Export limit exceeded: 404442 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (404442 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-106507 2 Backstage, Linuxfoundation 4 Backstage, Plugin-techdocs-node, Backstage and 1 more 2026-10-09 5.3 Medium
Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. Unsafe path resolution in TechDocs source tree handling allows an authenticated user who can register documentation sources to include content from outside the intended documentation boundary. Depending on deployment, this may expose files readable by the build process. This issue is fixed in version 1.15.4.
CVE-2026-88931 2026-10-09 5.3 Medium
The Social Web Suite WordPress plugin through 4.1.12 does not restrict which of its settings may be written through an unauthenticated endpoint, allowing attackers to overwrite arbitrary Social Web Suite WordPress plugin through 4.1.12 options, including the shared secret that guards its own privileged endpoints.
CVE-2026-87841 2026-10-09 5.3 Medium
The UnitechPay WordPress plugin through 1.0.6.3 does not verify the authenticity of the payment notifications it receives, allowing unauthenticated attackers to mark orders placed through it as paid without any payment being made, as well as to force other orders into a failed state.
CVE-2026-75345 1 Eipstackgroup 1 Opener 2026-10-09 7.5 High
OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected explicit messaging path. This allows a remote attacker to cause a denial of service.
CVE-2026-106508 2 Backstage, Linuxfoundation 4 Backstage, Plugin-techdocs-node, Backstage and 1 more 2026-10-09 5.3 Medium
Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. When using the local TechDocs publisher (techdocs.publisher.type: 'local'), it was possible for the documentation serving endpoint to follow filesystem references outside the intended documentation tree, potentially exposing host files to authenticated users. This is mitigated by the fact that exploration requires preconditions that do not arise through normal MkDocs operation. Cloud-based publishers (S3, GCS, Azure Blob Storage) are not affected. This issue is fixed in version 1.15.4.
CVE-2026-17615 1 Redhat 20 Apache Camel Quarkus, Apicurio Registry, Build Keycloak and 17 more 2026-10-09 7.5 High
A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability.
CVE-2026-20589 2 Mediatek, Mediatek, Inc. 51 Mt2718, Mt2718 Firmware, Mt6768 and 48 more 2026-10-09 6.7 Medium
In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV-9606.
CVE-2026-20542 1 Mediatek 39 Mediatek Chipset, Mt2718, Mt2718 Firmware and 36 more 2026-10-09 6.7 Medium
In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11076799; Issue ID: MSV-8143.
CVE-2026-20541 2 Mediatek, Mediatek, Inc. 167 Mt2716, Mt2716 Firmware, Mt2735 and 164 more 2026-10-09 5.3 Medium
In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8911.
CVE-2026-20540 1 Mediatek 167 Mediatek Chipset, Mt2716, Mt2716 Firmware and 164 more 2026-10-09 5.3 Medium
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8912.
CVE-2026-20539 2 Mediatek, Mediatek, Inc. 167 Mt2716, Mt2716 Firmware, Mt2735 and 164 more 2026-10-09 5.3 Medium
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8913.
CVE-2026-20538 2 Mediatek, Mediatek, Inc. 167 Mt2716, Mt2716 Firmware, Mt2735 and 164 more 2026-10-09 5.3 Medium
In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8914.
CVE-2026-20544 2 Mediatek, Mediatek, Inc. 119 Mt6739, Mt6739 Firmware, Mt6761 and 116 more 2026-10-09 6.8 Medium
In meta, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11049530 / ALPS11480843; Issue ID: MSV-7935.
CVE-2026-106509 2 Backstage, Linuxfoundation 4 Backstage, Plugin-techdocs-node, Backstage and 1 more 2026-10-09 7.7 High
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs theme configuration in techdocs. When TechDocs is configured to build documentation locally or in a container, a user with write access to a registered repository can include configuration values in mkdocs.yml that cause arbitrary code execution during the documentation build process. This issue is fixed in versions 1.14.6 and 1.15.4.
CVE-2026-107814 1 Mariadb 1 Server 2026-10-09 8.4 High
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB RPM packages created the dedicated mysql service account with the database data directory as its home directory. A database user with the FILE privilege could write startup dot-files such as .bash_profile into $HOME, and those files could execute when an administrator opened a login shell for the mysql account. Debian packages are not affected because they use /nonexistent as the account home. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.
CVE-2026-108156 1 Netease-youdao 1 Lobsterai 2026-10-09 7.1 High
LobsterAI 2026.5.27 through 2026.9.23 contains an external control of file path vulnerability in the skills:delete IPC handler that trusts the openclawSourceDir value from a skill's _meta.json during uninstall. Attackers who convince a user to install a crafted skill can make uninstallation recursively delete arbitrary user-writable directories, such as the home directory, since the security scanner never inspects _meta.json.
CVE-2026-48484 1 Pyload 1 Pyload 2026-10-09 6.5 Medium
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the API `rpc` function in `api_blueprint.py` handles `multipart/form-data` uploads by reading the whole content of the uploaded file into memory with `file.read()`. This occurs before the data is sent to the underlying function. Since there is no size limit set at this point, a large file upload can exhaust the server's available memory which led to process termination. Version 0.5.0b3.dev101 contains a patch.
CVE-2026-96396 1 Canva 1 Affinity 2026-10-09 4.9 Medium
The Affinity by Canva application for macOS before 3.3.1 (October 2026 release) did not safely calculate the size of an image buffer when generating QuickLook thumbnails and previews of Affinity document files, leading to an integer overflow and a heap-based buffer overflow. A threat actor could craft an Affinity document that, when displayed or previewed by a user in Finder, could corrupt heap memory and cause the thumbnail or preview extension to crash.
CVE-2026-96395 1 Canva 1 Affinity 2026-10-09 3.6 Low
The Affinity by Canva app for macOS before 3.3.1 (October 2026 release) did not perform adequate bounds checking when generating QuickLook thumbnails and previews of Affinity document files, leading to an out-of-bounds heap read. A threat actor could craft an Affinity document that, when displayed or previewed by a user in Finder, could disclose the contents of adjacent heap memory, including memory addresses, in the rendered thumbnail or preview image.
CVE-2026-96394 1 Canva 1 Affinity 2026-10-09 2.9 Low
The Affinity by Canva application for macOS before 3.3.1 (October 2026 release) did not validate image dimensions against the size of the pixel data when generating QuickLook thumbnails and previews of Affinity document files, leading to an out-of-bounds heap read. A threat actor could craft an Affinity document that, when displayed or previewed by a user in Finder, could disclose the contents of adjacent heap memory in the rendered thumbnail or preview image, or cause the thumbnail or preview extension to crash.