Export limit exceeded: 393724 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (393724 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-75051 | 1 Jetbrains | 1 Youtrack | 2026-09-15 | 8.1 High |
| In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible | ||||
| CVE-2026-75092 | 1 Redhat | 3 Enterprise Linux, Openstack, Rhel Eus | 2026-09-15 | 7.3 High |
| A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that normally starts the daemon as User=mysql. A process compromised as the mysql OS identity can write a version-2 persisted configuration (mysqld-auto.cnf) and a malicious shared object into /var/lib/mysql (a directory owned by mysql). That persisted map can set plugin_dir to /var/lib/mysql and early_plugin_load (or related loader options such as plugin_load / plugin_load_add) so MySQL loads the attacker-controlled object during configuration validation. Plugin loading can reach dlopen() before MySQL’s runtime-user check and before plugin-symbol validation. When an administrator subsequently runs the documented Leapp preupgrade or upgrade workflow, attacker-controlled code can execute as UID 0 with a full capability set in an unconfined SELinux domain (unconfined_t). The attack does not require write access to the default system plugin path under /usr; redirecting plugin_dir via mysql-owned persisted state is sufficient. Ordinary SQL privileges alone (including highly privileged SQL accounts) are not a sufficient startpoint — OS-level execution as the mysql service identity is required, plus later administrator invocation of Leapp. | ||||
| CVE-2026-73028 | 1 Microsoft | 12 Microsoft Sql Server 2017 (cu 31), Microsoft Sql Server 2017 (gdr), Microsoft Sql Server 2019 (cu 32) and 9 more | 2026-09-15 | 8.8 High |
| Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-77480 | 1 Microsoft | 11 Microsoft Sql Server 2017 (cu 31), Microsoft Sql Server 2017 (gdr), Microsoft Sql Server 2019 (cu 32) and 8 more | 2026-09-15 | 8.8 High |
| Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-77482 | 1 Microsoft | 6 Microsoft Sql Server 2017 (cu 31), Microsoft Sql Server 2017 (gdr), Microsoft Sql Server 2019 (cu 32) and 3 more | 2026-09-15 | 8.8 High |
| Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-87013 | 2 Open-webui, Openwebui | 2 Open-webui, Open Webui | 2026-09-15 | 4.3 Medium |
| Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/v1/folders/{id}/update/parent allowed a user to place a folder under itself or one of its descendants, while the folder tree walks used by DELETE /api/v1/folders/{id} and POST /api/v1/folders/{id}/read did not track visited folder identifiers. An authenticated user could persist a parent cycle and start a request that consumed CPU and memory indefinitely, with the condition remaining stored until repaired. This issue is fixed in version 0.11.1. | ||||
| CVE-2026-77483 | 1 Microsoft | 11 Microsoft Sql Server 2017 (cu 31), Microsoft Sql Server 2017 (gdr), Microsoft Sql Server 2019 (cu 32) and 8 more | 2026-09-15 | 8.8 High |
| Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-77485 | 1 Microsoft | 5 Microsoft Sql Server 2025 For X64-based Systems (gdr), Sql Server 2017, Sql Server 2019 and 2 more | 2026-09-15 | 7 High |
| Use after free in SQL Server allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2023-29377 | 1 Softing | 1 Secure Integration Server | 2026-09-15 | 6.6 Medium |
| An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA objects and a file path to File OPC UA objects. | ||||
| CVE-2023-24284 | 2026-09-15 | 2.9 Low | ||
| Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function. | ||||
| CVE-2023-24286 | 2026-09-15 | 2.9 Low | ||
| Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter. | ||||
| CVE-2023-24034 | 1 Nagios | 2 Nagios Xi, Xi | 2026-09-15 | 3.1 Low |
| An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a malicious site by using a open redirect vulnerability. | ||||
| CVE-2026-33964 | 1 Samsung | 1 Exynos 1580 Firmware | 2026-09-15 | 6.4 Medium |
| An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent to the camera driver, causing limited information disclosure or denial of service. | ||||
| CVE-2026-33967 | 1 Samsung | 1 Exynos 1330 Firmware | 2026-09-15 | 2.8 Low |
| An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, an out-of-bounds array access vulnerability in the error-handling path leads to memory corruption. | ||||
| CVE-2026-23787 | 1 Samsung | 1 Exynos 1280 Firmware | 2026-09-15 | 4.2 Medium |
| An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A Use-After-Free in the Exynos DRM HDR driver (due to improper cleanup upon vmap failure) leads to a kernel crash. | ||||
| CVE-2026-23792 | 1 Samsung | 1 Exynos 1080 Firmware | 2026-09-15 | 4 Medium |
| An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000, Modem 5300, Modem 5400, and Modem 5410. Incorrect handling of unauthenticated downlink RRC Setup messages can cause the baseband to crash. | ||||
| CVE-2026-23790 | 1 Samsung | 1 Exynos 1280 Firmware | 2026-09-15 | 4.2 Medium |
| An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory corruption and a potential use-after-free. | ||||
| CVE-2026-23788 | 1 Samsung | 1 Exynos 1280 Firmware | 2026-09-15 | 4.2 Medium |
| An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due to improper buffer size validation) leads to kernel memory corruption and a system crash. | ||||
| CVE-2026-23793 | 1 Samsung | 1 Exynos 1330 Firmware | 2026-09-15 | 3.5 Low |
| An issue was discovered in Samsung Mobile Processor Exynos 1330, 1380, 1480, and 2400. An out-of-bounds memory access vulnerability in the camera GDC driver may lead to kernel memory corruption under certain conditions. | ||||
| CVE-2026-33956 | 1 Samsung | 1 Exynos 1330 Firmware | 2026-09-15 | 2.8 Low |
| An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Sending a malformed message to the test_msg sysfs entry causes an out-of-bounds write, leading to denial of service. | ||||