Export limit exceeded: 403786 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403786 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-105841 | 2 Lrzsz Project, Uwe Ohse | 2 Lrzsz, Lrzsz | 2026-10-09 | 7.5 High |
| lrzsz before 0.13.0 contains an OS command injection vulnerability in the lrz receive utility's pipe mode that allows remote senders to execute commands by supplying crafted filenames. When lrz runs under a suffixed name such as lrztar, procheader() in src/lrz.c passes the unescaped ZMODEM/YMODEM filename to popen(), so shell metacharacters execute as the receiving user. | ||||
| CVE-2026-105842 | 2 Lrzsz Project, Uwe Ohse | 2 Lrzsz, Lrzsz | 2026-10-09 | 6.4 Medium |
| lrzsz before 0.13.0 contains a heap-based buffer overflow vulnerability in procheader() of the lrz receive utility when copying overlong sender-supplied filenames into Pathname. Malicious ZMODEM senders can supply filenames up to 8192 bytes, overflowing the buffer via sprintf() in pipe mode or strcpy() to corrupt heap memory and crash lrz. | ||||
| CVE-2026-91140 | 1 Progress Software | 1 Autonomous Rest Connector Genai Agents | 2026-10-09 | 9.6 Critical |
| An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator. | ||||
| CVE-2026-85523 | 1 Felisify Information Technologies Industry And Trade | 1 Sambabox | 2026-10-09 | 8.8 High |
| Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Felisify Information Technologies Industry and Trade Inc. SambaBox allows OS Command Injection. This issue affects SambaBox: before 5.4.1. | ||||
| CVE-2026-105794 | 1 Microsoft | 1 Msquic | 2026-10-09 | N/A |
| MsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed to C, C++, C#, and Rust. Prior to 2.4.20, 2.5.11, and 2.6.1, MsQuic clients using the OpenSSL or QuicTLS TLS backend do not properly verify that a server certificate matches the intended target server hostname. An on-path attacker can therefore present a certificate that does not match the intended target hostname and spoof the server in a man-in-the-middle attack. The Schannel backend is not affected. This issue is fixed in versions 2.4.20, 2.5.11, and 2.6.1. | ||||
| CVE-2026-105795 | 1 Microsoft | 3 Kiota, Microsoft.openapi.kiota, Microsoft.openapi.kiota.builder | 2026-10-09 | 3.1 Low |
| Kiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, Kiota copies x-ai-capabilities.response_semantics.oauth_card_path from an attacker-controlled or compromised OpenAPI description into a generated API plugin manifest without validating that the value is a safe package-relative file reference. Parent-directory traversal, rooted paths, or absolute URIs can therefore reach a consuming host that resolves the reference, allowing the host to cross the intended plugin-package boundary or use an unintended authentication card. Kiota does not itself read a local file or execute code merely while generating the manifest, and impact requires downstream resolution of the unsafe reference. This issue is fixed in version 1.35.0. | ||||
| CVE-2026-105796 | 1 Microsoft | 3 Kiota, Microsoft.openapi.kiota, Microsoft.openapi.kiota.builder | 2026-10-09 | 8.8 High |
| Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a terminator and place attacker-controlled OpenAPI text outside a generated documentation comment. The Java sanitizer also removes non-ASCII characters after deleting terminators, which can create a new terminator during normalization. Exploitation requires a developer or build pipeline to generate source from the malicious description and then compile and load the Java output or load the PHP output, after which injected code executes in the consuming application or build environment context. The version range is based on the Java defect and does not assert that PHP generation existed in every affected release. This issue is fixed in version 1.35.0. | ||||
| CVE-2026-105799 | 1 Langchain-ai | 2 Langchainjs, Redis | 2026-10-09 | N/A |
| LangChain is a framework for building LLM-powered applications. Prior to 1.1.1, @langchain/redis does not escape attacker-controlled values in structured RediSearch TAG filters and structured RediSearch TEXT filters, allowing injected RediSearch syntax to alter or broaden the generated search query. When an application uses an attacker-influenceable filter as a tenant or document-access boundary, the modified query can expose indexed documents outside the attacker's intended scope. This issue is fixed in version 1.1.1. | ||||
| CVE-2025-8352 | 1 Eset | 1 Eset Protect | 2026-10-09 | N/A |
| Allocation of resources without limits or throttling vulnerability in ESET PROTECT On-Prem increased resource consumption (CPU and RAM), leading to conditions for a Denial-of-Service attack. | ||||
| CVE-2026-105801 | 1 Openapi-generators | 1 Openapi-python-client | 2026-10-09 | N/A |
