Export limit exceeded: 403770 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403770 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403770 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-106493 | 1 Backstage | 3 Backstage, Plugin-catalog-backend-module-aws, Plugin-catalog-backend-module-azure | 2026-10-09 | 3 Low |
| Backstage is an open framework for building developer portals. Prior to 1.54.6, cloud storage catalog providers did not sufficiently validate object paths. A principal able to create or rename objects in a configured Azure Blob Storage or AWS S3 catalog source could cause catalog descriptors to be read from outside the intended storage boundary, limited to locations reachable with the backend's configured credentials. This issue is fixed in 1.54.6. | ||||
| CVE-2026-106494 | 1 Backstage | 2 Backend-defaults, Backstage | 2026-10-09 | 4.4 Medium |
| Backstage is an open framework for building developer portals. Prior to 0.17.8, the @backstage/backend-defaults package is affected by improper input validation in cloud storage url readers. An attacker with write access to a cloud storage bucket used by Backstage could craft object names that could collide with protected files in the output directory. In certain deployment configurations, this could lead to content injection. This issue is fixed in version 0.17.8. | ||||
| CVE-2026-106496 | 1 Backstage | 2 Backstage, Plugin-catalog-backend | 2026-10-09 | 3.1 Low |
| Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host. This issue is fixed in version 3.9.1. | ||||
| CVE-2026-106497 | 1 Backstage | 2 Backstage, Plugin-catalog-backend | 2026-10-09 | 4.3 Medium |
| Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent catalog property permission evaluation. In deployments that use affected value-based catalog permission conditions as a confidentiality boundary, an authenticated user could receive catalog entity data that policy authors intended to restrict. This issue is fixed in version 3.9.1. | ||||
| CVE-2026-106498 | 1 Backstage | 2 Backstage, Plugin-catalog-backend | 2026-10-09 | 7.7 High |
| Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/plugin-catalog-backend package is affected by improper url validation in catalog entity placeholder resolution. An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under certain configurations, this could allow access to data not intended to be available to the user. This issue is fixed in versions 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1. | ||||
| CVE-2026-80048 | 2 Redhat, Sssd | 4 Enterprise Linux, Openshift, Openshift Container Platform and 1 more | 2026-10-09 | 5.5 Medium |
| A flaw was found in `sssd-kcm`. A local user or process able to connect to the `sssd-kcm` UNIX socket can exploit this vulnerability. By sending a large request length header and then stalling the connection, an attacker can cause the system to preallocate significant memory. This leads to memory exhaustion within the `sssd-kcm` responder, resulting in a Denial of Service (DoS) for affected deployments. | ||||
| CVE-2025-70515 | 1 Fanvil | 1 X7a | 2026-10-09 | N/A |
| The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows for the injection of HTML which can be used to execute malicious JavaScript code on any target browser which renders the device log component. | ||||
| CVE-2025-70516 | 1 Fanvil | 1 X7a | 2026-10-09 | 9.1 Critical |
| The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests. | ||||
| CVE-2025-70517 | 1 Fanvil | 1 X7a | 2026-10-09 | 8.8 High |
| The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint. | ||||
| CVE-2025-70518 | 1 Fanvil | 1 X7a | 2026-10-09 | 10 Critical |
| The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system. | ||||
| CVE-2025-70519 | 1 Fanvil | 1 X7a | 2026-10-09 | 6.1 Medium |
| The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows for the injection of HTML which can be used to execute malicious JavaScript code on any target browser which renders the device log component. | ||||
| CVE-2025-70520 | 1 Fanvil | 1 X7a | 2026-10-09 | N/A |
| The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests. | ||||
| CVE-2025-70521 | 1 Fanvil | 1 X7a | 2026-10-09 | 9.8 Critical |
| The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system. | ||||
| CVE-2025-70522 | 1 Fanvil | 1 X7a | 2026-10-09 | 8.8 High |
| The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint. | ||||
| CVE-2026-59346 | 1 Vmware | 2 Vmware Fusion, Vmware Workstation | 2026-10-09 | 9.3 Critical |
| VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1) | ||||
| CVE-2026-59347 | 1 Vmware | 2 Vmware Fusion, Vmware Workstation | 2026-10-09 | 8.1 High |
| VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1) | ||||
| CVE-2026-103323 | 1 Wordpress-extensions | 1 Integration For Epos Now And Woocommerce | 2026-10-09 | 5.9 Medium |
| The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2 does not perform an authorization check on one of its REST endpoints, allowing unauthenticated users to retrieve the site's scheduled background tasks and their arguments, which include order identifiers and, when WooCommerce's deferred emails feature is enabled, the plaintext passwords of newly registered customers. | ||||
| CVE-2026-103378 | 1 Wordpress-extensions | 1 Geliver Aklly Kargo Pazaryeri | 2026-10-09 | 6.5 Medium |
| The Geliver Akıllı Kargo Pazaryeri WordPress plugin before 3.1.1 does not prevent unauthenticated access to a log file it stores within its own web-accessible directory, into which it writes the site's carrier integration key while processing requests from unauthenticated users, allowing attackers to retrieve the key and use it to modify WooCommerce order statuses. The same log file also exposes customer information from orders the shop has processed. | ||||
| CVE-2026-103681 | 1 Wordpress-extensions | 1 Frontend Dashboard | 2026-10-09 | 4.3 Medium |
| The Frontend Dashboard WordPress plugin before 3.0.0 does not perform a capability check in one of its AJAX actions, allowing authenticated users with low privileges, such as subscribers, to delete the Frontend Dashboard WordPress plugin before 3.0.0's configured profile and post form fields. | ||||
| CVE-2026-104049 | 1 Wordpress-extensions | 1 Academy Lms | 2026-10-09 | 4.3 Medium |
| The Academy LMS WordPress plugin before 4.0.0 does not verify course enrollment or object ownership when returning a lesson's content through one of its REST API routes, allowing users with a self-registerable student account to read the full content of arbitrary lessons, including lessons of paid or private courses they are not enrolled in. | ||||