Export limit exceeded: 403519 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403519 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-105825 | 1 Imagemagick | 1 Imagemagick | 2026-10-08 | 5.3 Medium |
| ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a denial of service vulnerability in its handling of XMP profiles, where a crafted profile terminates the process instead of raising an exception. Attackers can supply images with malicious XMP profiles to crash applications that process them using ImageMagick. | ||||
| CVE-2026-105399 | 1 Imagemagick | 1 Imagemagick | 2026-10-08 | 5.3 Medium |
| ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a denial of service vulnerability in the MVG decoder caused by a missing limit check. Attackers can supply a crafted MVG image that triggers a long-running decoding operation, consuming excessive CPU resources and stalling image processing. | ||||
| CVE-2026-105404 | 1 Imagemagick | 1 Imagemagick | 2026-10-08 | 5.3 Medium |
| ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a code injection vulnerability in its PostScript coders, because some values are not properly escaped or trimmed when written to output. Attackers can supply crafted values that embed arbitrary PostScript code into files generated by these coders. | ||||
| CVE-2026-105826 | 1 Imagemagick | 1 Imagemagick | 2026-10-08 | 5.3 Medium |
| ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a security policy bypass in the MAT decoder, which does not enforce configured temporary file size limits when reading highly compressed data. Attackers can supply a crafted MAT image whose decompressed data is written to temporary files larger than the policy allows, consuming disk resources. | ||||
| CVE-2026-105405 | 1 Imagemagick | 1 Imagemagick | 2026-10-08 | 5.9 Medium |
| ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains an invalid memory free vulnerability in the MVG decoder. Attackers can supply a crafted MVG image for processing to trigger the invalid free and crash the application, causing a denial of service. | ||||
| CVE-2026-105823 | 1 Imagemagick | 1 Imagemagick | 2026-10-08 | 4 Medium |
| ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 lacks a security policy check in the CUT encoder, allowing configured security policies to be bypassed. Attackers can supply crafted input processed by the CUT encoder to crash the application or leak sensitive data. | ||||
| CVE-2026-105401 | 1 Imagemagick | 1 Imagemagick | 2026-10-08 | 5.3 Medium |
| ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability in the distributed pixel cache server that allows connecting clients to overwrite heap memory by sending crafted data. Attackers can connect to the distributed pixel cache server and transmit malicious data to trigger a heap buffer over-write that crashes the server, causing denial of service. | ||||
| CVE-2026-107315 | 1 Pgjdbc | 1 Pgjdbc | 2026-10-08 | 5.3 Medium |
| pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.4 through 42.7.13 pads a value that is shorter than its declared length with bytes left in its send buffer instead of zeros, and the server stores those bytes as part of the value. The bytes are messages the driver sent earlier on the same connection: SQL text and parameter values of recent statements, which on a pooled connection can come from other requests. Each padded value can carry up to 8192 bytes of this traffic, or 16320 bytes on a connection with GSS encryption. The padding happens when an application declares a length larger than the data it supplies, through PreparedStatement.setObject with a ByteStreamWriter, CopyIn.writeToCopy, PGCopyOutputStream.write, LargeObject.write, or Blob.setBytes. The driver accepts these calls without an error. An attacker who can make the application store such a value and read it back can collect earlier traffic. Applications whose declared lengths always match their data are not affected. Versions 42.7.3 and earlier pad with zeros. | ||||
| CVE-2026-107314 | 1 Pgjdbc | 1 Pgjdbc | 2026-10-08 | 5.9 Medium |
| pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. The driver then accepts any method the server asks for, including cleartext password authentication. A value without a method in it, such as requireAuth=, (a single comma), is affected the same way. An attacker positioned between the application and its server can ask for cleartext password authentication and receive the database password. A positive list such as requireAuth=scram-sha-256, and a partial exclusion such as requireAuth=!password,!md5, are enforced correctly. The property has no default value, so a deployment that does not set it is not affected. 42.7.14 fixes the problem: such a connection is refused with SQLState 08004, and a value without a method in it is rejected as invalid. | ||||
