Export limit exceeded: 27290 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (27290 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-70590 | 1 Ghost | 1 Ghost | 2026-08-05 | 4.8 Medium |
| Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead to account takeover if successful, but Device Verification should have prevented an attacker from logging in with a recovered password. Depending on the database used, leaked hashes may not have had the correct casing for all characters, increasing the difficulty of a password-guessing attack. This issue is fixed in version 6.54.1. | ||||
| CVE-2026-46334 | 1 Opensips | 1 Opensips | 2026-08-05 | N/A |
| OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the SDP bandwidth-line parsing logic. A SIP request with Content-Type: application/sdp and a malformed session-level SDP bandwidth line missing the required colon delimiter can corrupt parsed SDP bandwidth metadata. When a route or module subsequently clones the corrupted SDP state, as occurs with dialog and QoS processing, the OpenSIPS worker process crashes. An unauthenticated remote attacker can therefore trigger a crash in any configuration whose routing script parses attacker-controlled SDP and applies dialog/QoS processing. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1. | ||||
| CVE-2026-70589 | 1 Ghost | 1 Ghost | 2026-08-05 | 4.8 Medium |
| Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1. | ||||
| CVE-2026-61891 | 1 Eclipse | 1 Theia | 2026-08-05 | 7.5 High |
| In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to the workspace or any allow-listed root. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests, so these endpoints are reachable without a valid token. As a result an unauthenticated client can read any file readable by the backend process, including files outside the opened workspace (for example `/etc/hosts`, SSH keys, or tokens). Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path. | ||||
| CVE-2026-16993 | 2026-08-05 | 3.7 Low | ||
| The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an Apache .htaccess file, so on a web server that does not honor .htaccess (such as nginx) an unauthenticated visitor can download stored shipping labels (each containing a customer's name and postal address) by requesting predictable filenames. | ||||
| CVE-2026-55998 | 1 Suse | 1 Rancher | 2026-08-05 | 5.3 Medium |
| The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, a nil pointer dereference in pkg/systemtemplate/private_registry.go causes the request to return HTTP 502 Bad Gateway. For cluster IDs that do not exist, the endpoint returns HTTP 200. This observable difference in response codes constitutes a reliable enumeration oracle. | ||||
| CVE-2026-21548 | 1 Unisoc | 4 T8100, T8200, T8300 and 1 more | 2026-08-05 | 7.5 High |
| In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed. | ||||
| CVE-2026-21549 | 1 Unisoc | 4 T8100, T8200, T8300 and 1 more | 2026-08-05 | 7.5 High |
| In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | ||||
| CVE-2026-21550 | 1 Unisoc | 4 T8100, T8200, T8300 and 1 more | 2026-08-05 | 7.5 High |
| In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | ||||
| CVE-2026-21551 | 1 Unisoc | 4 T8100, T8200, T8300 and 1 more | 2026-08-05 | 7.5 High |
| In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | ||||
| CVE-2026-21552 | 1 Unisoc | 4 T8100, T8200, T8300 and 1 more | 2026-08-05 | 7.5 High |
| In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | ||||
| CVE-2026-21553 | 1 Unisoc | 4 T8100, T8200, T8300 and 1 more | 2026-08-05 | 7.5 High |
| In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | ||||
| CVE-2026-21554 | 1 Unisoc | 1 Udx710 | 2026-08-05 | 7.5 High |
| In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | ||||
| CVE-2026-21555 | 1 Unisoc | 1 Udx710 | 2026-08-05 | 7.5 High |
| In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | ||||
| CVE-2026-25703 | 1 Suse | 1 Neuvector | 2026-08-05 | 7.3 High |
| NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information. | ||||
| CVE-2026-62658 | 1 Netgear | 5 Rax43, Rax45, Rax50 and 2 more | 2026-08-05 | N/A |
| A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged in to the device to run unauthorized commands or code on the router. | ||||
| CVE-2026-62659 | 1 Netgear | 1 Wax333 | 2026-08-05 | N/A |
| A security flaw was discovered in the NETGEAR WAX333 Access Point that could allow someone already logged in and connected to the local network to make unauthorized changes to the device's settings | ||||
| CVE-2026-11835 | 1 Caliptra | 1 Core Rom | 2026-08-05 | N/A |
| Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mode allows a compromised local attacker to silently bypass secure boot by supplying an AXI staging address that is not validated against the strap-configured SS_EXTERNAL_STAGING_AREA_BASE_ADDR, enabling firmware to be modified between verification and loading into ICCM. Attestation continues to report the originally verified image digest, masking the compromise. Exploitation requires a compromised MCU firmware with AXI manager access to unprotected SRAM reachable by Caliptra. This issue affects Core ROM: 2.1.0 through 2.1.1. | ||||
| CVE-2026-14202 | 1 Bilin Software And Informatics Consultancy Inc. | 1 Humanist Digital Human Resources | 2026-08-05 | 5.3 Medium |
| Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | ||||
| CVE-2026-60007 | 1 Eclipse | 2 Eclipse Milo, Milo | 2026-08-05 | 7.4 High |
| In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession` requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials. | ||||