Export limit exceeded: 20902 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400992 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-48005 | 2 Apache, Redhat | 3 Apache Http Server, Http Server, Hummingbird | 2026-10-02 | 7.5 High |
| Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck . Users are recommended to upgrade to version 2.4.69, which fixes this issue. | ||||
| CVE-2026-90454 | 1 Cisagov | 1 Malcolm | 2026-10-02 | 4.3 Medium |
| A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, and the proxy configuration otherwise permits the request method those routes use. This allows an authenticated user on a deployment intended to be read-only to add or remove tags on stored session records. | ||||
| CVE-2026-56153 | 2 Apache, Redhat | 2 Http Server, Hummingbird | 2026-10-02 | 7.5 High |
| Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | ||||
| CVE-2026-90455 | 1 Cisagov | 1 Malcolm | 2026-10-02 | 3.7 Low |
| A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a single fixed, trusted vendor URL at initialization and does not process attacker-controlled input through the library, limiting practical exploitability of the reintroduced version in this context. | ||||
| CVE-2026-100255 | 1 Jetbrains | 1 Teamcity | 2026-10-02 | 8.1 High |
| In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset | ||||
| CVE-2026-90456 | 1 Cisagov | 1 Malcolm | 2026-10-02 | 8.1 High |
| An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value. | ||||
| CVE-2026-100256 | 1 Jetbrains | 1 Intellij Idea | 2026-10-02 | 7.8 High |
| In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects | ||||
| CVE-2026-98162 | 1 Linux | 1 Linux Kernel | 2026-10-02 | 5.5 Medium |
| In the Linux kernel, the following vulnerability has been resolved: smb/server: fix tree connection leak in smb2_tree_connect() See the procedure below: smb2_tree_connect ksmbd_tree_conn_connect xa_store(&sess->tree_conns, tree_conn->id, tree_conn) ksmbd_counter_inc(KSMBD_COUNTER_TREE_CONNS) ksmbd_share_tree_conn_inc(sc) ksmbd_iov_pin_rsp // fail status.ret = KSMBD_TREE_CONN_STATUS_NOMEM // do not disconnect tree_conn Disconnect the new tree connection if ksmbd_iov_pin_rsp() fails. | ||||
| CVE-2026-90457 | 1 Cisagov | 1 Malcolm | 2026-10-02 | 6.2 Medium |
| The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissions allowing it to be read by any local user. This is inconsistent with a separate, stronger hashing algorithm used for the same password on another authentication path. A party able to read this file, including a local user or a party with access to a configuration backup, could feasibly recover the underlying password through offline computation, compromising the administrative credential across every path that accepts it. | ||||
| CVE-2026-100257 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export | ||||
| CVE-2026-98161 | 1 Linux | 1 Linux Kernel | 2026-10-02 | 5.5 Medium |
| In the Linux kernel, the following vulnerability has been resolved: nvdimm: pmem: keep PREFLUSH before data writes pmem_submit_bio() records a REQ_PREFLUSH error, but continues to copy the bio data and can later overwrite the error with a successful REQ_FUA flush. That lets data writes run after a failed preflush and can complete the bio successfully despite the failed ordering barrier. Run the REQ_PREFLUSH flush synchronously before touching the bio data and complete the bio with the flush error if it fails. Keep asynchronous flush chaining for REQ_FUA. At that point, data copy has completed and the parent bio can wait for the chained flush bio. | ||||
| CVE-2026-100258 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings | ||||
| CVE-2026-104055 | 2026-10-02 | N/A | ||
| The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the monitoring user's password in cleartext to its logs. Any actor able to read those logs can recover the password, which grants read-only pg_monitor access to PostgreSQL. This is fixed in the dev track (14/edge) in revisions 1189 (arm64) and 1190 (amd64), and in the stable track (14/stable) in revisions 1216 (arm64) and 1217 (amd64). | ||||
| CVE-2026-100259 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access | ||||
| CVE-2026-75937 | 2026-10-02 | N/A | ||
| A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device. | ||||
| CVE-2026-12392 | 1 Canonical | 1 Maas | 2026-10-02 | 5.3 Medium |
| An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. If a target machine was deployed with the 'register as rack' option enabled, an attacker who obtains or infers the machine's system ID can query the preseed/metadata server to leak the secret. | ||||
| CVE-2026-100260 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 5.3 Medium |
| In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset | ||||
| CVE-2026-63177 | 1 Cisagov | 1 Malcolm | 2026-10-02 | 7.1 High |
| Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while Nginx itself routes requests using the normalized path. An authenticated low-privilege user can prepend a traversal segment (for example `/x/../upload/...`) so that Nginx routes the request to a restricted backend while the Lua role check fails to match any rule and falls open, granting access it should deny. Version 26.07.0 fixes the issue. | ||||
| CVE-2026-100261 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 5.4 Medium |
| In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission | ||||
| CVE-2026-100262 | 1 Jetbrains | 1 Youtrack | 2026-10-02 | 7.6 High |
| In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates | ||||