Export limit exceeded: 14803 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 10081 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10081 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-75573 | 1 Mongodb | 1 Bi Connector | 2026-09-23 | 4.4 Medium |
| In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access the associated TLS client key. | ||||
| CVE-2026-59302 | 2 Spring, Vmware | 2 Spring Cloud Stream, Spring Cloud Function | 2026-09-23 | 3.1 Low |
| Potential for logging sensitive data in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6 | ||||
| CVE-2026-96560 | 1 Modeltc | 1 Lightllm | 2026-09-23 | 9.8 Critical |
| LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel that deserializes attacker-supplied data. Attackers can send malicious pickled objects to the exposed RPyC ThreadedServer to execute arbitrary code with the privileges of the LightLLM service account. | ||||
| CVE-2026-59903 | 1 Netty | 1 Netty | 2026-09-23 | 6.5 Medium |
| Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN to reuse authenticated responses across users and disclose sensitive information. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final. | ||||
| CVE-2026-95897 | 1 Dask | 1 Dask | 2026-09-23 | 5.5 Medium |
| A security vulnerability has been detected in Dask up to 2026.8.0. This affects the function from_npy_stack of the file dask/array/core.py of the component Loader. Such manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-95815 | 1 Openclaw | 1 Openclaw | 2026-09-23 | 6.3 Medium |
| OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obtain diagnostic archives can recover unrotated keys and replay them in forged deep links to submit agent requests without local confirmation prompts. | ||||
| CVE-2026-67615 | 1 Apereo Foundation | 1 Openequella | 2026-09-23 | 8.8 High |
| openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that allows any authenticated non-guest user to execute arbitrary code by exploiting Java deserialization in the HTTP invoker endpoint at /invoker/*. Attackers can bypass the class-name denylist enforced by PluginAwareObjectInputStream by nesting a serialized payload inside a java.security.SignedObject, causing the inner stream to be deserialized by a separate ObjectInputStream that does not apply the denylist, ultimately reaching a JNDI sink and enabling code execution. | ||||
| CVE-2026-19202 | 1 Google | 1 Mcp-toolbox-sdk-python | 2026-09-23 | N/A |
| A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences. If an application uses the SDK to authenticate to two or more different audiences within the same process, the module-level token cache fails to key its cached tokens by the requested audience. Consequently, a valid, unexpired token minted for a sensitive service (Service A) can be retrieved from the cache and sent to a secondary service (Service B). An attacker who operates, compromises, or monitors traffic to Service B can capture this token and replay it to impersonate the victim application against Service A. | ||||
| CVE-2026-95928 | 1 Recommenders-team | 1 Recommenders | 2026-09-23 | 5.5 Medium |
| A security flaw has been discovered in recommenders-team recommenders up to 1.2.1. This impacts the function pickle.load of the file recommenders/models/newsrec/io/mind_iterator.py of the component Dict Loading. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-81657 | 1 Ibm | 1 Guardium Data Protection | 2026-09-23 | 9.8 Critical |
| IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data. | ||||
| CVE-2026-84686 | 1 Redhat | 1 Ansible Automation Platform | 2026-09-23 | 7.6 High |
| A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Notification template password fields are encrypted with a key derived from the secret key, the object primary key, and the field name, but not the subfield name, and the API returns the full ciphertext of a password subfield after the notification type is changed to one that does not define that subfield. A user with administrative access to a single notification template, but without any wider privilege, can switch the template type to reveal the stored ciphertext, replant that ciphertext into a webhook password field pointing at a server they control, and trigger a test notification. The controller decrypts the replayed ciphertext to the original plaintext and sends it to the attacker's server in an HTTP Basic authorization header, allowing recovery of Slack, PagerDuty, Twilio, AWS SNS, and Grafana credentials the administrator was only permitted to use, not read. | ||||
| CVE-2026-87766 | 1 Redhat | 3 Enterprise Linux, Hardened Images, Hummingbird | 2026-09-22 | 8.8 High |
| A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0. | ||||
| CVE-2026-88623 | 1 Nuuo | 1 Network Video Recorder | 2026-09-22 | 7.5 High |
| NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is received, and fopen() is used to open the URL in binary read-only mode. The content is then written to the /tmp/ directory, with the filename derived from basename() of the URL. This operation requires no authentication. | ||||
| CVE-2026-18508 | 2 Gnu, Redhat | 8 Tar, Discovery, Enterprise Linux and 5 more | 2026-09-22 | 4.4 Medium |
| A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction. | ||||
| CVE-2026-28325 | 1 Solarwinds | 1 Observability Self-hosted | 2026-09-22 | 8.8 High |
| SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode. | ||||
| CVE-2026-78627 | 1 Okta | 2 Hyperdrive, Okta Hyperdrive Integration Plugin | 2026-09-22 | 7.3 High |
| The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the workstation. | ||||
| CVE-2026-78631 | 1 Okta | 2 Hyperdrive, Okta Hyperdrive Agent | 2026-09-22 | 5.3 Medium |
| The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authentication credential readable by any local user with access to the log file. | ||||
| CVE-2026-25826 | 1 Keyfactor | 1 Signserver | 2026-09-22 | 4.9 Medium |
| An issue was discovered in Keyfactor SignServer before 7.6.0. The attribute ATTRIBUTESFILE in PKCS11CryptoToken can be set to a readable file but not an accepted file (i.e., recognized with attributes). In this case, an error is thrown which - together with the error - also prints the content of the file to the application server log. This gives a user that has both SignServer admin access and access to read the output of the server log (i.e., if remote syslog shipping is configured), the possibility to read the content of files accessible by the local user JBoss. | ||||
| CVE-2026-69771 | 1 Microsoft | 8 Windows 11 23h2, Windows 11 23h2, Windows 11 24h2 and 5 more | 2026-09-22 | 4.7 Medium |
| Improper link resolution before file access ('link following') in Windows Container Manager Service allows an authorized attacker to bypass a security feature locally. | ||||
| CVE-2026-93088 | 1 Sglang | 1 Sglang | 2026-09-22 | 9.8 Critical |
| SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and passes the final frame of received multipart messages directly to pickle.loads() before any validation occurs. | ||||