Export limit exceeded: 51784 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (51784 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-107161 | 2 Cyrusimap, Redhat | 6 Cyrus-sasl, Enterprise Linux, Hardened Images and 3 more | 2026-10-09 | 7.5 High |
| A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application. | ||||
| CVE-2026-93565 | 2 Red Hat, Redhat | 23 Red Hat Amq Broker 7, Amq Broker, Amq Clients and 20 more | 2026-10-09 | 7.5 High |
| A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens in Real-Time Streaming Protocol (RTSP) requests. A remote attacker can exploit this by sending a specially crafted RTSP request, leading to method-token smuggling. This vulnerability allows an attacker to bypass method-based access controls and can also be used to launder malicious requests through Netty-based RTSP proxies, making them appear legitimate to backend systems. | ||||
| CVE-2026-93564 | 1 Redhat | 20 Amq Broker, Amq Broker 7, Apache Camel Quarkus and 17 more | 2026-10-09 | 7.5 High |
| A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to send specially crafted PROXY-protocol v2 headers. This can lead to memory exhaustion, resulting in a Denial of Service (DoS) for the affected system. | ||||
| CVE-2026-93558 | 2 Io.netty, Redhat | 24 Netty-codec-http, Amq Broker, Amq Broker 7 and 21 more | 2026-10-09 | 7.5 High |
| A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the application can respond. This leads to an unbounded growth of a per-connection queue, consuming excessive memory. Eventually, this can cause the Java Virtual Machine (JVM) to exhaust its heap, resulting in a Denial of Service (DoS) for the affected server. | ||||
| CVE-2026-75346 | 1 Eipstackgroup | 1 Opener | 2026-10-09 | 7.5 High |
| An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master through commit 76b95cf in the server-side CIP SetAttributeList service. This allows a remote attacker to cause a denial of service | ||||
| CVE-2026-75351 | 1 Eipstackgroup | 1 Opener | 2026-10-09 | 7.5 High |
| OpENer v2.3/commit 76b95cf, contains an out-of-bounds read in the server-side EtherNet/IP ForwardOpen connection-path parser. This allows a remote attacker to cause a denial of service. | ||||
| CVE-2026-108263 | 1 Iflytek | 1 Astron-agent | 2026-10-09 | 9.9 Critical |
| Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/code/code_node.py when CODE_EXEC_TYPE is not explicitly changed. LocalExecutor supplies complete Python builtins to dynamic code execution without the documented sandbox restrictions. An authenticated low-privilege tenant can execute code as root in the core-workflow container and use shared service and database credentials to bypass application-level tenant checks, read or modify other tenants' data, and disrupt shared services. This issue is fixed in version 1.1.2. | ||||
| CVE-2026-75348 | 1 Eipstackgroup | 1 Opener | 2026-10-09 | 7.5 High |
| An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master up to commit 76b95cf in the EtherNet/IP TCP SendRRData Common Packet Format parser. The issue occurs in CreateCommonPacketFormatStructure() when it parses recognized optional socket address information items of type 0x8000 or 0x8001 without first validating that the remaining CPF buffer contains the complete fixed sockaddr structure. This allows a remote attacker to cause a denial of service. | ||||
| CVE-2026-107818 | 1 Mariadb | 1 Server | 2026-10-09 | 8.4 High |
| MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mariadb.service unit used /run/mysqld/wsrep-new-cluster during the next service restart. A database user with FILE privilege and a secure-file-priv configuration permitting writes to /run/mysqld could create that file and inject attacker-controlled environment values into the restarted service. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2. | ||||
| CVE-2026-93566 | 2 Red Hat, Redhat | 22 Red Hat Amq Broker 7, Amq Broker, Amq Clients and 19 more | 2026-10-09 | 6.5 Medium |
| A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arbitrary HTTP requests. This vulnerability can lead to HTTP request smuggling, potentially resulting in information disclosure or other unauthorized actions. | ||||
| CVE-2026-93562 | 2 Io.netty, Redhat | 22 Netty-codec-http, Amq Broker, Amq Clients and 19 more | 2026-10-09 | 6.5 Medium |
| A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending specially crafted HTTP requests, an attacker can inject arbitrary HTTP requests, potentially bypassing security controls or accessing unauthorized resources. | ||||
