Export limit exceeded: 403624 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403626 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-67693 | 1 Gnu | 1 Gnutls | 2026-10-09 | 5.9 Medium |
| An issue in gnutls v.3.8.13 allows an attacker to obtain sensitive information via failing to reject end-entity X.509 certificates that contain a contradictory combination of Key Usage (KU) and Extended Key Usage (EKU) | ||||
| CVE-2026-95209 | 1 Gnu | 1 Gnutls | 2026-10-09 | 7.5 High |
| An issue in gnutls v3.8.13 causes legitimate CA certificates to be rejected, leading to a Denial of Service (DoS). | ||||
| CVE-2026-107577 | 1 Progressive Robot | 1 Hmailserver | 2026-10-09 | 7.5 High |
| Inefficient algorithmic complexity and a non-terminating loop in the MIME processing of received messages in Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a remote unauthenticated attacker to make the mail services unavailable by sending a message. Removing a MIME header parameter whose value is empty and directly followed by a semicolon (for example a Content-Disposition with 'filename=a.bat; filename=;') entered a loop that never terminates, holding a worker thread at full load until the server is restarted; this is reached when the attachment blocker renames a blocked attachment or a filename is set over the REST API. Separately, decoding a header field that holds many RFC 2047 encoded words of an encoding other than base64 or quoted-printable, removing a parameter with many RFC 2231 continuations, and deleting many header fields of one name each took time growing with the square of the message, on the small thread pools that serve IMAP, SMTP and POP3 connections, delivery and the REST API. | ||||
| CVE-2026-107587 | 1 Progressive Robot | 1 Hmailserver | 2026-10-09 | 5.9 Medium |
| Improper certificate validation in the webmail of Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to have S/MIME-encrypted mail that the account later sends to another correspondent also encrypted to the attacker's key. When its recipient opened a signed message, the webmail kept the signer's certificate for encrypting replies whether or not the server found its chain trusted, under the first e-mail address the certificate listed rather than the message's From address, and beside any certificate already held for that address. Encrypted mail later sent from the webmail to that address was encrypted to every certificate held for it, so a holder of the kept certificate's key who obtains a copy of such a message can read it. | ||||
| CVE-2026-87108 | 1 Mongodb | 1 Ops Manager | 2026-10-09 | 3.1 Low |
| An authenticated Ops Manager user with a read-only project role can retrieve a daily host monitoring record associated with a different project when they possess the required record identifier. Insufficient ownership validation can expose deployment metadata, including host and configuration details. | ||||
| CVE-2026-95184 | 1 Gnu | 1 Gnutls | 2026-10-09 | 7.5 High |
| Improper certificate validation in gnutls v3.8.13 causes the application to reject legitimate certificates for valid users, leading to a Denial of Service (DoS). | ||||
| CVE-2026-95210 | 1 Gnu | 1 Gnutls | 2026-10-09 | 9.1 Critical |
| Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions. | ||||
| CVE-2026-102488 | 1 Octopus | 1 Octopus Server | 2026-10-09 | N/A |
| In affected versions, Octopus Server incorrectly evaluates multiple scoped permission assignments, allowing a highly privileged user to obtain deployment permissions beyond those actually granted to them. | ||||
| CVE-2023-5649 | 1 Broadcom | 1 Brocade Active Support Connectivity Gateway | 2026-10-09 | N/A |
| An Improper Input Validation vulnerability for the registered case credentials in Brocade ASCG before v3.0 could allow a local authenticated user to provide invalid inputs like special characters leading to a Denial of Service (DoS) when collecting “supportsave” from a Brocade Switch. | ||||
| CVE-2026-5047 | 1 Broadcom | 1 Brocade Sannav | 2026-10-09 | N/A |
| A vulnerability in Brocade SANnav before 2.4.0b and 3.0.0 prints encoded passwords and authentication tokens in log files. The vulnerability could allow an authenticated attacker with access to the log file including the SANnav supportsave to access the passwords. | ||||
| CVE-2026-5048 | 1 Broadcom | 1 Brocade Sannav | 2026-10-09 | N/A |
