Export limit exceeded: 400204 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400204 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400204 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-100242 | 2026-09-29 | N/A | ||
| Dependency on Vulnerable Third-Party Component and Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - DataTransfer Extension allows Excessive Allocation. This issue affects Mediawiki - DataTransfer Extension: from 1.46.0 before 1.47.0. | ||||
| CVE-2026-88023 | 1 Mongodb | 1 Php Library | 2026-09-29 | 8.3 High |
| Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Library can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. The affected rename operation may also rename a stored file other than the intended target. | ||||
| CVE-2026-88024 | 1 Mongodb | 2 Rust-driver, Rust Driver | 2026-09-29 | 8.3 High |
| Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. | ||||
| CVE-2026-101139 | 1 Webkul | 1 Bagisto | 2026-09-29 | 2.7 Low |
| A vulnerability was detected in Webkul Bagisto up to 2.4.6/2.5.0-beta4. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.5.0-beta5 will fix this issue. The patch is named 2c34b94d0313824ce98efee8aef8ee141d9b89d0. It is recommended to apply a patch to fix this issue. The vendor confirms: "[W]e run continuous automated AI-assisted security scanning across the Bagisto codebase. The behaviour you describe has already been identified and reproduced internally, and it is actively being fixed rather than triaged from scratch." | ||||
| CVE-2026-56198 | 1 Microsoft | 8 Windows 11 24h2, Windows 11 24h2, Windows 11 25h2 and 5 more | 2026-09-29 | 7.8 High |
| Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-62762 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-29 | 6.5 Medium |
| Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. | ||||
| CVE-2026-68828 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-29 | 8.8 High |
| Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-68850 | 1 Microsoft | 6 Windows 11 24h2, Windows 11 24h2, Windows 11 25h2 and 3 more | 2026-09-29 | 7.8 High |
| Heap-based buffer overflow in Microsoft Account allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-68852 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-29 | 5.5 Medium |
| Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-88025 | 1 Mongodb | 2 C# Driver, C\# Driver | 2026-09-29 | 8.3 High |
| Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. The affected rename operation may also rename a stored file other than the intended target. | ||||
| CVE-2026-96419 | 1 Wireshark | 1 Wireshark | 2026-09-29 | 5.5 Medium |
| Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service and possible code execution | ||||
| CVE-2026-96416 | 1 Wireshark | 1 Wireshark | 2026-09-29 | 5.5 Medium |
| IEEE 802.11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-96415 | 1 Wireshark | 1 Wireshark | 2026-09-29 | 5.5 Medium |
| Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-95393 | 1 Wireshark | 1 Wireshark | 2026-09-29 | 4.7 Medium |
| CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-95388 | 1 Wireshark | 1 Wireshark | 2026-09-29 | 5.5 Medium |
| Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-95386 | 1 Wireshark | 1 Wireshark | 2026-09-29 | 5.5 Medium |
| TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of service | ||||
| CVE-2026-91006 | 1 Apache | 1 Karaf | 2026-09-29 | 8.8 High |
| Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (;, |, `, $(...)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user. Reachable via the shell commands instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance). Mitigation * Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes. * Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments. * Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators. | ||||
| CVE-2026-88777 | 1 Citrix | 3 Netscaler Adc, Netscaler Application Delivery Controller, Netscaler Gateway | 2026-09-29 | 9.8 Critical |
| Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior or Denial of Service | ||||
| CVE-2026-88775 | 1 Citrix | 3 Netscaler Adc, Netscaler Application Delivery Controller, Netscaler Gateway | 2026-09-29 | 9.8 Critical |
| Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service | ||||
| CVE-2026-88773 | 1 Citrix | 3 Netscaler Adc, Netscaler Application Delivery Controller, Netscaler Gateway | 2026-09-29 | 10.0 Critical |
| Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23. | ||||