Export limit exceeded: 403057 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403057 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403057 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104035 | 2 Redhat, Sssd | 4 Enterprise Linux, Openshift, Openshift Container Platform and 1 more | 2026-10-08 | 5.5 Medium |
| A flaw was found in SSSD. An issue in the Kerberos Credential Manager (KCM) responder allows a local user to cause a Denial of Service (DoS) by maintaining a persistent connection and repeatedly storing and destroying credentials. Because the service fails to release cached objects from memory when credentials are removed, memory consumption grows continuously, ultimately exhausting available memory and rendering the service unresponsive. | ||||
| CVE-2026-87680 | 1 Brocade | 1 Fabric Os | 2026-10-08 | N/A |
| A command injection vulnerability in the REST API management interface of Brocade Fabric OS versions before 10.0.1 allows an authenticated user to execute arbitrary system commands via crafted input parameters. | ||||
| CVE-2026-87682 | 1 Brocade | 1 Fabric Os | 2026-10-08 | N/A |
| Multiple OS Command Injection vulnerabilities exist in the management interface and session processing routines of Brocade Fabric OS versions before 10.0.1. Input processing flaws during remote management connection validation and session verification for directory-based user accounts allow untrusted input containing shell metacharacters to reach internal system execution wrappers. An authenticated user or a compromised directory service account can exploit these vulnerabilities to execute arbitrary operating system commands with elevated privileges on the target device. | ||||
| CVE-2026-87683 | 1 Brocade | 1 Fabric Os | 2026-10-08 | N/A |
| Multiple stack-based buffer overflow vulnerabilities exist in the REST API management component of Brocade Fabric OS versions prior to 10.0.1. When processing API request payloads (such as device configuration attributes or port mapping requests) the REST API service fails to properly validate incoming array counts and string lengths against internal buffer capacities. An authenticated attacker with REST API access can transmit crafted, oversized request parameters to induce memory corruption on the execution stack. This may result in a denial-of-service condition (daemon crash) or potential arbitrary code execution within the management process context. | ||||
| CVE-2026-102488 | 2026-10-08 | N/A | ||
| In affected versions, Octopus Server incorrectly evaluates multiple scoped permission assignments, allowing a highly privileged user to obtain deployment permissions beyond those actually granted to them. | ||||
| CVE-2017-20283 | 1 Nxp | 1 Mqx | 2026-10-08 | 6.5 Medium |
| NXP MQX Classic before 5.0 contains an out-of-bounds write vulnerability in the RTCS UDP recvfrom() implementation. Improper enforcement of the application-supplied receive buffer length may allow a crafted UDP packet to overflow the destination buffer, resulting in memory corruption, or denial of service. | ||||
| CVE-2025-70516 | 2026-10-08 | 9.1 Critical | ||
| The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests. | ||||
| CVE-2026-95386 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 5.5 Medium |
| TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of service | ||||
| CVE-2026-95387 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 8.1 High |
| SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-95388 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 5.5 Medium |
| Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-95389 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 8.1 High |
| SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-95390 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 5.5 Medium |
| PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of service | ||||
| CVE-2026-95391 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 5.5 Medium |
| ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial of service | ||||
| CVE-2026-95392 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 5.5 Medium |
| MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-95393 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 4.7 Medium |
| CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-95394 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 4.7 Medium |
| Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-95395 | 1 Wireshark | 1 Wireshark | 2026-10-08 | 5.5 Medium |
| IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-105752 | 2 Vllm, Vllm-project | 2 Vllm, Vllm | 2026-10-08 | 3.1 Low |
| vLLM is an inference and serving engine for large language models. Prior to 0.30.0, Harmony tool continuations submitted through "POST /v1/responses" requests rebuild the next-turn engine input without preserving the cache_salt value, placing the continuation prefix in the global unsalted cache namespace even when the caller enabled salting. On deployments with prefix caching enabled, which is the default, an authenticated tenant who can reconstruct a victim's low-entropy post-tool history can submit the same continuation and use the cached_tokens_per_turn count to determine whether the prefix was previously processed, defeating the intended tenant isolation of salted prefix caching. This issue is fixed in version 0.30.0. | ||||
| CVE-2026-105753 | 2 Vllm, Vllm-project | 2 Vllm, Vllm | 2026-10-08 | 6.5 Medium |
| vLLM is an inference and serving engine for large language models. Prior to 0.28.0, the default mirrored multimodal LRU cache can commit a media hash in the frontend sender cache during multimodal rendering and before engine admission, while the engine receiver cache never receives the payload if that request is rejected. A later request reusing the same media hash causes MultiModalProcessorSenderCache to send no payload and MultiModalReceiverCache to reach an assertion with the message "Expected a cached item," producing a shared-service availability failure. This issue is fixed in version 0.28.0. | ||||
| CVE-2026-105755 | 2 Vllm, Vllm-project | 2 Vllm, Vllm | 2026-10-08 | 4.2 Medium |
| vLLM is an inference and serving engine for large language models. Prior to 0.30.0, flash late-interaction scoring at the /score and /rerank endpoints derives each worker's query_key value from the caller-controlled X-Request-Id header. A concurrent request that reuses a victim's identifier can overwrite the cached query embedding so the victim's documents are scored against the attacker's query, and shared use counters can also cause a late-interaction cache-miss error. This issue is fixed in version 0.30.0. | ||||