Export limit exceeded: 403698 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403698 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403698 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-92555 | 1 Akin | 1 Akinsoft Wolvox Control Panel | 2026-10-09 | 9.8 Critical |
| Insertion of sensitive information into sent data vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. AKINSOFT WOLVOX Control Panel allows Pull Data from System Resources. This issue affects AKINSOFT WOLVOX Control Panel: from 26.02.25 before 26.02.26. | ||||
| CVE-2026-19218 | 1 Akin | 1 Myrezzta | 2026-10-09 | 9.1 Critical |
| Weak Password Recovery Mechanism for Forgotten Password vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. MyRezzta allows Password Recovery Exploitation. This issue affects MyRezzta: from 2.06.03 before 2.07.01. | ||||
| CVE-2026-62128 | 2 Creator Lms, Wordpress-extensions | 2 Creator Lms, Creator Lms | 2026-10-09 | 5.3 Medium |
| Missing Authorization vulnerability in Creator LMS Creator LMS creatorlms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Creator LMS: from n/a through 1.2.21. | ||||
| CVE-2026-62127 | 2 Mediaron, Wordpress-extensions | 2 Wp Plugin Info Card, Wp Plugin Info Card | 2026-10-09 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MediaRon LLC WP Plugin Info Card wp-plugin-info-card allows Stored XSS.This issue affects WP Plugin Info Card: from n/a through 6.3.5. | ||||
| CVE-2026-42698 | 2 Themeum, Wordpress-extensions | 2 Tutor Lms, Tutor Lms | 2026-10-09 | 5.3 Medium |
| Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Themeum Tutor LMS tutor allows Leveraging Race Conditions.This issue affects Tutor LMS: from n/a through 4.1.1. | ||||
| CVE-2026-27420 | 2 Katieseaborn, Wordpress-extensions | 2 Zotpress, Zotpress | 2026-10-09 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Katie Seaborn Zotpress zotpress allows Stored XSS.This issue affects Zotpress: from n/a through 7.4.4. | ||||
| CVE-2026-107611 | 1 Glavsoft | 1 Tightvnc | 2026-10-09 | 7.1 High |
| An out-of-bounds read vulnerability in the ZRLE decoder of GlavSoft TightVNC Viewer for Windows before 2.8.88 allows a malicious or compromised VNC server to read heap memory beyond the palette allocation and crash the viewer by sending ZRLE-encoded tiles whose palette indices exceed the declared palette size. readPaletteRleTile() and readPackedPaletteTile() use the attacker-supplied index to look up colours without validating it against the palette size; out-of-bounds heap data is copied into the framebuffer (garbled display) or the read faults, terminating the viewer. | ||||
| CVE-2026-107612 | 1 Glavsoft | 1 Tightvnc | 2026-10-09 | 7.8 High |
| Incorrect permission assignment in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to read or overwrite the inter-process communication handles used between the TightVNC service and its desktop server process. The named shared memory segment in the Global\ namespace that carries the pipe HANDLE values is created with a NULL DACL, and its name is derived from a time-seeded srand(time(0)) value that is predictable to one-second granularity. A low-privileged local process can open the mapping and tamper with the IPC channel of a service running as SYSTEM, potentially leading to disclosure of session data, privilege escalation, or denial of service. | ||||
| CVE-2026-107613 | 1 Glavsoft | 1 Tightvnc | 2026-10-09 | 5.9 Medium |
| A NULL pointer dereference vulnerability in the Win8ScreenDriver component of GlavSoft TightVNC Server for Windows before 2.8.88 allows an attacker to crash the server, causing a denial of service. When re-initialization of the DXGI Desktop Duplication driver fails in applyNewScreenProperties() (for example after a GPU reset, display hot-plug or session change), m_drvImpl is left NULL and is subsequently dereferenced without a check by executeDetection(), getScreenBuffer(), grabFb(), getScreenPropertiesChanged() and getCursorPosition(). | ||||
| CVE-2026-107614 | 1 Glavsoft | 1 Tightvnc | 2026-10-09 | 6.1 Medium |
| An integer underflow in WinCursorShapeUtils::trimTransparent() in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to crash the server, and potentially read out-of-bounds memory, by causing a cursor shape with a width or height of zero to be processed on the DXGI capture path. The loop bound width - 1 wraps to 0xFFFFFFFF, producing an access roughly 4 GB beyond the 64 KB cursor buffer; a monochrome cursor of height 1 also becomes 0 because getCursorHeight() halves the height in place. | ||||
