Export limit exceeded: 403660 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403663 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-97791 | 1 Apache | 1 Cxf | 2026-10-09 | N/A |
| In Apache CXF, STSTokenValidator checks whether a SAML assertion is signed by a trusted certificate before deciding to send it to the STS. That result was stored in one object shared by all requests, so one request could read another's result. A remote, unauthenticated attacker could send a forged assertion signed with an untrusted certificate while legitimate requests were being processed, and it could be accepted as trusted without ever reaching the STS. Only services that use STSTokenValidator to validate SAML tokens without alwaysValidateToSts set are affected. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue. | ||||
| CVE-2026-104047 | 3 Fedoraproject, Redhat, Sssd | 5 Sssd, Enterprise Linux, Openshift and 2 more | 2026-10-09 | 5.3 Medium |
| A flaw was found in SSSD. When configured to use Microsoft Entra ID, search inputs are not properly sanitized before being incorporated into directory query filters. A local user can exploit this vulnerability by submitting a crafted lookup request, manipulating the query logic to cause unauthorized information disclosure from the directory. | ||||
| CVE-2026-104048 | 3 Fedoraproject, Redhat, Sssd | 5 Sssd, Enterprise Linux, Openshift and 2 more | 2026-10-09 | 6.8 Medium |
| A flaw was found in SSSD. In trust-enabled identity management environments, SSSD evaluates Host-Based Access Control (HBAC) rules by stripping domain qualifiers and comparing only short usernames. An authenticated user in a trusted domain who shares the same username as an authorized local account can bypass access policies and gain unauthorized access to protected services or hosts. | ||||
| CVE-2026-103413 | 2026-10-09 | 8.8 High | ||
| Improper input validation vulnerability in Apache Camel Karavan. When a deployment was started, Karavan unmarshalled a project's `kubernetes.yaml` and applied every resource it contained to the cluster without restricting the resource kinds, without rejecting security-sensitive pod options, and without pinning the target namespace. An authenticated user of any role could therefore have Karavan apply arbitrary Kubernetes resources within the reach of its service account, including pods requesting hostNetwork, hostPID, hostIPC, hostPath volumes, host ports, privileged containers, privilege escalation or added capabilities. This issue affects Apache Camel Karavan: from 4.0.0 before 4.22.1. Users are recommended to upgrade to version 4.22.1, which fixes the issue. | ||||
| CVE-2026-103412 | 2026-10-09 | 8.8 High | ||
| Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Apache Camel Karavan. A project file name supplied through the project file API was used verbatim as a path segment when the project was written to the working copy for a Git commit, so a name containing `../` sequences caused the file content to be written outside the project directory, to any location writable by the Karavan process. An authenticated user of any role could use this to overwrite application configuration or files on the application classpath and so execute code in the Karavan container. This issue affects Apache Camel Karavan: from 3.18.0 before 4.22.1. Users are recommended to upgrade to version 4.22.1, which fixes the issue. | ||||
| CVE-2026-86405 | 2026-10-09 | 9.8 Critical | ||
| Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. PrestaShop Virtual POS Module allows Signature Spoofing by Improper Validation. This issue affects PrestaShop Virtual POS Module: from 26.8.1 before 26.9.1. | ||||
| CVE-2026-103220 | 1 Canva | 1 Affinity | 2026-10-09 | 4.5 Medium |
| The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing raster image data in Affinity document files, leading to an out-of-bounds read and the dereference of an untrusted pointer. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could result in memory corruption or an application crash. | ||||
| CVE-2026-101130 | 1 Canva | 1 Affinity | 2026-10-09 | 3.6 Low |
| The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing arrays of strings in Affinity document files, leading to a heap buffer over-read. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could disclose the contents of adjacent heap memory in the document's text or result in an application crash. | ||||
| CVE-2026-78022 | 2026-10-09 | 6.8 Medium | ||
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Not Failing Securely ('Failing Open') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. | ||||
| CVE-2026-96396 | 1 Canva | 1 Affinity | 2026-10-09 | 4.9 Medium |
| The Affinity by Canva application for macOS before 3.3.1 (October 2026 release) did not safely calculate the size of an image buffer when generating QuickLook thumbnails and previews of Affinity document files, leading to an integer overflow and a heap-based buffer overflow. A threat actor could craft an Affinity document that, when displayed or previewed by a user in Finder, could corrupt heap memory and cause the thumbnail or preview extension to crash. | ||||
