techdocs-node 2026-10-09 7.7 High
Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package did not sufficiently validate TechDocs Markdown extension configuration. An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary, potentially exposing backend-host data or internal network resources. This issue is fixed in versions 1.14.6 and 1.15.4 when pymdown-extensions 10.21.3 or later is also used, normally through mkdocs-techdocs-core 1.7.0 or later.
CVE-2026-92542 2 Docker, Moby 3 Docker Engine, Docker Engine Overlay Network Driver, Moby Overlay Network Driver 2026-10-09 7.1 High
The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged datagrams sent by user processes. Any packet sent from the host network namespace of a Linux Swarm node is encrypted with the overlay-network IPsec parameters which meets the following criteria: - UDP datagram - Destination port is the Swarm data-path port - Datagram starts with a VXLAN header for the VNI of an encrypted overlay network which any running container on the node is connected to
CVE-2026-94662 2 Unlimited-elements, Wordpress-extensions 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor 2026-10-09 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Stored XSS. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.19.
CVE-2026-94670 2 Wordpress-extensions, Wpeverest 2 Everest Forms, Everest Forms 2026-10-09 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Everest Forms allows Reflected XSS. This issue affects Everest Forms: from n/a through 3.6.1.
CVE-2026-95534 2 Unlimited-elements, Wordpress-extensions 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor 2026-10-09 8.8 High
Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Object Injection. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.19.
CVE-2026-95595 2 Fontsplugin, Wordpress-extensions 2 Disable And Remove Google Fonts Gdpr Dsgvo Friendly, Disable And Remove Google Fonts Gdpr Dsgvo Friendly 2026-10-09 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fontsplugin Disable and Remove Google Fonts | GDPR & DSGVO friendly disable-remove-google-fonts allows Reflected XSS. This issue affects Disable and Remove Google Fonts | GDPR & DSGVO friendly: from n/a through 2.0.2.
CVE-2026-96335 2 Wordpress-extensions, Wpmudev 2 Forminator, Forminator Forms 2026-10-09 7.5 High
Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Forminator: from n/a through 1.57.2.
CVE-2026-56851 1 Golang 1 Text 2026-10-09 7.5 High
The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer.
CVE-2026-103371 1 Apache 1 Geode 2026-10-09 7.5 High
Insertion of Sensitive Information into Log File in Apache Geode Web Management. This issue affects Apache Geode: from 2.0.0 before 2.0.3. Users are recommended to upgrade to version 2.0.3, which fixes the issue.
CVE-2026-107161 2 Cyrusimap, Redhat 6 Cyrus-sasl, Enterprise Linux, Hardened Images and 3 more 2026-10-09 7.5 High
A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application.
CVE-2026-88648 1 Gnu 1 Gnutls 2026-10-09 7.4 High
Incomplete X.509 implementation in GnuTLS v3.8.13 allows attackers controlling a subordinate Certificate Authority to bypass cross-domain PKI restrictions and issue unauthorized certificates.