| In Brocade SANnav before 3.0.0a, an SQL Injection vulnerability in various external API inventories have a vulnerability that allows an authenticated attacker to inject malicious data into some of the REST API -query parameters. | ||||
| CVE-2026-5049 | 1 Broadcom | 1 Brocade Sannav | 2026-10-09 | N/A |
| A path traversal vulnerability affects the The Zone Alias Import flow feature in Brocade SANnav before 3.0.0a. A local authenticated attacker can write an uploaded content outside the intended directory. | ||||
| CVE-2026-5769 | 1 Broadcom | 1 Brocade Sannav | 2026-10-09 | N/A |
| A vulnerability in Brocade SANnav before 3.0.1 can have the Brocade Fabric OS switch admin password captured in plaintext within a memory swap file on the server hosting the Brocade SANnav Virtual Machine (VM). This can happen when the SANnav server encounters an Out Of Memory (OOM) condition. The vulnerability could allow an authenticated admin user with access to the server hosting the SANnav to potentially view the memory swap file and access the password(s). | ||||
| CVE-2026-85421 | 1 Broadcom | 1 Brocade Active Support Connectivity Gateway | 2026-10-09 | N/A |
| A critical security vulnerability has been identified in Brocade ASCG versions before 3.5.0. The HTTPS service fails to properly enforce authentication or access control checks on incoming requests. An unauthenticated attacker with network access can issue control commands, alter cluster states, and modify system configurations, leading to a complete compromise of the streaming service control plane. | ||||
| CVE-2026-85422 | 1 Broadcom | 1 Brocade Active Support Connectivity Gateway | 2026-10-09 | N/A |
| A vulnerability in Brocade ASCG version before 3.5.0 could allow an attacker to obtain a static cryptographic key hardcoded into the software binaries to secure sensitive data at rest and to protect inter-node communication protocols. An attacker who extracts this key can decrypt stored management credentials or craft forged administrative synchronization messages. | ||||
| CVE-2026-85423 | 1 Broadcom | 1 Brocade Active Support Connectivity Gateway | 2026-10-09 | N/A |
| A vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0. An API endpoint within the data collector service fails to perform authentication or authorization checks on incoming requests. An attacker with network access to the service can instruct the application to establish SSH connections to arbitrary hosts and execute arbitrary system commands, effectively turning the appliance into an unauthenticated proxy or execution vector. | ||||
| CVE-2026-85486 | 1 Broadcom | 1 Brocade Active Support Connectivity Gateway | 2026-10-09 | N/A |
| Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation. When an authenticated user submits a configuration form, the submitted text could immediately be processed. A malicious actor with basic access can supply crafted input to execute arbitrary code on the server and take control of the application. | ||||
| CVE-2026-85487 | 1 Broadcom | 1 Brocade Active Support Connectivity Gateway | 2026-10-09 | N/A |
| A path traversal vulnerability exists in the HTTP service component of Brocade ASCG versions before 3.5.0. An unauthenticated attacker on the local network could send a manipulated API request to the service endpoint bypassing path restrictions to arbitrary file read, file write, or file deletion operations. | ||||
| CVE-2026-85488 | 1 Broadcom | 1 Brocade Active Support Connectivity Gateway | 2026-10-09 | N/A |
| Brocade ASCG before 3.5.0 has a well-known Brocade default password embedded in a script distributed to every customer. Any local authenticated user with read access to the installation path can discover this credential and perform privilege escalation on affected Open Virtual Appliance (OVA) deployments, where default configuration settings remain in place. | ||||
| CVE-2026-85489 | 1 Broadcom | 1 Brocade Active Support Connectivity Gateway | 2026-10-09 | N/A |
| An authentication flaw exists in the Brocade ASCG administrative management service component. An unauthenticated network user can issue direct API requests to perform privileged actions, including accessing sensitive system configuration mapping data, modifying managed device inventories, and altering operational settings. This vulnerability affects all versions of Brocade ASCG before 3.5.0. | ||||