| CVE-2026-108264 | 2026-10-09 | 9.1 Critical | ||
| Wizarr is an advanced user invitation and management system for Jellyfin, Plex, Emby, and other media servers. Prior to 2026.9.1, wizard step Markdown supplied through the editor or imported bundles was evaluated by app/blueprints/wizard/routes.py in the application's non-sandboxed Jinja2 environment with application globals exposed. An authenticated user able to create steps, or an administrator importing an untrusted bundle through POST /settings/wizard/import, could execute arbitrary Python when GET /wizard/{server}/{idx} rendered the stored step; app/jinja_filters.py and app/services/wizard_widgets.py contained additional evaluation sinks. This could execute operating-system commands as the application user, disclose the Flask SECRET_KEY, access connected service credentials and the database, and produce stored cross-site scripting. This issue is fixed in 2026.9.1. | ||||
| CVE-2026-92705 | 2026-10-09 | 7.8 High | ||
| Aegisub is a cross-platform advanced subtitle editor. From 3.2.0 to 3.4.2, Aegisub automatically loads Automation scripts referenced by `Automation Scripts` metadata in `ASS` subtitle projects without asking whether the user trusts the scripts or their authors. An attacker can distribute a crafted `ASS` file together with a referenced malicious Automation script, and opening the `AS` file executes arbitrary code with the privileges of the Aegisub process. From 3.4.0 to 3.4.2, inconsistent handling of embedded `NUL` characters between extension validation and filesystem operations additionally allows a crafted `ASS/Lua` polyglot to reference and execute itself as a single-file variant. The vulnerability is fixed in Aegisub 3.5.0. | ||||
| CVE-2026-107845 | 1 Contao | 1 Contao | 2026-10-09 | 9.3 Critical |
| Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. This issue is fixed in versions 5.3.50 and 5.7.12. | ||||
| CVE-2026-75353 | 1 Eipstackgroup | 1 Opener | 2026-10-09 | N/A |
| OpENer v2.3/ commit 76b95cf, contains an out-of-bounds read in the server-side EtherNet/IP ForwardOpen connection-path parser. This allows a remtoe attacker to cause a denial of service | ||||
| CVE-2026-73661 | 2 Freepbx, Sangoma | 2 Freepbx Framework, Freepbx | 2026-10-09 | 6.5 Medium |
| FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in amp_conf/htdocs/admin/libraries/Builtin/Restore.php. An authenticated user with sufficient backup-restore access or write access to backup files can thereby disable FreePBX authentication during restoration, bypassing the user-interface removal of AUTHTYPE=none. This issue is fixed in versions 16.0.47 and 17.0.30. | ||||
| CVE-2026-75352 | 1 Eipstackgroup | 1 Opener | 2026-10-09 | N/A |
| OpENer v2.3/commit 76b95cf, contains an integer underflow in the server-side EtherNet/IP ForwardOpen connection-path parser. This allows a remote attacker to cause a denial of service | ||||
| CVE-2026-75350 | 1 Eipstackgroup | 1 Opener | 2026-10-09 | 7.5 High |
| EIPStackGroup OpENer v2.3 / master commit 76b95cf contains a buffer overflow in the GetAttributeList() implementation for the EtherNet/IP Get_Attribute_List service. This allows a remote attacker to cause a denial of service | ||||
| CVE-2026-107817 | 1 Mariadb | 1 Server | 2026-10-09 | 4.4 Medium |
| MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mysql_json plugin assumed that imported MySQL tables contained valid MySQL binary JSON data. A specially prepared MySQL table containing invalid JSON data could cause out-of-bounds reads, information disclosure, or a server crash. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2. | ||||
| CVE-2026-107837 | 1 Riot-os | 1 Riot | 2026-10-09 | 8.2 High |
| RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, _receive() in sys/net/gnrc/network_layer/sixlowpan/gnrc_sixlowpan.c can route an undersized packet into SFF fragment handling after only a minimal payload check. The code then interprets the packet as a sixlowpan_frag_t or larger fragment header without verifying that the packet snip contains the required bytes. A remote attacker can send a malformed 6LoWPAN fragment that causes gnrc_sixlowpan_frag_recv() to read beyond the packet buffer, potentially disclosing memory and crashing the network stack. No fixed repository release is available as of this review. | ||||