| CVE-2026-96395 | 1 Canva | 1 Affinity | 2026-10-09 | 3.6 Low |
| The Affinity by Canva app for macOS before 3.3.1 (October 2026 release) did not perform adequate bounds checking when generating QuickLook thumbnails and previews of Affinity document files, leading to an out-of-bounds heap read. A threat actor could craft an Affinity document that, when displayed or previewed by a user in Finder, could disclose the contents of adjacent heap memory, including memory addresses, in the rendered thumbnail or preview image. | ||||
| CVE-2026-87846 | 2026-10-09 | 5.3 Medium | ||
| The Shipping for Nova Poshta WordPress plugin through 1.19.8 does not perform any authorisation, nonce or ownership checks on one of its AJAX actions available to unauthenticated users, allowing anyone to delete the shipment records of arbitrary orders and to make the store issue the carrier's waybill-deletion request for those orders using the store's own stored API credentials. | ||||
| CVE-2026-103329 | 2026-10-09 | 5.3 Medium | ||
| The Super Payments WordPress plugin before 1.43.1 does not properly verify the authenticity of incoming payment webhook notifications, as the signing key used to validate their signature is empty by default, allowing unauthenticated attackers to forge a valid signature and mark arbitrary WooCommerce orders as paid without payment. | ||||
| CVE-2026-85531 | 2026-10-09 | 9.8 Critical | ||
| Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. OpenCart Virtual POS Module allows Signature Spoofing by Improper Validation. This issue affects OpenCart Virtual POS Module: from 26.8.2 before 26.9.1. | ||||
| CVE-2026-98375 | 1 Linux | 1 Linux Kernel | 2026-10-09 | N/A |
| In the Linux kernel, the following vulnerability has been resolved: xen/netfront: drop RX packets with a short Ethernet header handle_incoming_queue() pulls pull_to bytes into the head before calling eth_type_trans(). pull_to is the length of the first RX slot, capped at RX_COPY_THRESHOLD, and that length comes from the backend. Nothing checks it against ETH_HLEN. If the first slot is shorter than ETH_HLEN and more slots follow, the head ends up shorter than an Ethernet header while skb->len is longer, and eth_type_trans() BUG()s in __skb_pull(). If the whole packet is shorter than ETH_HLEN, eth_type_trans() reads the header past the end of the data instead. Pull at least ETH_HLEN, and drop the packet if that fails, which also drops packets too short to hold an Ethernet header. This also checks the return value of the pull, which was ignored. | ||||
| CVE-2026-97468 | 2026-10-09 | N/A | ||
| Apache CXF's STSTokenValidator and Security Token Service (STS) cached validated security tokens under a non-cryptographic 32-bit hash of the token (Java Arrays.hashCode/hashCode()), and treated a cache hit as proof that the presented token had already been validated. An attacker could craft a token (for example a UsernameToken or a self-signed SAML Assertion) whose hash collides with a cached entry. The token would then be accepted without password validation, signature trust verification or a call to the STS. This could let the attacker authenticate as another user and, through STS token validation or renewal, obtain STS-signed tokens for that identity. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue. | ||||
| CVE-2026-93860 | 1 Openstack | 1 Mistral | 2026-10-09 | 6.5 Medium |
| In OpenStack Mistral through 23.0.0, the /v2/maintenance API controller clears the request context and calls the maintenance service directly without any policy enforcement. Any holder of a valid Mistral token, regardless of assigned role, can read and change the service's cluster-wide maintenance state. Setting the state to PAUSED stops processing of new workflow and execution objects across all tenant projects until an operator restores it. | ||||
| CVE-2026-86463 | 1 Apache | 1 Cxf | 2026-10-09 | N/A |
| Apache CXF's FIQL query parser has a vulnerability in how it searches for operators in query expressions. The search pattern can get stuck trying many combinations when it encounters a long string without an operator, causing the parser to consume excessive CPU time. An attacker can send a crafted query to make the server use up CPU resources, potentially slowing down or stopping other requests. The fix was to limit FIQL expressions to 4 KiB by default, preventing attackers from sending extremely long inputs while still allowing normal queries. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue. | ||||
| CVE-2026-84250 | 1 Ibm | 1 Guardium Data Protection | 2026-10-09 | 8.4 High |
| IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. A local attacker could exploit this vulnerability to recover the root password and gain root privileges. | ||||
| CVE-2026-82334 | 1 Ibm | 1 Guardium Data Protection | 2026-10-09 | 8.1 High |
| IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based out-of-bounds read in the TDS7 LOGIN7 protocol parser. A remote attacker could send a specially crafted TDS LOGIN7 packet containing invalid offset or length values, potentially causing information disclosure or denial of service. | ||||