Export limit exceeded: 398994 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (398994 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-97026 | 1 Redhat | 1 Enterprise Linux | 2026-09-28 | 3.9 Low |
| Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used while installing apps or runtimes, potentially causing installation failures (denial of service); tampered content would fail signature/digest verification rather than being trusted. | ||||
| CVE-2026-97025 | 1 Redhat | 1 Enterprise Linux | 2026-09-28 | 3.2 Low |
| Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate the authenticated user against the OCI repository. Only OCI-based sources (e.g. as used by Fedora) are affected; libostree-based sources such as Flathub are not. | ||||
| CVE-2026-6544 | 2 Ibm, Linux | 2 Concert, Linux Kernel | 2026-09-28 | 6.2 Medium |
| IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface. | ||||
| CVE-2026-6925 | 2 Ibm, Linux | 2 Concert, Linux Kernel | 2026-09-28 | 5.3 Medium |
| IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system. | ||||
| CVE-2026-6794 | 2 Ibm, Linux | 2 Concert, Linux Kernel | 2026-09-28 | 7.8 High |
| IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local attacker can exploit this flaw to corrupt heap memory and execute arbitrary code in the context of the affected process. | ||||
| CVE-2026-6730 | 2 Ibm, Linux | 2 Concert, Linux Kernel | 2026-09-28 | 9.8 Critical |
| IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system. | ||||
| CVE-2026-102006 | 2026-09-28 | 5.5 Medium | ||
| In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process management subsystem failing to properly release allocated kernel memory before terminating the calling application. Fixed in Version 26.09 | ||||
| CVE-2026-6721 | 2 Ibm, Linux | 2 Concert, Linux Kernel | 2026-09-28 | 9.8 Critical |
| IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system. Successful exploitation allows remote code execution with the privileges of the affected application. | ||||
| CVE-2026-101187 | 1 Ziroom | 1 Zhome A0101 | 2026-09-28 | 9.1 Critical |
| A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function pop_usb_device of the file usr/lib/lua/luci/controller/api/zrUsb.lua of the component USB Device Management API. This manipulation of the argument path causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-101146 | 1 Eleveo | 1 Quality Management | 2026-09-28 | 4.3 Medium |
| A security flaw has been discovered in Eleveo Quality Management 9.7.0. This issue affects the function UtilsService.createAndSaveAudit of the file /qm/cz.zoom.scorecard.webui.Scorecard/QMUtilsService of the component GWT RPC Handler. Performing a manipulation results in information disclosure. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-70582 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-28 | 6.4 Medium |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-70583 | 1 Microsoft | 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more | 2026-09-28 | 7.8 High |
| Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-77492 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-28 | 5.5 Medium |
| Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-97023 | 1 Redhat | 1 Enterprise Linux | 2026-09-28 | 7.1 High |
| A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is installed or upgraded. In system-wide installations, the deletion is performed as root. | ||||
| CVE-2026-85740 | 1 Hkuds | 1 Lightrag | 2026-09-28 | 7.1 High |
| LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py evaluates the literal resolved address with ipaddress.is_global without consistently classifying an IPv4 address embedded in an IPv6 transition wrapper. A caller who can upload a Markdown or textpack document can supply an external image URL using NAT64 64:ff9b::/96 or an IPv4-compatible form that embeds a loopback, private, or cloud-metadata IPv4 address. On a deployment with compatible NAT64 or DNS64 routing, _download and _build_guarded_opener accept the wrapper and fetch the internal resource, whose body is then ingested. Current interpreter behavior already blocks some RFC 8215 and 6to4 forms, but the fixed guard handles all documented wrappers without becoming more permissive than the standard library. This issue is fixed in version 1.5.5. | ||||
| CVE-2026-83602 | 1 Netdata | 1 Netdata | 2026-09-28 | 6.5 Medium |
| Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api/v3/web_api_v3.c with HTTP_ACL_NOCHECK and HTTP_ACCESS_ANONYMOUS_DATA, causing unauthenticated PUT requests handled by src/web/api/v3/api_v3_settings.c to bypass operator-configured allow dashboard from IP restrictions. A network-reachable caller can persist attacker-controlled JSON in {varlib}/settings/default.json, manipulate its version counter, and use repeated near-20 MiB writes to consume disk space, although the file does not control collection or security policy. This vulnerability is fixed in 2.11.0. | ||||
| CVE-2026-76804 | 1 Projectdiscovery | 1 Nuclei | 2026-09-28 | 5.5 Medium |
| Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading path does not enforce the -file capability gate when resolving file: protocol templates referenced by a workflow. An untrusted unsigned workflow can therefore load a file-protocol template and read local files from the scanner host even when the operator has not enabled file templates. The issue affects CLI users running workflows with -w and SDK integrations that accept end-user workflows while relying on the default file-access restriction. This issue is fixed in version 3.10.0. | ||||
| CVE-2026-75608 | 1 Blakeblackshear | 1 Frigate | 2026-09-28 | 7.7 High |
| Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/go2rtc/api in docker/main/rootfs/usr/local/nginx/conf/nginx.conf requires authentication but does not require an administrator role for GET requests, exposing the proxied go2rtc API to viewer users. An authenticated viewer can request the streams, config, log, and stack subpaths to obtain internal addresses, configuration paths, application logs, goroutine stack data, and RTSP stream URLs that may contain camera credentials. Non-GET methods remain blocked by limit_except GET. This issue is fixed in version 0.18.0. | ||||
| CVE-2026-56681 | 1 Decolua | 1 9router | 2026-09-28 | 7.3 High |
| 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper trust the client-supplied X-9r-Real-Ip header in src/dashboardGuard.js when isLocalRequest decides whether canAccessPublicLlmApi may skip API-key validation for /api/v1/* routes. A remote unauthenticated attacker can set X-9r-Real-Ip to 127.0.0.1 and be classified as a local client, including on the verified GET /api/v1/models route. This permits unauthorized use of the instance owner's configured LLM providers, consumption of paid credits, and enumeration of configured providers and models. This issue is fixed in version 0.5.6. | ||||
| CVE-2026-49994 | 1 Dannymcc | 1 Bluehood | 2026-09-28 | 9.1 Critical |
| Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* handlers (settings, devices, groups, per-device endpoints including /api/device/{mac}/notes) called no auth check at all. A network attacker reachable on the dashboard port could read Bluetooth tracking data and modify application state — including the heartbeat URL, prune retention, device groups, and per-device notes — without a session cookie. This issue has been patched in version 0.7.1. | ||||