| CVE-2026-107615 | 1 Glavsoft | 1 Tightvnc | 2026-10-09 | 7.8 High |
| An uncontrolled search path element vulnerability in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to execute arbitrary code with SYSTEM privileges. DynamicLibrary::init() (and ThemeLib) load screenhooks32.dll / screenhooks64.dll with LoadLibrary() using a bare file name and no LOAD_LIBRARY_SEARCH_* flags, so the TightVNC service follows the default DLL search order and loads an attacker-planted DLL from a writable directory earlier in that order (for example, an installation directory with permissive ACLs). | ||||
| CVE-2026-91844 | 1 İzometri It | 1 Eimzamip | 2026-10-09 | 7.3 High |
| Unrestricted upload of file with dangerous type vulnerability in İzometri IT Services Domestic and Foreign Trade Co. Ltd. Eimzamip allows Using Malicious Files. This issue affects eimzamip: from v1.6.4 before v1.6.6. | ||||
| CVE-2026-89290 | 1 İzometri It | 1 Eimzamip | 2026-10-09 | 3.5 Low |
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in İzometri IT Services Domestic and Foreign Trade Co. Ltd. Eimzamip allows Stored XSS. This issue affects eimzamip: from v1.6.4 before v1.6.7. | ||||
| CVE-2026-107634 | 1 Aorimn | 1 Dislocker | 2026-10-09 | 6.1 Medium |
| Dislocker through 0.7.3 contains a heap out-of-bounds read vulnerability in get_dataset() and get_next_datum() that never validate dataset and datum sizes against the metadata allocation. Attackers can craft a BitLocker volume image with inflated dataset or datum sizes that, when opened or mounted, crashes dislocker or discloses adjacent heap memory. | ||||
| CVE-2026-107635 | 1 Aorimn | 1 Dislocker | 2026-10-09 | 5.5 Medium |
| Dislocker through 0.7.3 contains an integer underflow vulnerability in get_vmk() and get_fvek() that allows attackers to trigger out-of-bounds heap reads via crafted datum sizes. Attackers can supply a malicious BitLocker volume image with a datum_size smaller than the 36-byte AES-CCM header, causing hexdump() to over-read and crash dislocker. | ||||
| CVE-2026-107640 | 1 Integrics | 1 Enswitch | 2026-10-09 | 9.1 Critical |
| Integrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json/user/password/update/ that allows unauthenticated attackers to change account passwords by omitting the reset parameter. Attackers can target accounts with no pending reset, whose empty reset_key matches the defaulted empty value, to take over administrator accounts after enumerating valid usernames. | ||||
| CVE-2026-12859 | 1 Caz Informatics | 1 Advancity Alms Cloud | 2026-10-09 | 6.5 Medium |
| Missing Authorization vulnerability in Caz Informatics Services Trade Inc. Advancity ALMS Cloud allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Advancity ALMS Cloud: through 2026-10-08. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-107565 | 2 Luksmeta, Redhat | 4 Luksmeta, Enterprise Linux, Openshift and 1 more | 2026-10-09 | 5.1 Medium |
| A flaw was found in luksmeta. A local attacker with administrative privileges can cause data corruption when saving metadata to a Linux Unified Key Setup (LUKS) device. Due to incorrect boundary calculations and flawed overlap detection, new metadata entries can be written beyond available free space or over existing records. This issue can corrupt stored encrypted payload data or existing metadata, potentially rendering the affected data inaccessible. | ||||
| CVE-2026-107623 | 1 Redhat | 4 Build Keycloak, Build Of Keycloak, Red Hat Single Sign On and 1 more | 2026-10-09 | 4.3 Medium |
| A flaw was found in the OIDC Dynamic Client Registration (DCR) component of Keycloak. A bug in the response serialization causes the backchannel logout offline token revocation setting to be omitted from responses. When a client performs a standard update, this missing information causes the setting to be silently disabled. As a result, offline tokens may remain valid even after a user session is terminated via backchannel logout. | ||||
| CVE-2026-107589 | 1 Jacamar Ci | 1 Jacamar Ci | 2026-10-09 | 7.5 High |
| Insufficient job validation for service accounts in Jacamar CI prior to v0.30.0 allows authenticated CI users to generate arbitrary account names. | ||||