Export limit exceeded: 400226 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 400226 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (400226 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-103270 1 Modeltc 1 Lightllm 2026-10-01 7.5 High
LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group to disrupt inference operations and wedge workers on deployments started with --enable_rl.
CVE-2026-100262 1 Jetbrains 1 Youtrack 2026-10-01 7.6 High
In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates
CVE-2026-100263 1 Jetbrains 1 Youtrack 2026-10-01 4.7 Medium
In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible
CVE-2026-100265 1 Jetbrains 1 Rider 2026-10-01 4.8 Medium
In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation
CVE-2026-100266 1 Jetbrains 1 Hub 2026-10-01 7.7 High
In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address
CVE-2026-100267 1 Jetbrains 1 Youtrack 2026-10-01 5.9 Medium
In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters
CVE-2026-100268 1 Jetbrains 1 Youtrack 2026-10-01 7.7 High
In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
CVE-2026-100276 1 Jetbrains 1 Youtrack 2026-10-01 5.9 Medium
In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action
CVE-2026-100277 1 Jetbrains 1 Youtrack 2026-10-01 8.9 High
In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
CVE-2026-100278 1 Jetbrains 1 Youtrack 2026-10-01 4.9 Medium
In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments
CVE-2026-100280 1 Jetbrains 1 Youtrack 2026-10-01 3.1 Low
In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible
CVE-2026-100823 1 Mozilla 1 Firefox 2026-10-01 5.4 Medium
Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157.
CVE-2026-76727 1 Hewlett Packard Enterprise (hpe) 1 Instant On 2026-10-01 7.2 High
Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
CVE-2026-76732 1 Hewlett Packard Enterprise (hpe) 1 Instant On 2026-10-01 6.4 Medium
A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control.
CVE-2026-76736 1 Hewlett Packard Enterprise (hpe) 1 Instant On 2026-10-01 3.3 Low
A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service.
CVE-2026-76737 1 Hewlett Packard Enterprise (hpe) 1 Instant On 2026-10-01 3 Low
An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service.
CVE-2026-51568 2026-10-01 8.1 High
modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file.
CVE-2026-51570 2026-10-01 8.1 High
modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file.
CVE-2026-51852 2026-10-01 N/A
agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks.
CVE-2026-51856 2026-10-01 N/A
In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to Toolkit.call_tool_function, which invokes execute_python_code without an additional approval or isolation boundary on that path.