Export limit exceeded: 51781 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403800 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403800 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-87742 | 1 Redhat | 4 Build Of Quarkus, Enterprise Linux Ai, Exploit Intelligence and 1 more | 2026-10-09 | 7.5 High |
| A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single connection faster than the application can process them. Due to unbounded message buffering and a lack of read backpressure, this rapidly exhausts heap space, leading to a java.lang.OutOfMemoryError that crashes the Java Virtual Machine (JVM). | ||||
| CVE-2024-3656 | 1 Redhat | 3 Build Keycloak, Jboss Enterprise Application Platform, Red Hat Single Sign On | 2026-10-09 | 8.1 High |
| A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This flaw allows users to perform actions reserved for administrators, potentially leading to data breaches or system compromise. | ||||
| CVE-2026-105241 | 1 Apache | 1 Log4net | 2026-10-09 | 5.3 Medium |
| Improper Handling of Unicode Encoding vulnerability in the SmtpPickupDirAppender of Apache log4net. Content that the mail file writer cannot encode, such as an unpaired UTF-16 surrogate, made the write throw. Every buffered event in the batch was discarded, not only the one carrying the content, and a truncated mail could be left in the pickup directory. A party whose data reaches a log message could suppress the records of other events. Only applications that use SmtpPickupDirAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue. | ||||
| CVE-2026-105242 | 1 Apache | 1 Log4net | 2026-10-09 | 5.3 Medium |
| Improper Handling of Exceptional Conditions vulnerability in the aspnet-request pattern converter of Apache log4net. Reading request parameters triggers ASP.NET request validation, so a request carrying content such as markup made the layout throw and the appender discarded the whole event. A sender could suppress the log record of their own request. Only applications on ASP.NET for .NET Framework whose layout uses %aspnet-request are affected. This issue affects Apache log4net: from 1.2.11 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue. | ||||
| CVE-2026-105243 | 1 Apache | 1 Log4net | 2026-10-09 | 5.3 Medium |
| Insufficient Logging vulnerability in the EventLogAppender of Apache log4net. Long messages were truncated to a fixed size that exceeds what the Windows Event Log accepts once the log and source names are counted, and the event log then stored nothing and reported nothing. A party whose data reaches a log message could suppress the whole record by making it long enough. Only applications on Windows that use EventLogAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue. | ||||
| CVE-2026-105244 | 1 Apache | 1 Log4net | 2026-10-09 | 5.3 Medium |
| Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net. Every character outside visible ASCII and space was removed from the record instead of being escaped, so non-ASCII text and control characters such as tabs disappeared without notice. A party whose data reaches a log message could make a distinct value look identical in the record, for example a user name holding a zero-width space logged as admin. Only applications that use RemoteSyslogAppender are affected. This issue affects Apache log4net: from 1.2.12 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue. | ||||
| CVE-2026-96207 | 1 Microsoft | 1 Partner Center | 2026-10-09 | 10 Critical |
| Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-94510 | 1 Microsoft | 1 Bookings | 2026-10-09 | 9.9 Critical |
| Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-92990 | 2026-10-09 | 5.3 Medium | ||
| The SendPress Newsletters WordPress plugin through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the same on every site rather than a per-site secret, allowing unauthenticated users to read newsletter sending logs, including recipient email addresses. | ||||
| CVE-2026-92989 | 2026-10-09 | 4.3 Medium | ||
| The SendPress Newsletters WordPress plugin through 1.26.1.20 does not check the user's capability on several newsletter-management actions, allowing any authenticated subscriber-level user to synchronise all site users into a mailing list and to drive the newsletter send queue. | ||||
| CVE-2026-89235 | 2026-10-09 | 6.8 Medium | ||
| The Testimonials by BestWebSoft WordPress plugin through 1.0.8 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL to the query. | ||||
| CVE-2026-88131 | 1 Microsoft | 1 Dataverse | 2026-10-09 | 9.8 Critical |
| Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-86850 | 2026-10-09 | 6.5 Medium | ||
| The SKU Error Fixer for WooCommerce WordPress plugin through 1.0 does not perform any capability or nonce checks on two of its AJAX actions, which are also available to unauthenticated users, allowing them to permanently delete product variations it classifies as obsolete, and to disclose those variations' details, with no recoverable copy left behind. | ||||
| CVE-2026-85348 | 2026-10-09 | 4.3 Medium | ||
| The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF protection when updating one of its settings, allowing attackers to change that setting via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | ||||
| CVE-2026-84224 | 2026-10-09 | 4.1 Medium | ||
| The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetching it, allowing users with editor-level access and above to make the site issue requests to internal services that are not otherwise reachable, and to tell which of those are live from the response. | ||||
| CVE-2026-84032 | 1 Ibm | 1 Guardium Data Protection | 2026-10-09 | 5.6 Medium |
| IBM Guardium Data Protection 12.2.2 could allow a remote attacker to conduct a man-in-the-middle attack due to improper certificate validation. | ||||
| CVE-2026-83947 | 1 Microsoft | 1 Azure Event Grid System | 2026-10-09 | 7.7 High |
| Missing authorization in Azure Event Grid allows an authorized attacker to perform spoofing over a network. | ||||
| CVE-2026-83943 | 1 Microsoft | 1 Azure Api Center | 2026-10-09 | 8.7 High |
| Exposure of sensitive information to an unauthorized actor in Azure API Center allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-78027 | 2026-10-09 | 5.8 Medium | ||
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Server-side request forgery. | ||||
| CVE-2026-78022 | 2026-10-09 | 6.8 Medium | ||
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Not Failing Securely ('Failing Open') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. | ||||