Export limit exceeded: 103063 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (103063 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2016-2568 | 2 Freedesktop, Redhat | 2 Polkit, Enterprise Linux | 2026-10-08 | 7.8 High |
| pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. | ||||
| CVE-2026-96940 | 1 Microsoft | 7 Exchange Server 2016, Exchange Server 2019, Exchange Server Se and 4 more | 2026-10-08 | 8.8 High |
| An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests. An attacker who successfully exploited this vulnerability could perform script/content injection attacks and attempt to trick the user into disclosing sensitive information. To exploit the vulnerability, an attacker could send a specially crafted email message containing a malicious link to a user. Alternatively, an attacker could use a chat client to social engineer a user into clicking the malicious link. The security update addresses the vulnerability by correcting how Microsoft Exchange validates web requests. Note: In order to exploit this vulnerability, a user must click a maliciously crafted link from an attacker. | ||||
| CVE-2026-86404 | 1 Redhat | 7 Amq Broker, Build Of Apache Camel For Quarkus, Build Of Apache Camel For Spring Boot and 4 more | 2026-10-08 | 8.8 High |
| EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list and block-list are empty. When the allow-list is empty (size == 0), isTrustedType() returns true for ALL classes. This means all classes are deserializable by default. | ||||
| CVE-2026-107376 | 1 Webonyx | 1 Graphql-php | 2026-10-08 | 8.2 High |
| webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote attacker can submit deeply nested selection sets, object or list values, or list types that exhaust the PHP process stack during pre-validation parsing, before query validation and complexity controls run. The resulting SIGSEGV can terminate PHP-FPM workers or long-running Swoole, RoadRunner, ReactPHP, or CLI processes and cannot be caught by application-level exception handling. This issue is fixed in version 15.32.3. | ||||
| CVE-2026-81932 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.6 High |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | ||||
| CVE-2026-84247 | 1 Ibm | 1 Guardium Data Protection | 2026-10-08 | 8.1 High |
| IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability. | ||||
| CVE-2026-66087 | 1 Apache | 1 Dolphinscheduler | 2026-10-08 | 8.1 High |
| An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to operate task instance in projects they are not authorized to access through the * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/stop * /dolphinscheduler/projects/{projectCode}/task-instances/{taskInstanceId}/savepoint This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue. | ||||
| CVE-2026-66084 | 1 Apache | 1 Dolphinscheduler | 2026-10-08 | 8.1 High |
| An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/projects/{projectCode}/task-definition/{code}/with-upstream endpoint. The endpoint fails to verify that the task definition identified by code belongs to the project specified by projectCode. An authenticated user can supply the code of a project they are authorized to access together with a task definition code from another project, bypassing project access restrictions and modifying the target task definition and its upstream dependencies. This vulnerability can compromise workflow integrity and disrupt task execution in unauthorized projects.This issue affects Apache DolphinScheduler: before 3.4.3. Users are recommended to upgrade to version 3.4.3, which fixes the issue. | ||||
| CVE-2023-32028 | 1 Microsoft | 7 Ole Db Driver 18 For Sql Server, Ole Db Driver 19 For Sql Server, Ole Db Driver For Sql Server and 4 more | 2026-10-08 | 7.8 High |
| Microsoft SQL OLE DB Remote Code Execution Vulnerability | ||||
| CVE-2022-2522 | 1 Vim | 1 Vim | 2026-10-08 | 7.8 High |
| Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0061. | ||||
| CVE-2022-2345 | 2 Fedoraproject, Vim | 2 Fedora, Vim | 2026-10-08 | 7.8 High |
| Use After Free in GitHub repository vim/vim prior to 9.0.0046. | ||||
| CVE-2022-2344 | 2 Fedoraproject, Vim | 2 Fedora, Vim | 2026-10-08 | 7.8 High |
| Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0045. | ||||
| CVE-2022-2343 | 2 Fedoraproject, Vim | 2 Fedora, Vim | 2026-10-08 | 7.8 High |
| Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0044. | ||||
| CVE-2022-2287 | 2 Fedoraproject, Vim | 2 Fedora, Vim | 2026-10-08 | 7.1 High |
| Out-of-bounds Read in GitHub repository vim/vim prior to 9.0. | ||||
| CVE-2022-2286 | 2 Fedoraproject, Vim | 2 Fedora, Vim | 2026-10-08 | 7.8 High |
| Out-of-bounds Read in GitHub repository vim/vim prior to 9.0. | ||||
| CVE-2022-2285 | 3 Debian, Fedoraproject, Vim | 3 Debian Linux, Fedora, Vim | 2026-10-08 | 7.8 High |
| Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0. | ||||
| CVE-2022-2284 | 2 Fedoraproject, Vim | 2 Fedora, Vim | 2026-10-08 | 7.8 High |
| Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0. | ||||
| CVE-2022-2210 | 2 Fedoraproject, Vim | 2 Fedora, Vim | 2026-10-08 | 7.8 High |
| Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. | ||||
| CVE-2022-2207 | 2 Fedoraproject, Vim | 2 Fedora, Vim | 2026-10-08 | 7.8 High |
| Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||||
| CVE-2022-2206 | 2 Fedoraproject, Vim | 2 Fedora, Vim | 2026-10-08 | 7.8 High |
| Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||||