| openapi-python-client generates Python clients from OpenAPI documents. Prior to 0.29.1, the generator does not safely neutralize malicious OpenAPI document content before rendering string, docstring, and f-string contexts in generated Python. The generated Python client can contain attacker-controlled Python that executes when a user imports the client, affecting the importing environment's integrity and potentially its confidentiality and availability. This issue is fixed in version 0.29.1. | ||||
| CVE-2026-104069 | 2 Daniel Brendel, Wordpress-extensions | 2 Hortusfox, Hortusfox | 2026-10-09 | 7.2 High |
| HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() where an uploaded ZIP archive is extracted directly into the public web root before any validation of file names, extensions, or content is performed. An authenticated administrator can upload a crafted theme archive containing a PHP file and an .htaccess file to re-enable execution, then request it under the themes directory to execute arbitrary OS commands as the web-server user. | ||||
| CVE-2026-105806 | 1 Payloadcms | 2 Payload, Plugin-mcp | 2026-10-09 | N/A |
| Payload is a free and open source headless content management system. In @payloadcms/plugin-mcp versions from 3.61.0 until 3.88.0, an authenticated user can manage MCP API keys outside the intended account, enabling privilege escalation through account takeover. This issue is fixed in version 3.88.0. | ||||
| CVE-2026-105844 | 1 Payloadcms | 2 Payload, Plugin-import-export | 2026-10-09 | N/A |
| Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an unauthenticated user can submit prototype-sensitive field paths when @payloadcms/plugin-import-export is enabled, causing unintended application behavior that can lead to remote code execution. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27. | ||||
| CVE-2026-105846 | 1 Payloadcms | 2 Next, Payload | 2026-10-09 | 6.1 Medium |
| Payload is a free and open source headless content management system. In versions from 3.40.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an attacker can craft a redirect URL parameter that sends a guest user to an untrusted destination after the authentication flow completes. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27. | ||||
| CVE-2026-105848 | 1 Payloadcms | 2 Payload, Plugin-stripe | 2026-10-09 | N/A |
| Payload is a free and open source headless content management system. In @payloadcms/plugin-stripe versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can reach the enabled optional Stripe REST proxy can perform unintended Stripe operations. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34. | ||||
| CVE-2026-105850 | 1 Payloadcms | 2 Payload, Plugin-ecommerce | 2026-10-09 | N/A |
| Payload is a free and open source headless content management system. In @payloadcms/plugin-ecommerce versions before 3.90.0 and canary versions before 4.0.0-canary.34, use of the Stripe payment adapter can allow a Stripe order confirmation to be processed more than once under certain conditions. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34. | ||||
| CVE-2026-104070 | 1 Spip | 1 Spip Crayons Plugin | 2026-10-09 | 9.8 Critical |
| The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a malicious .html skeleton file, disclose sensitive configuration files containing the site secret, and forge a signed ajax context to execute the uploaded skeleton, achieving arbitrary PHP code execution as the web-server user. | ||||
| CVE-2026-105856 | 1 Payloadcms | 5 Db-d1-sqlite, Db-postgres, Db-sqlite and 2 more | 2026-10-09 | N/A |
| Payload is a free and open source headless content management system. Prior to 3.90.0 and 4.0.0-canary.34, an attacker with read and create or update access to a collection containing a json field or a blocks field with blocksAsJSON enabled can inject SQL through a crafted field path and operators. Collections without those fields are not affected, and richText fields are not affected. The SQLite packages are fixed in versions 3.90.0 and 4.0.0-canary.34, and the Postgres packages are fixed in version 3.73.0. | ||||
| CVE-2026-105864 | 1 Payloadcms | 2 Payload, Plugin-multi-tenant | 2026-10-09 | N/A |
| Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user limited to one tenant can create a record in another tenant when at least one tenant-enabled collection exists. Reads and direct edits of existing documents in the target tenant are not bypassed. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34. | ||||
| CVE-2026-105867 | 1 Payloadcms | 2 Payload, Storage-s3 | 2026-10-09 | N/A |
| Payload is a free and open source headless content management system. In @payloadcms/storage-s3 versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user can overwrite an existing S3 object belonging to another upload collection when client uploads are enabled for multiple collections sharing a bucket and useCompositePrefixes is false or unset. This bypasses the target collection's access controls and prior file validation. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34. | ||||