Export limit exceeded: 403539 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (2945 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-77105 | 3 Commvault, Linux, Microsoft | 3 Commvault, Linux Kernel, Windows | 2026-09-09 | 8.8 High |
| CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server. | ||||
| CVE-2026-6734 | 3 Nodejs, Redhat, Undici | 3 Undici, Hummingbird, Undici | 2026-09-09 | 7.5 High |
| Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dispatched through the pool connected to the first origin, regardless of the intended destination. This causes cross-origin request routing: credentials and request data intended for origin B are sent to origin A, responses from the wrong origin are trusted, and HTTPS requests may be silently downgraded to HTTP. Impacted users are applications that use Socks5ProxyAgent (directly or via setGlobalDispatcher) and make requests to more than one origin. This was introduced in undici 7.23.0 via PR #4385 and affects all versions through 8.1.0. Patches: Upgrade to undici v7.26.0 or v8.2.0. Workarounds: Use a separate Socks5ProxyAgent instance per origin, or avoid using Socks5ProxyAgent with multiple origins. | ||||
| CVE-2026-15141 | 1 Tp-link | 3 Td-w8961n, Tl-wr820n, Tl-wr820n Firmware | 2026-09-09 | 5.7 Medium |
| The web interface of the affected device relies on the HTTP referrer header as part of request validation. Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic. Successful exploitation may allow an adjacent attacker with access to the web management interface to obtain device configuration details and other sensitive information. | ||||
| CVE-2026-52767 | 1 Yeswiki | 1 Yeswiki | 2026-09-08 | 8.2 High |
| YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose boolean negation - if (!openssl_verify(...)) { throw ... }. PHP's openssl_verify has four possible return values: 1, 0, -1, and "false". The -1 row is the bypass: PHP's truthiness rules make -1 a truthy value, so !(-1) === false, the throw is skipped, and the controller proceeds to processActivity(). Any condition that makes OpenSSL's EVP_VerifyFinal() return -1 triggers the bypass. The reachable consequence is the controller silently treats a failed verification as success and processes the attacker's payload. This issue has been patched in version 4.6.6. | ||||
| CVE-2026-14296 | 1 Nordic Semiconductor Asa | 1 Nrf54h20 | 2026-09-08 | 7.5 High |
| When using the Direct XIP update strategy, the main application image starts other cores (i.e. radio core), based on the currently active slot without additional verification. The MCUboot in the bare (upstream) configuration assumes that if there is at least a single slot for each image available, the system is bootable and continues the boot process. This may lead to a situation when MCUboot picks different slot for different images (i.e. (a) for the main application and (b) for the radio image), boots the main application (from slot (a)) that afterwards starts the radio image by providing an address of the unauthenticated slot ((a) instead of (b)). | ||||
| CVE-2026-66776 | 2 Sap, Sap Se | 2 Approuter, Sap Business Ai Platform (approuter) | 2026-09-08 | 5.9 Medium |
| SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack complex to execute. This could result in a high impact on confidentiality and a low impact on integrity. There is no impact on availability. | ||||
| CVE-2026-69559 | 1 Microsoft | 1 Teams | 2026-09-08 | 5.8 Medium |
| Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. | ||||
| CVE-2026-86304 | 1 Perl | 1 Mojox::authentication | 2026-09-08 | 9.8 Critical |
| MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAML2::Binding::POST->new with no cacert, cert_text or anchors argument, then passes the returned XML to Net::SAML2::Protocol::Assertion->new_from_xml with the IdP signing certificate as cacert. In Net::SAML2 before 0.86 that certificate guards only encrypted assertions, so the signature on an unencrypted assertion is checked against the certificate the response itself carries. An attacker starts a SAML login, then posts a response signed with a certificate of their own. The audience, InResponseTo and timestamp checks that follow are all satisfiable by the attacker, so the response authenticates any NameID it carries. | ||||
| CVE-2026-80098 | 1 Microsoft | 1 Copilot Studio | 2026-09-08 | 9.3 Critical |
| Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-20355 | 1 Cisco | 1 Secure Email | 2026-09-08 | 5.9 Medium |
| Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication. | ||||
| CVE-2026-85434 | 1 Moos-ivp | 1 Moos-ivp | 2026-09-05 | 9.1 Critical |
| MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses. | ||||
| CVE-2026-85429 | 1 Moos-ivp | 1 Moos-ivp | 2026-09-05 | 7.5 High |
| MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable notifications without validation. | ||||
| CVE-2023-20576 | 2026-09-04 | 7.7 High | ||
| Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation. | ||||
| CVE-2026-84185 | 2 Red Hat, Redhat | 6 Red Hat Openshift Ai (rhoai), Ansible Automation Platform, Enterprise Linux and 3 more | 2026-09-04 | 5.9 Medium |
| A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error, the library fails to correctly identify the specific key ID (kid) and may instead accept a signature made by any valid key in the set. This can allow an attacker with a valid key to bypass authorization checks in applications that rely on the key ID to identify specific tenants or users. | ||||
| CVE-2026-84043 | 2026-09-04 | 5.3 Medium | ||
| The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature. | ||||
| CVE-2026-85435 | 1 Moos-ivp | 1 Moos-ivp | 2026-09-04 | 9.1 Critical |
| MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to receive bridged vehicle traffic including sensor data and control information. | ||||
| CVE-2026-85430 | 1 Themoos | 1 Essential-moos | 2026-09-04 | 9.1 Critical |
| MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity intact. Attackers can send crafted UDP datagrams to pShare input routes to inject messages into the local MOOS community under spoofed identities, or send malformed datagrams to crash the pShare process. | ||||
| CVE-2026-84767 | 2 Nexcess, Wordpress | 2 Bookit, Wordpress | 2026-09-04 | 5.3 Medium |
| Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions. | ||||
| CVE-2026-85431 | 1 Themoos | 1 Essential-moos | 2026-09-04 | 7.5 High |
| MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injection vulnerability in pMOOSBridge when configured with UDPListen. Attackers can send crafted UDP packets to the configured port to inject arbitrary variables into the local MOOS community with spoofed source and community identifiers. | ||||
| CVE-2026-73776 | 2 Hewlett Packard Enterprise (hpe), Hpe | 157 Aos-cx, Aruba Cx 10000-48y6c \(r8p13a\), Aruba Cx 10000-48y6c \(r8p14a\) and 154 more | 2026-09-04 | 7.9 High |
| A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an authenticated malicious actor with administrative privileges to execute arbitrary code on the underlying operating system, when certain pre-conditions outside of the attacker’s control are met. | ||||