Export limit exceeded: 399206 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399206 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-41875 | 1 Opensolution | 1 Quick.cart | 2026-09-29 | N/A |
| Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request that changes admin's login and password. This software does implement simple protection against this type of attack, but it is easily bypassed by manipulating the referer header. All forms available in this software are potentially vulnerable. This issue was fixed in a patch to version 6.7 published on 09.11.2026, deployments without this patch are still vulnerable | ||||
| CVE-2026-11796 | 2026-09-29 | N/A | ||
| Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availability. These servlets are designed to perform specific functions within production environment depending on how the Asset Suite application is configured. | ||||
| CVE-2026-102570 | 1 Clip-bucket | 1 Clipbucket | 2026-09-29 | 5.5 Medium |
| ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the language update function where the language_id parameter is concatenated unescaped into the WHERE clause of an UPDATE statement. An authenticated administrator with basic_settings permission can inject arbitrary SQL payloads to extract or modify database contents. | ||||
| CVE-2026-102567 | 2026-09-29 | 6.1 Medium | ||
| CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious model files to trigger heap memory reads past buffer boundaries, causing crashes or disclosing adjacent heap memory contents. | ||||
| CVE-2026-102566 | 2026-09-29 | 7.8 High | ||
| CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model files with oversized payload lengths to write past heap allocation boundaries, causing crashes or arbitrary code execution. | ||||
| CVE-2026-102437 | 2026-09-29 | 7.8 High | ||
| OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer. | ||||
| CVE-2026-102279 | 1 Laravel | 1 Framework | 2026-09-29 | 3.1 Low |
| Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML true, enabling DOM-based cross-site scripting when a user hovers over the tooltip. This issue is fixed in versions 12.69.0 and 13.30.0. | ||||
| CVE-2026-102272 | 1 Jpadilla | 1 Pyjwt | 2026-09-29 | 7.4 High |
| PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize accepted Unicode byte-order marks before checking for JSON. This occurs when a public JWK is prefixed with a UTF-8 BOM and used in a mixed-algorithm verification path. As a result, public JWK bypasses asymmetric-key detection and becomes the HMAC secret. Consequently, an attacker who knows the public key can forge authenticated tokens. This issue is fixed in version 2.14.0. | ||||
| CVE-2026-101271 | 2026-09-29 | N/A | ||
| OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled. | ||||
| CVE-2026-101270 | 2026-09-29 | N/A | ||
| Malicious HTML content could be injected into the help texts of various fields with organizer permissions. | ||||
| CVE-2026-101269 | 2026-09-29 | N/A | ||
| The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users. Since API-uploaded files are refered to by randomly generated UUIDs and only exist for a day, there is virtually no risk, but it renders the added protection mechanism useless. | ||||
| CVE-2026-101268 | 2026-09-29 | N/A | ||
| If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account. If the victim does not notice this, this might lead to their order details being stored into the attacker's account. The attack only works when the event is available on a different domain than the organizer page. | ||||
| CVE-2026-101267 | 2026-09-29 | N/A | ||
| A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue. | ||||
| CVE-2026-101266 | 2026-09-29 | N/A | ||
| A logic flaw in the checkout flow allows users to bypass validations performed during the check-in by skipping entire check-in steps. | ||||
| CVE-2026-100815 | 2026-09-29 | 8.8 High | ||
| Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | ||||
| CVE-2026-100814 | 2026-09-29 | 8.8 High | ||
| Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | ||||
| CVE-2026-100813 | 2026-09-29 | 8.8 High | ||
| Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 157. | ||||
| CVE-2026-100811 | 2026-09-29 | 9.6 Critical | ||
| Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. | ||||
| CVE-2026-100804 | 2026-09-29 | 9.6 Critical | ||
| Sandbox escape due to use-after-free in the Preferences: Backend component. This vulnerability was fixed in Firefox 157. | ||||
| CVE-2026-100800 | 2026-09-29 | 9.6 Critical | ||
| Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | ||||