Export limit exceeded: 400603 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400603 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-102578 | 1 Moodle | 1 Moodle | 2026-10-01 | 5.5 Medium |
| A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database. | ||||
| CVE-2026-102580 | 1 Moodle | 1 Moodle | 2026-10-01 | 2.2 Low |
| A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may result in unexpected application behavior. | ||||
| CVE-2026-103347 | 2026-10-01 | 5.3 Medium | ||
| Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions. | ||||
| CVE-2026-100514 | 2026-10-01 | 7.5 High | ||
| Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions. | ||||
| CVE-2026-97277 | 2026-10-01 | 7.6 High | ||
| Subscriber Broken Access Control in Social Boost <= 3.6.2 versions. | ||||
| CVE-2026-97258 | 2026-10-01 | 6.5 Medium | ||
| Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions. | ||||
| CVE-2026-47512 | 1 Nvidia | 5 Geforce, Nvs, Quadro and 2 more | 2026-10-01 | 7.8 High |
| NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read leading to kernel information disclosure. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-102587 | 1 Moodle | 1 Moodle | 2026-10-01 | 2.7 Low |
| A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized information disclosure by inferring hidden user data. | ||||
| CVE-2026-103491 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues | ||||
| CVE-2026-103497 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 5.5 Medium |
| In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration | ||||
| CVE-2026-103496 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 5.4 Medium |
| In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications | ||||
| CVE-2026-103495 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs | ||||
| CVE-2026-103494 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 6.6 Medium |
| In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes | ||||
| CVE-2026-95366 | 1 Google | 1 Chrome | 2026-10-01 | 6.5 Medium |
| Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-102579 | 1 Moodle | 1 Moodle | 2026-10-01 | 4.3 Medium |
| A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other students enrolled in the same course that they should not have permission to view. This issue leads to unauthorized information disclosure. | ||||
| CVE-2026-103492 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments | ||||
| CVE-2026-96760 | 1 Authlib | 1 Authlib | 2026-10-01 | 9.8 Critical |
| Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key. | ||||
| CVE-2026-103757 | 1 Budibase | 1 Budibase | 2026-10-01 | 7.7 High |
| Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. Authenticated builder users can send a prompt to POST /api/ai/tables that places an internal URL in an attachment column, causing the server to fetch it and return a presigned object-storage URL containing the response, such as cloud metadata credentials. | ||||
| CVE-2026-103754 | 1 Redhat | 1 Ansible Automation Platform | 2026-10-01 | 5.9 Medium |
| A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a streamed zip archive on the worker side of the ansible-runner transmit/worker protocol, re-creates symbolic links from archive content without validating the link target and applies chmod() and utime() to an unsanitized filesystem path derived from the archive member name. A crafted archive processed by a worker that consumes attacker-influenced input can create files, create symbolic links, or change permissions outside the intended target directory, which can be leveraged toward code execution. | ||||
| CVE-2026-103490 | 1 Jetbrains | 1 Youtrack | 2026-10-01 | 7.2 High |
| In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links | ||||