| CVE-2026-107623 | 1 Redhat | 2 Build Keycloak, Red Hat Single Sign On | 2026-10-08 | 4.3 Medium |
| A flaw was found in the OIDC Dynamic Client Registration (DCR) component of Keycloak. A bug in the response serialization causes the backchannel logout offline token revocation setting to be omitted from responses. When a client performs a standard update, this missing information causes the setting to be silently disabled. As a result, offline tokens may remain valid even after a user session is terminated via backchannel logout. | ||||
| CVE-2026-107565 | 1 Redhat | 2 Enterprise Linux, Openshift | 2026-10-08 | 5.1 Medium |
| A flaw was found in luksmeta. A local attacker with administrative privileges can cause data corruption when saving metadata to a Linux Unified Key Setup (LUKS) device. Due to incorrect boundary calculations and flawed overlap detection, new metadata entries can be written beyond available free space or over existing records. This issue can corrupt stored encrypted payload data or existing metadata, potentially rendering the affected data inaccessible. | ||||
| CVE-2026-107392 | 1 Borewit | 1 Music-metadata | 2026-10-08 | 6.2 Medium |
| music-metadata is a metadata parser for audio and video media files. Prior to 11.15.0, the DSF parser handles an unrecognized chunk by calling tokenizer.ignore without awaiting the returned promise and without first rejecting a chunk size smaller than the 12-byte chunk header. A crafted DSF input can produce a negative ignore length; with strtok3 10.3.5 or later, the resulting RangeError is detached from the parseBuffer promise and becomes an unhandled rejection under Node.js default behavior. The parse call can appear to resolve before the process crashes, bypassing per-parse try/catch handling. The demonstrated impact is availability loss only and requires the DSF parsing path. This issue is fixed in version 11.15.0. | ||||
| CVE-2026-107291 | 1 Pydantic | 1 Pydantic-ai | 2026-10-08 | 4.3 Medium |
| Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.3.4 until 1.107.6 and 2.44.0, OpenTelemetry instrumentation configured with InstrumentationSettings(include_content=False) can still export sensitive agent content through exception.message and exception.stacktrace events, error status descriptions, and model_request_parameters containing instructions or the prompted_output_template. The exposed data is available to readers of the configured telemetry backend and can include tool feedback, provider error bodies, runtime instructions, and structured-output templates even though message attributes are redacted. This issue does not grant new access to agent data, and deployments that do not use include_content=False are not affected by the setting bypass. This issue is fixed in versions 1.107.6 and 2.44.0. | ||||
| CVE-2026-16313 | 1 Redhat | 10 Enterprise Linux, Enterprise Linux Eus, Openshift and 7 more | 2026-10-08 | 7.6 High |
| A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected. | ||||
| CVE-2026-14474 | 1 Redhat | 9 Enterprise Linux, Enterprise Linux Eus, Openshift and 6 more | 2026-10-08 | 8.8 High |
| A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts. | ||||
| CVE-2026-1933 | 2 Redhat, Samba | 10 Enterprise Linux, Enterprise Linux Eus, Openshift and 7 more | 2026-10-08 | 7.1 High |
| A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point metadata through SMB operations even on read-only exports. This could allow modification of SMB-visible file behavior, including converting files into symbolic links or other reparse point types. | ||||
| CVE-2026-26950 | 1 Dell | 1 Smartfabric Manager | 2026-10-08 | 8.1 High |
| Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | ||||
| CVE-2026-54471 | 1 Dell | 1 Smartfabric Manager | 2026-10-08 | 3.5 Low |
| Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | ||||
| CVE-2026-67100 | 1 Hcltech | 1 Bigfix Service Management | 2026-10-08 | 9.8 Critical |
| HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile data and PII across different organizations. | ||||
| CVE-2026-67101 | 1 Hcltech | 1 Bigfix Service Management | 2026-10-08 | 9.3 Critical |
| HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet. | ||||