Export limit exceeded: 400496 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (400496 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-101901 1 Axios 1 Axios 2026-10-01 7.5 High
Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session initialization or reuse. A request uses httpVersion: 2 and the ClientHttp2Session emits an error during session initialization or reuse. The unhandled session error escapes normal Promise rejection handling. The uncaught error can terminate the Node.js process and cause denial of service. This issue is fixed in version 1.20.0.
CVE-2026-101142 1 Eleveo 1 Quality Management 2026-10-01 6.3 Medium
A vulnerability has been found in Eleveo Quality Management 9.7.0. Affected by this vulnerability is an unknown functionality of the file Scorecard.jsp of the component Questionnaire Audio Upload. The manipulation leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-101132 2 Deepseek, Deepseek-ai 2 Deepseek-harness, Deepseek-harness 2026-10-01 3.1 Low
A security flaw has been discovered in DeepSeek deepseek-harness up to 0.1.7-rc.2. The affected element is the function loadProfile of the file packages/boot/app-boot/src/profile.ts of the component Bundle Patch Handler. The manipulation of the argument dsh.bundle.patch results in path traversal. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-101102 1 Deepseek-ai 1 Deepseek-harness 2026-10-01 6.3 Medium
A vulnerability was found in deepseek-ai deepseek-harness up to 0.1.0-rc.7. Impacted is the function run_code of the component Code Mode Sandbox. The manipulation results in sandbox issue. The attack can be executed remotely. The vendor's own code, SAFETY.md, and design notes all explicitly state the worker is "containment, not a security boundary". The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-101099 1 Ag-ui-protocol 1 Ag-ui 2026-10-01 4.3 Medium
A vulnerability was detected in ag-ui-protocol ag-ui up to 2026-09-23. This affects an unknown part of the file SseParser.kt of the component Kotlin Community SDK. Performing a manipulation results in handling of exceptional conditions. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.
CVE-2026-101082 1 Pmweb 1 Pmweb 2026-10-01 5.3 Medium
A weakness has been identified in PMWeb 7.x/8.x/2025.x. This issue affects some unknown processing of the file downloader.aspx. This manipulation of the argument FullFileName/FileName causes path traversal. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-101079 1 Agentverus 1 Agentverus-scanner 2026-10-01 2.8 Low
A vulnerability was found in agentverus agentverus-scanner up to 0.8.1. Affected by this vulnerability is the function isSecurityDefenseSkill of the file dist/scanner/analyzers/context.js. Performing a manipulation results in reliance on untrusted inputs in a security decision. The attack must be initiated from a local position. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-101076 1 Netcore 1 Nr289-ge 2026-10-01 10 Critical
A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-101073 1 Netcore 1 Nr289-ge 2026-10-01 8.3 High
A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing a manipulation results in improper authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-101070 1 Dbgate 1 Dbgate 2026-10-01 5.3 Medium
A security vulnerability has been detected in dbgate up to 7.3.1. Affected by this vulnerability is the function files of the file packages/api/src/controllers/runners.js of the component Files Endpoint. The manipulation of the argument runid leads to path traversal. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-101067 1 Dbgate 1 Dbgate 2026-10-01 7.3 High
A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile of the file files.js of the component save-uploaded-file Endpoint. Such manipulation of the argument filePath/fileName leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-101054 1 Thinkware 1 U3000 2026-10-01 5.3 Medium
A vulnerability was identified in Thinkware U3000 up to 1.02.04. Affected is the function get_file of the file /tmp/wpa_supplicant.conf of the component TCP Service. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-101040 1 Ricoh 4 Aficio Sp 3500sf, Sp 221, Sp 330dn and 1 more 2026-10-01 6.5 Medium
A security flaw has been discovered in Ricoh SP 330DN, SP 221, SP C252SF and Aficio SP 3500SF up to 20260813. This affects an unknown part of the component HTTP Multipart Form-Data Parser. Performing a manipulation results in denial of service. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-101037 1 Fast 1 Fac1200r 2026-10-01 9.9 Critical
A vulnerability was found in FAST FAC1200R 5.0_20201119_1.0.2. Affected is the function parse_advertisement_frame of the component devdiscover Service. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-101018 2 Dayrui, Xunruicms 2 Xunruicms, Xunruicms 2026-10-01 4.7 Medium
A vulnerability was determined in dayrui XunruiCMS up to 4.7.2. This issue affects the function group_all_edit of the file dayrui/App/Member/Controllers/Admin/Home.php of the component Group Editing. This manipulation of the argument groupid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-101015 1 Trusted Domain Project 1 Opendmarc 2026-10-01 7.3 High
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functionality of the file policy.c of the component Domain Handler. Executing a manipulation can lead to improper validation of unsafe equivalence in input. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-101009 1 Aapanel 1 Baota 2026-10-01 8.4 High
A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._unzip of the file /www/server/panel/class/panelTask.py of the component Unzip Handler. Executing a manipulation of the argument Password can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-101006 1 Frappe 1 Hr 2026-10-01 4.3 Medium
A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: "This issue has already been reported by another individual, and based on that, we have fixed it."
CVE-2026-101003 1 Cesanta 1 Mongoose 2026-10-01 5.3 Medium
A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the file tutorials/mqtt/mqtt-server/main.c of the component MQTT Broker. Executing a manipulation can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 7.22 addresses this issue. This patch is called a9df523f76f43a38bd53b4232b9cfd4c16869e71. Upgrading the affected component is advised.
CVE-2026-101000 1 Netcore 1 Nbr100v2 2026-10-01 10 Critical
A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.