Export limit exceeded: 51783 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (51783 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-105842 2 Lrzsz Project, Uwe Ohse 2 Lrzsz, Lrzsz 2026-10-09 6.4 Medium
lrzsz before 0.13.0 contains a heap-based buffer overflow vulnerability in procheader() of the lrz receive utility when copying overlong sender-supplied filenames into Pathname. Malicious ZMODEM senders can supply filenames up to 8192 bytes, overflowing the buffer via sprintf() in pipe mode or strcpy() to corrupt heap memory and crash lrz.
CVE-2026-105801 1 Openapi-generators 1 Openapi-python-client 2026-10-09 N/A
openapi-python-client generates Python clients from OpenAPI documents. Prior to 0.29.1, the generator does not safely neutralize malicious OpenAPI document content before rendering string, docstring, and f-string contexts in generated Python. The generated Python client can contain attacker-controlled Python that executes when a user imports the client, affecting the importing environment's integrity and potentially its confidentiality and availability. This issue is fixed in version 0.29.1.
CVE-2026-105844 1 Payloadcms 2 Payload, Plugin-import-export 2026-10-09 N/A
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an unauthenticated user can submit prototype-sensitive field paths when @payloadcms/plugin-import-export is enabled, causing unintended application behavior that can lead to remote code execution. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.
CVE-2026-106107 1 Quasarframework 2 App-vite, Quasar 2026-10-09 N/A
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 3.3.0, several @quasar/app-vite SSR and SSG rendering paths interpolated ssrContext.nonce directly into quoted HTML attributes. An application that derives or overrides this value with attacker-controlled data can allow a quote to terminate the nonce attribute and inject additional attributes or markup into generated HTML across development and production SSR or SSG output. Cryptographically generated base64 or base64url nonces are not affected because they lack HTML attribute delimiters. This issue is fixed in version 3.3.0.
CVE-2026-104945 1 Tp-link 1 Tapo C500 V2 2026-10-09 N/A
TP-Link Tapo C500 v2.0 contains an out-of-bounds stack write vulnerability in its ONVIF PTZ SOAP handlers. An authenticated ONVIF client can submit an excessive number of preset-related elements, causing writes beyond the bounds of fixed-size stack arrays and resulting in a crash of the affected service. Successful exploitation may allow an authenticated attacker to cause the affected service to crash, resulting in a denial-of-service condition. Repeated exploitation may repeatedly disrupt camera management and PTZ-related functionality until the service recovers or restarts.
CVE-2026-82162 1 Dell 1 Command|configure 2026-10-09 7.4 High
Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain an Improper Handling of Mixed Encoding vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of Privileges.
CVE-2026-106442 1 Hydra-ecosystem 1 Hydra 2026-10-09 7.8 High
Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the effective callable selected by the target field. Execution wrappers such as timeit.timeit, executable deserialization through pickle.loads, aliases, callable-returning helpers, generic dispatch, and deferred calls can obscure or defer the effective target and bypass name-based authorization. An attacker who causes an application to instantiate untrusted Hydra configuration can use these gaps to execute code with the application's privileges. This issue is fixed in versions 1.3.6 and 1.4.0.dev9.
CVE-2026-76741 1 Hewlett Packard Enterprise (hpe) 1 Aos-switch 2026-10-09 6.5 Medium
Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an authenticated remote attacker to cause a denial-of-service condition on the affected system.
CVE-2026-76744 1 Hewlett Packard Enterprise (hpe) 1 Aos-switch 2026-10-09 9.8 Critical
Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code.
CVE-2026-76745 1 Hewlett Packard Enterprise (hpe) 1 Aos-switch 2026-10-09 9.6 Critical
Memory corruption vulnerabilities exist in AOS-S that are reachable by an unauthenticated adjacent attacker. Successful exploitation could allow an attacker to execute arbitrary code.
CVE-2026-76746 1 Hewlett Packard Enterprise (hpe) 1 Aos-switch 2026-10-09 9.3 Critical
An unauthenticated buffer overflow vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated adjacent attacker to expose sensitive memory contents and cause a denial of service on the affected device.
CVE-2026-76747 1 Hewlett Packard Enterprise (hpe) 1 Aos-switch 2026-10-09 9.1 Critical
Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to expose sensitive memory contents and cause a denial of service on the device.
CVE-2026-106063 2 Gimp, Redhat 2 Gimp, Enterprise Linux 2026-10-09 6.3 Medium
A heap-based buffer overflow was found in GIMP’s DICOM export plug-in. When exporting an image with extremely large width and height, the export path allocates a buffer using a 32-bit width * height (and bytes-per-pixel) product that can overflow. GEGL then writes the full uncompressed extent into the undersized buffer, after integer overflow in the allocation size
CVE-2026-102162 1 Arista 1 Wi-fi Access Points 2026-10-09 8.8 High
On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition or potentially execute arbitrary code on the device. The wireless gateway service is automatically restarted after a crash, allowing repeated exploitation attempts.
CVE-2026-102168 1 Arista 1 Wi-fi Access Points 2026-10-09 6.5 Medium
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is not possible.
CVE-2026-102164 1 Arista 1 Wi-fi Access Points 2026-10-09 3.1 Low
On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific configuration unique to the VESPA use-case), a wireless client associated to the tunnelled SSID can send a crafted packet, causing the access point to reveal memory contents in network traffic. No write primitive or remote code execution is possible.
CVE-2026-102167 1 Arista 1 Wi-fi Access Points 2026-10-09 7.5 High
On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access point's wired uplink.
CVE-2026-102165 1 Arista 1 Wi-fi Access Points 2026-10-09 7.5 High
On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the service to crash or potentially achieve remote code execution. This exploit requires an uncommonly used non-default streaming mode.
CVE-2026-106448 1 Stablelib 1 Stablelib 2026-10-09 N/A
StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor CBOR map decoding path creates ordinary JavaScript objects and assigns attacker-controlled keys with bracket assignment. A map key named __proto__ invokes the inherited prototype setter instead of creating an ordinary own property, allowing the decoded object's prototype to contain attacker-controlled authorization or feature-flag values. Downstream code that trusts normal property lookup or merges the decoded object can therefore make security-sensitive decisions using inherited attacker data. This issue is fixed in version 2.0.4.
CVE-2026-106062 2 Gimp, Redhat 2 Gimp, Enterprise Linux 2026-10-09 7.8 High
A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height, and pitch can be computed using 32-bit arithmetic that overflows. The allocated buffer is too small for the amount of pixel data written through GEGL, following integer overflow in size calculations. This may allow heap corruption and, in the worst case, arbitrary code execution in the context of the GIMP process.