Export limit exceeded: 400233 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400233 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400233 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100268 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 7.7 High |
| In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates | ||||
| CVE-2026-100276 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 5.9 Medium |
| In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action | ||||
| CVE-2026-100277 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 8.9 High |
| In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature | ||||
| CVE-2026-100278 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 4.9 Medium |
| In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments | ||||
| CVE-2026-100280 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 3.1 Low |
| In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible | ||||
| CVE-2026-100823 | 1 Mozilla | 1 Firefox | 2026-10-01 | 5.4 Medium |
| Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157. | ||||
| CVE-2026-76727 | 1 Hewlett Packard Enterprise (hpe) | 1 Instant On | 2026-10-01 | 7.2 High |
| Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system. | ||||
| CVE-2026-76732 | 1 Hewlett Packard Enterprise (hpe) | 1 Instant On | 2026-10-01 | 6.4 Medium |
| A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control. | ||||
| CVE-2026-76736 | 1 Hewlett Packard Enterprise (hpe) | 1 Instant On | 2026-10-01 | 3.3 Low |
| A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service. | ||||
| CVE-2026-76737 | 1 Hewlett Packard Enterprise (hpe) | 1 Instant On | 2026-10-01 | 3 Low |
| An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service. | ||||
| CVE-2026-51568 | 2026-10-01 | 8.1 High | ||
| modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file. | ||||
| CVE-2026-51570 | 2026-10-01 | 8.1 High | ||
| modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file. | ||||
| CVE-2026-51852 | 2026-10-01 | N/A | ||
| agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks. | ||||
| CVE-2026-51856 | 2026-10-01 | N/A | ||
| In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to Toolkit.call_tool_function, which invokes execute_python_code without an additional approval or isolation boundary on that path. | ||||
| CVE-2026-51860 | 2026-10-01 | N/A | ||
| bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Directory Traversal in src/backend/bisheng/linsight/domain/task_exec.py. | ||||
| CVE-2026-88920 | 1 Apache | 1 Wss4j | 2026-10-01 | 9.8 Critical |
| An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. | ||||
| CVE-2026-102993 | 2026-10-01 | 6.5 Medium | ||
| pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0. | ||||
| CVE-2026-100254 | 1 Jetbrains | 1 Teamcity | 2026-10-01 | 8.8 High |
| In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings | ||||
| CVE-2026-100255 | 1 Jetbrains | 1 Teamcity | 2026-10-01 | 8.1 High |
| In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset | ||||
| CVE-2026-100257 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export | ||||