Export limit exceeded: 390878 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (390878 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-89177 | 1 Howyar | 1 Weenygenius | 2026-09-13 | 8.8 High |
| WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with forged commands to disrupt classroom operations. | ||||
| CVE-2026-89178 | 1 Howyar | 1 Weenygenius | 2026-09-13 | 8.8 High |
| WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student computers to attempt to establish a connection with the attacker. | ||||
| CVE-2026-89179 | 1 Howyar | 1 Weenygenius | 2026-09-13 | 4.3 Medium |
| WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability. Unauthenticated attackers on the same network can intercept a student's connection packet and replay it, thereby forging the appearance that the student remains connected. | ||||
| CVE-2025-15679 | 1 Bull | 2 Bullsequana Xh3406, Bullsequana Xh3515 | 2026-09-13 | N/A |
| Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515. | ||||
| CVE-2026-19486 | 1 Google Cloud | 1 Gemini Enterprise Agent Platform App Builder | 2026-09-13 | N/A |
| A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users will need to redeploy their previously deployed apps. | ||||
| CVE-2026-80469 | 1 Sick Ag | 1 Sentio Creator Extension 'device Manager' | 2026-09-13 | 8.3 High |
| An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-controlled code. User interaction is required. | ||||
| CVE-2026-77159 | 1 Redhat | 2 Enterprise Linux, Libvirt | 2026-09-13 | 5.5 Medium |
| A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can replace the logfile with a symlink, causing libvirtd (running as root) to transfer ownership of an arbitrary file to the swtpm user. | ||||
| CVE-2026-89146 | 1 Libp2p | 1 Libp2p-rendezvous | 2026-09-13 | 7.5 High |
| libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL value that causes the client node process to panic when computing the expiry timer. | ||||
| CVE-2026-87776 | 1 Expressjs | 1 Compression | 2026-09-13 | 7.5 High |
| compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never destroyed, so each aborted compressed response leaks its native zlib memory. A remote unauthenticated attacker can repeatedly open requests and disconnect early, exhausting the available memory and crashing the server. All applications using compression are affected. The issue is fixed in compression 1.8.2, and users should upgrade to 1.8.2 or later. | ||||
| CVE-2026-80462 | 1 Progress Software | 1 Chef Automate | 2026-09-13 | 10 Critical |
| A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions. | ||||
| CVE-2026-89298 | 1 Redhat | 3 Build Keycloak, Build Of Keycloak, Red Hat Single Sign On | 2026-09-13 | 4.9 Medium |
| A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution. The issue occurs when a user with the view-clients role accesses the client registration endpoint to retrieve client details. Due to a failure to mask sensitive information, the service returns the client's confidential secret in cleartext. This could allow a read-only administrator to obtain full access to the affected client's account and potentially escalate their privileges within the realm. | ||||
| CVE-2026-15710 | 1 Netskope | 1 Endpoint Dlp | 2026-09-13 | N/A |
| An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141. An internal communication channel used by the user-space hook DLL to pass messages through the kernel driver to the daemon lacked proper token-based message validation, allowing local unprivileged processes to send unauthorized queries. Additionally, a reply buffer used by the port message handler was not properly initialized before returning data, leaking residual kernel pool memory from prior allocations. A local unprivileged attacker could exploit this vulnerability to enumerate DLP configuration and feature flags, extract live session tokens, and read kernel memory fragments from other users' operations. | ||||
| CVE-2026-82583 | 1 Nextgen Healthcare | 1 Mirth Connect | 2026-09-13 | 8.3 High |
| NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and a denial-of-service condition. | ||||
| CVE-2026-78224 | 1 Nextgen Healthcare | 1 Mirth Connect | 2026-09-13 | 8.2 High |
| The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks. | ||||
| CVE-2026-82578 | 1 Nextgen Healthcare | 1 Mirth Connect | 2026-09-13 | 7.5 High |
| When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks. | ||||
| CVE-2026-85979 | 1 Perforce Software | 1 Puppet Enterprise | 2026-09-13 | N/A |
| Affected versions of Puppet Enterprise contain a command injection vulnerability in the handling of the java_keystore_passwd parameter. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, which is passed to a shell execution context without sufficient sanitization. Because the resulting commands are executed with root privileges, successful exploitation can lead to full compromise of the affected system. | ||||
| CVE-2026-38058 | 1 St Engineering Idirect | 3 3315-series Terminals, 9-series Terminals, Evolution Iq‑series Terminals | 2026-09-13 | 8.1 High |
| The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware. | ||||
| CVE-2026-38056 | 1 St Engineering Idirect | 3 3315-series Terminals, 9-series Terminals, Evolution Iq‑series Terminals | 2026-09-13 | 8.8 High |
| A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured low-privilege local user account. This account is intended for field technicians who need shell access for maintenance and diagnostics but should not have full administrative control over the device. This built-in account provides the initial access required to exploit this vulnerability. No additional credentials need to be obtained or brute-forced. | ||||
| CVE-2026-85083 | 1 Carecam | 1 Anjia Ajl33pc0801 Firmware | 2026-09-13 | 6.8 Medium |
| The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise. | ||||
| CVE-2026-89009 | 1 Wavlink | 2 Wn535m1, Wn535m3 | 2026-09-13 | 9.1 Critical |
| WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to the sync_server daemon on TCP port 13136. The daemon, which runs as root and requires no authentication, accepts a 100-byte filename field in its protocol header without path canonicalization, allowing attackers to supply an absolute path and write arbitrary content to overwrite startup scripts or credential stores to achieve persistent system compromise. | ||||