Export limit exceeded: 403368 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403368 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403368 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-37906 | 1 Arubanetworks | 2 Arubaos, Sd-wan | 2026-10-08 | 6.5 Medium |
| An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnerability results in the ability to delete arbitrary files on the underlying operating system. | ||||
| CVE-2026-106399 | 1 Google | 1 Chrome | 2026-10-08 | 3.3 Low |
| Out of bounds read in Skia in Google Chrome prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to potentially read memory via a crafted file. (Chromium security severity: Low) | ||||
| CVE-2022-37897 | 1 Arubanetworks | 2 Arubaos, Sd-wan | 2026-10-08 | 9.8 Critical |
| There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system. | ||||
| CVE-2026-106424 | 1 Google | 1 Chrome | 2026-10-08 | 4.0 Medium |
| Information leak in Audio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium) | ||||
| CVE-2026-64015 | 1 Linux | 1 Linux Kernel | 2026-10-08 | 7.8 High |
| In the Linux kernel, the following vulnerability has been resolved: security/keys: fix missed RCU read section on lookup Nicholas Carlini reports that the keyring code calls assoc_array_find() in find_key_to_update() without holding the RCU read lock, while the assoc_array_gc() code really is designed around removing the node from the tree and then freeing it after an RCU grace-period. The regular key handling doesn't see this because holding the keyring semaphore hides any lifetime issues, but the persistent key handling uses a different model. Instead of extending the keyring locking, just do the simple RCU locking that the assoc_array was designed for. | ||||
| CVE-2026-107299 | 2026-10-08 | 5.9 Medium | ||
| msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When 0xc1 begins a stream, subsequent data remains buffered while the decoder waits for bytes that cannot make the value valid, allowing a remote peer to exhaust memory. This issue is fixed in version 6.1.0. | ||||
| CVE-2026-107298 | 2026-10-08 | 5.3 Medium | ||
| msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the array and map decoding paths have no nesting-depth limit, allowing an attacker who can provide MessagePack input to submit deeply nested containers that exhaust the JavaScript call stack and interrupt a process, worker, or request handler. This issue is fixed in version 6.1.0. | ||||
| CVE-2026-107296 | 2026-10-08 | 3.7 Low | ||
| msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer while computing the value. Applications that retain or reuse encoded input for integrity checks, logging, or later processing can observe silently corrupted data, while positive integers and other MessagePack value types are unaffected. This issue is fixed in version 6.1.0. | ||||
| CVE-2026-93034 | 1 Sglang | 1 Sglang | 2026-10-08 | N/A |
| SGLang contains an arbitrary code execution vulnerability caused by the ZMQ message decoder unconditionally deserializing PickleWrapper payloads via pickle.loads() in _maybe_unwrap_pickle without type allowlisting or authentication; this vulnerability persists via the msgpack path even when SGLANG_USE_PICKLE_IPC is disabled, and becomes remotely exploitable if data-parallel attention is enabled with a non-loopback --dist-init-addr setting. | ||||
| CVE-2026-105436 | 2026-10-08 | 8.8 High | ||
| Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-child allows Object Injection.This issue affects MainWP Child: from n/a through 6.2.1. | ||||
| CVE-2026-62167 | 2026-10-08 | N/A | ||
| This CVE is a duplicate of another CVE. | ||||
| CVE-2026-67411 | 2 Broadcom, Rabbitmq | 2 Rabbitmq Server, Rabbitmq-server | 2026-10-08 | 7.1 High |
| RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18, 4.0.23, 4.1.14, 4.2.9, and 4.3.3, native MQTT and MQTT over WebSocket behind a trusted PROXY Protocol frontend could lose the proxy-derived client address before the MQTT authentication path checked loopback_users, causing the frontend-to-broker address to be treated as loopback. An attacker who can reach the trusted frontend and has valid credentials for a loopback-restricted account can therefore bypass the source-address restriction; the issue does not bypass password authentication. This issue is fixed in versions 3.13.18, 4.0.23, 4.1.14, 4.2.9, and 4.3.3. | ||||
| CVE-2026-67412 | 2 Broadcom, Rabbitmq | 2 Rabbitmq Server, Rabbitmq-server | 2026-10-08 | 7.1 High |
| RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18, Federation upstream in RabbitMQ skips vhost authorization allowing cross-vhost message access. what the bug lets you do. A policymaker on one vhost reads and drains messages out of another vhost it has no permission on. With the default ack-mode the source messages are consumed (deleted), not copied. Why that should not 1. Federation validates the upstream URI without any vhost-access Cross-vhost message read/drain from a per-vhost policymaker, breaking vhost tenancy This issue is fixed in versions 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18. | ||||
| CVE-2026-62166 | 2026-10-08 | N/A | ||
| This CVE is a duplicate of another CVE. | ||||
| CVE-2026-62163 | 2026-10-08 | N/A | ||
| Reason: This candidate is a duplicate of CVE-2026-60089. | ||||
| CVE-2026-105828 | 2 Parse Community, Parseplatform | 2 Parse Server, Parse-server | 2026-10-08 | N/A |
| Parse Server 8.2.2 before 8.6.92 and 9.0.0 before 9.10.1-alpha.12 contains an information disclosure vulnerability in which GraphQL validation error messages reveal hidden class names when public introspection is disabled. Unauthenticated attackers holding only the public Application Id can send crafted operations triggering unknown-argument or invalid enum value errors to learn pointer and relation target classes. | ||||
| CVE-2026-39790 | 2 E4jvikwp, Wordpress-extensions | 2 Vikrentcar, Vikrentcar | 2026-10-08 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRentCar vikrentcar allows Reflected XSS.This issue affects VikRentCar: from n/a through 1.4.7. | ||||
| CVE-2026-39723 | 2026-10-08 | 7.5 High | ||
| Missing Authorization vulnerability in Green Invoice Morning for WooCommerce wc-gateway-greeninvoice allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Morning for WooCommerce: from n/a through 2.4.1. | ||||
| CVE-2026-94583 | 1 Brocade | 1 Fabric Os | 2026-10-08 | N/A |
| A race condition vulnerability exists in the request processing logic of the REST management interface on Brocade Fabric OS versions before 10.0.1. When handling concurrent incoming network management FCIP requests, a timing window exists between when a request populates the address variable and when the service constructs and returns the response context. As a result, the first request adopts the modified context, causing the service to return sensitive management details or configuration data belonging to the second context back to the original requester. | ||||
| CVE-2026-94582 | 1 Brocade | 1 Fabric Os | 2026-10-08 | N/A |
| A memory buffer overflow vulnerability exists in the internal diagnostic and route validation routines used by the Fabric Shortest Path First (FSPF) protocol component of Brocade Fabric OS versions before 10.0.1. While this code path is part of internal diagnostic functionality and is not directly accessible via standard user interfaces or CLI management commands, an input processing flaw allows incoming or internally routed diagnostic state payloads to exceed allocated memory boundaries. An attacker that is able to chain or link other vulnerabilities to exploit this internal diagnostic could cause a heap- or stack-based memory overrun, resulting in a daemon crash (Denial of Service) or potential arbitrary code execution within the context of the routing daemon. | ||||