Export limit exceeded: 400203 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400203 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-92232 | 1 Joomla | 2 Joomla!, Joomla! Framework Filter Package | 2026-09-30 | N/A |
| Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The cleanAttribute method removes HTML data URIs, however injected whitespaces characters could circumvent that cleanup, causing an XSS vector. | ||||
| CVE-2026-92227 | 1 Joomla | 1 Joomla! | 2026-09-30 | N/A |
| Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability. | ||||
| CVE-2026-92225 | 1 Joomla | 1 Joomla! | 2026-09-30 | N/A |
| Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user supplied values, leading to an XSS vector. | ||||
| CVE-2026-90917 | 1 Joomla | 1 Joomla! | 2026-09-30 | N/A |
| Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view content items from inaccessible categories. | ||||
| CVE-2026-92223 | 1 Joomla | 1 Joomla! | 2026-09-30 | N/A |
| Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to update the workflow stage of inaccessible contents. | ||||
| CVE-2026-92222 | 1 Joomla | 1 Joomla! | 2026-09-30 | N/A |
| Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly validated, leading to SSRF vectors. | ||||
| CVE-2026-90918 | 1 Joomla | 1 Joomla! | 2026-09-30 | N/A |
| Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions. | ||||
| CVE-2026-92231 | 1 Joomla | 2 Joomla!, Joomla! Framework Filter Package | 2026-09-30 | N/A |
| Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex, however without decoding HTML5 entities beforehand, causing an XSS vector. | ||||
| CVE-2026-90914 | 1 Joomla | 1 Joomla! | 2026-09-30 | N/A |
| Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to an XSS vulnerability in the generic audio and video output layouts. | ||||
| CVE-2026-90907 | 1 Joomla | 1 Joomla! | 2026-09-30 | N/A |
| Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The profile.save controller did not check the login state of a user, allowing the creation of guest-level users on sites without active user registration. | ||||
| CVE-2026-92224 | 1 Joomla | 1 Joomla! | 2026-09-30 | N/A |
| Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The link toolbar layout did not properly escape inputs, leading to an XSS vector. | ||||
| CVE-2026-92226 | 1 Joomla | 1 Joomla! | 2026-09-30 | N/A |
| Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform edit actions on otherwise uneditable items. | ||||
| CVE-2026-90915 | 1 Joomla | 1 Joomla! | 2026-09-30 | N/A |
| Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 -An improper validation of the cache group name allowed path traverals in the file storage of the caching layer, resulting in arbitrary directory deletions. | ||||
| CVE-2026-102555 | 2 Libsoup, Redhat | 2 Libsoup, Enterprise Linux | 2026-09-30 | 8.2 High |
| A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded NUL bytes, the decoded length could remain uninitialized and be used as the size of the returned GBytes. This can lead to an out-of-bounds read or application crash when processing a crafted data URI. | ||||
| CVE-2026-102558 | 2 Libsoup, Redhat | 2 Libsoup, Enterprise Linux | 2026-09-30 | 8.6 High |
| A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the length wrapped, causing a heap buffer overflow while reading frame data. | ||||
| CVE-2026-102560 | 2 Libsoup, Redhat | 2 Libsoup, Enterprise Linux | 2026-09-30 | 8.6 High |
| A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could wrap, causing zlib to write past the allocated buffer and resulting in a heap buffer overflow. | ||||
| CVE-2026-102810 | 1 Rochacbruno | 1 Marmite | 2026-09-30 | 7.5 High |
| Marmite through 0.4.2 contains a path traversal vulnerability in the development server started by --serve that allows unauthenticated attackers to read arbitrary files. The handle_request function in src/server.rs fails to reject .. segments after percent-decoding and joining the request path to the output folder, enabling attackers to request encoded traversal sequences to access files readable by the marmite process. | ||||
| CVE-2026-102811 | 1 Rochacbruno | 1 Marmite | 2026-09-30 | 7.5 High |
| Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in handle_create_content and handle_clone_content to write files outside the project directory via directory traversal. | ||||
| CVE-2026-102759 | 1 Eclipse | 1 Netx Duo | 2026-09-30 | N/A |
| NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is never generated or compared. Empty TLS application-data records are legal, and are commonly emitted by TLS 1.0 implementations as a BEAST mitigation. | ||||
| CVE-2026-102760 | 1 Eclipse | 1 Netx Duo | 2026-09-30 | N/A |
| When NetX Secure is built with `NX_SECURE_KEY_CLEAR`, every TLS record sent on an active session is wiped after it has been handed to TCP. By then the TCP layer owns the packet chain and may already have released it to the packet pool. The wipe therefore writes zeros into packets that are free or in use by another thread, and when a reused packet's pointers no longer describe the old data, the length of the wipe underflows and it runs past the end of the packet pool. | ||||