Export limit exceeded: 396675 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 396675 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (396675 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65126 | 1 Nvidia | 1 Infrastructure Controller | 2026-09-22 | 5 Medium |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-65128 | 1 Nvidia | 1 Infrastructure Controller | 2026-09-22 | 8.8 High |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-65129 | 1 Nvidia | 1 Infrastructure Controller | 2026-09-22 | 6.7 Medium |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service. | ||||
| CVE-2026-65112 | 1 Nvidia | 1 Infrastructure Controller | 2026-09-22 | 6.5 Medium |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. | ||||
| CVE-2026-65111 | 1 Nvidia | 1 Nemo Speech | 2026-09-22 | 7.8 High |
| NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. | ||||
| CVE-2026-65113 | 1 Nvidia | 1 Infrastructure Controller | 2026-09-22 | 9.8 Critical |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-65121 | 1 Nvidia | 1 Infrastructure Controller | 2026-09-22 | 8.2 High |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering. | ||||
| CVE-2026-65125 | 1 Nvidia | 1 Infrastructure Controller | 2026-09-22 | 6.6 Medium |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service. | ||||
| CVE-2026-65130 | 1 Nvidia | 1 Infrastructure Controller | 2026-09-22 | 8 High |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-65179 | 1 Nvidia | 1 Nemo Speech | 2026-09-22 | 8.8 High |
| NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation. A successful exploit of this vulnerability may lead to code execution, data tampering, denial of service, and information disclosure. | ||||
| CVE-2026-65124 | 1 Nvidia | 1 Infrastructure Controller | 2026-09-22 | 5.9 Medium |
| NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to data tampering and denial of service. | ||||
| CVE-2026-25275 | 1 Qualcomm | 753 5g Fixed Wireless Access Platform, 5g Fixed Wireless Access Platform Firmware, Aqt1000 and 750 more | 2026-09-22 | 7.5 High |
| Transient DOS when processing authentication frames with invalid FILS information element header lengths. | ||||
| CVE-2026-24075 | 1 Qualcomm | 87 Aqt1000, Aqt1000 Firmware, Cologne and 84 more | 2026-09-22 | 7.8 High |
| Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions. | ||||
| CVE-2026-95623 | 1 Tauri | 1 Tauri-plugin-http | 2026-09-22 | 5.6 Medium |
| The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request. When the remote server responds with an HTTP 3xx redirect, reqwest follows the redirect internally without re-checking the new target URL against the scope. This allows an attacker who controls an allowed URL (or finds an open redirect on an allowed host) to reach disallowed destinations such as cloud metadata endpoints, localhost services, or internal network hosts. | ||||
| CVE-2025-59607 | 1 Qualcomm | 29 Cologne, Cologne Firmware, Fastconnect 6900 and 26 more | 2026-09-22 | 7.8 High |
| Memory Corruption when copying large input data exceeds normal allocation limits. | ||||
| CVE-2026-75595 | 1 Netty | 1 Netty | 2026-09-22 | 9.1 Critical |
| Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHello whose handshake header spans records can cause an IndexOutOfBoundsException and invoke select(ctx, null). This selects the default SslContext instead of the SNI-specific context. In deployments where per-SNI clientAuth=REQUIRE is the sole mutual TLS gate, the default SslContext uses clientAuth=NONE or clientAuth=OPTIONAL, and no application-layer certificate verification exists, an unauthenticated remote attacker can bypass the protected route's mutual TLS requirement. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final. | ||||
| CVE-2026-24073 | 1 Qualcomm | 29 Cologne, Cologne Firmware, Fastconnect 6900 and 26 more | 2026-09-22 | 7.8 High |
| Memory corruption when processing decode statistics due to insufficient validation of offset against structure size. | ||||
| CVE-2026-24074 | 1 Qualcomm | 51 Cologne, Cologne Firmware, Fastconnect 6200 and 48 more | 2026-09-22 | 7.8 High |
| Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations. | ||||
| CVE-2025-56565 | 2026-09-22 | 7.6 High | ||
| DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within non-volatile memory. The exposed material includes SSH private keys, dynamic DNS passwords, email notification credentials and administrative passwords. An attacker with physical access to the device can extract these credentials from an SPI flash dump, leading to device compromise, infiltration of the connected network and unauthorised access to dependent third-party services. | ||||
| CVE-2026-38999 | 2026-09-22 | 7.5 High | ||
| A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk_scheduler.c) of Monkey through commit 4fb0c16 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. | ||||