Export limit exceeded: 384605 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (384605 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65093 | 1 Nvidia | 1 Openshell | 2026-08-28 | 9.9 Critical |
| NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | ||||
| CVE-2026-65083 | 1 Nvidia | 1 Openshell | 2026-08-28 | 9.9 Critical |
| NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service. | ||||
| CVE-2026-65085 | 1 Nvidia | 1 Openshell | 2026-08-28 | 5.2 Medium |
| NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper encoding or escaping of output. A successful exploit of this vulnerability might lead to information disclosure and data tampering. | ||||
| CVE-2026-65086 | 1 Nvidia | 1 Openshell | 2026-08-28 | 6.8 Medium |
| NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. | ||||
| CVE-2026-70665 | 1 Doorkeeper-gem | 1 Doorkeeper-openid Connect | 2026-08-28 | 4.2 Medium |
| Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes without validating them against the server's configured scope set. Under certain conditions, this allows a self-registered client to obtain scopes beyond what the server intended to grant. In DynamicClientRegistrationController#application_params, the scopes attribute is assigned directly from params[:scope] with no validation against Doorkeeper.configuration.scopes or optional_scopes. Combined with enforce_configured_scopes being off by default and Doorkeeper's ScopeChecker prioritizing application-level scopes over server-level scopes, this creates a privilege escalation path. This issue is fixed in version 1.10.4. | ||||
| CVE-2026-18985 | 1 Drupal | 1 Edit In-place Field | 2026-08-28 | 8.1 High |
| Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1. | ||||
| CVE-2026-18261 | 1 Drupal | 1 Powerful Surveys | 2026-08-28 | 5.7 Medium |
| Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*. | ||||
| CVE-2026-18259 | 1 Drupal | 1 Token Content Access | 2026-08-28 | 7.5 High |
| Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2. | ||||
| CVE-2026-15088 | 1 Drupal | 1 Development Environment | 2026-08-28 | 5.7 Medium |
| Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*. | ||||
| CVE-2026-16645 | 1 Drupal | 1 Photoswipe - Responsive Javascript Modal Image Gallery | 2026-08-28 | 9.1 Critical |
| Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0. | ||||
| CVE-2026-16643 | 1 Drupal | 1 Lunr Exposed Filters | 2026-08-28 | 5.7 Medium |
| Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*. | ||||
| CVE-2026-16642 | 1 Drupal | 1 Email Login Otp | 2026-08-28 | 5.7 Medium |
| Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*. | ||||
| CVE-2026-16640 | 1 Drupal | 1 Search Api Autocomplete | 2026-08-28 | 6.1 Medium |
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete versions: from 0.0.0 to 1.12.0. | ||||
| CVE-2026-16639 | 1 Drupal | 1 Internationalization Single Sign-on | 2026-08-28 | 9.8 Critical |
| Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0. | ||||
| CVE-2026-16638 | 1 Drupal | 1 Media Folders | 2026-08-28 | 6.1 Medium |
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8. | ||||
| CVE-2026-44476 | 1 Doorkeeper-gem | 1 Doorkeeper-openid Connect | 2026-08-28 | N/A |
| Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain an access token without providing its client_secret. This occurs because the Dynamic Client Registration feature creates applications with confidential: false hard-coded, even though the registration response returns a client_secret and advertises support for the client_secret_basic and client_secret_post authentication methods; since Doorkeeper treats a blank or missing secret as valid for non-confidential (public) clients, the secret is never verified. Only projects that have explicitly enabled Dynamic Client Registration, which is disabled by default, are affected. This issue is fixed in version 1.10.0. | ||||
| CVE-2026-9805 | 1 Insyde | 1 Insydeh2o | 2026-08-28 | 2.7 Low |
| SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size and could cause buffer overflow. | ||||
| CVE-2026-73335 | 1 Digital Agency | 1 Android App "myna Point" | 2026-08-28 | N/A |
| Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, potentially allowing arbitrary JavaScript to be executed within the affected application. | ||||
| CVE-2026-76148 | 1 Sasaki Nobuyuki | 1 Corvusskk | 2026-08-28 | N/A |
| CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product. | ||||
| CVE-2026-76149 | 1 Sasaki Nobuyuki | 1 Corvusskk | 2026-08-28 | N/A |
| CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file. | ||||