Export limit exceeded: 48747 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 386138 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 386138 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (386138 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66381 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 5.3 Medium |
| A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions. | ||||
| CVE-2026-66382 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 4.3 Medium |
| An authenticated user may write files outside the intended Artifactory work directory under specific conditions. | ||||
| CVE-2026-68760 | 1 Jfrog | 1 Artifactory | 2026-09-02 | 5.3 Medium |
| An unauthenticated user may bypass authentication under specific cache conditions. | ||||
| CVE-2026-84857 | 1 Sigoden | 1 Aichat | 2026-09-02 | 5.3 Medium |
| A flaw has been found in sigoden aichat up to 0.30.4. This affects an unknown function of the file src/serve.rs of the component API Endpoint. This manipulation causes uncontrolled memory allocation. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2023-20577 | 2026-09-02 | 7.4 High | ||
| A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution. | ||||
| CVE-2026-76221 | 1 Gitpython Project | 1 Gitpython | 2026-09-02 | 8.8 High |
| GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via core.sshCommand or core.hooksPath on the next git operation. | ||||
| CVE-2023-20576 | 2026-09-02 | 7.7 High | ||
| Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation. | ||||
| CVE-2026-76222 | 2 Gitpython-developers, Gitpython Project | 2 Gitpython, Gitpython | 2026-09-02 | 8.2 High |
| GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule names that GitPython processes during submodule initialization, creating attacker-controlled Git repositories at escaped filesystem locations. | ||||
| CVE-2026-78675 | 1 Gitpython Project | 1 Gitpython | 2026-09-02 | 8.4 High |
| GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message. | ||||
| CVE-2026-84840 | 1 Tsi-coop | 1 Tsi-dpdp-cms | 2026-09-02 | 6.5 Medium |
| A vulnerability was identified in tsi-coop tsi-dpdp-cms up to 0.5.0. This affects an unknown part of the file InterceptingFilter.java of the component Bootstrap Setup Endpoint. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used. Upgrading to version 0.5.1 is able to mitigate this issue. Upgrading the affected component is recommended. | ||||
| CVE-2026-84641 | 1 Mozilla | 1 Thunderbird | 2026-09-02 | 7.5 High |
| A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | ||||
| CVE-2026-84640 | 1 Mozilla | 1 Thunderbird | 2026-09-02 | 7.5 High |
| A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | ||||
| CVE-2026-84639 | 1 Mozilla | 1 Thunderbird | 2026-09-02 | 9.1 Critical |
| Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | ||||
| CVE-2026-84357 | 1 Google | 1 Chrome | 2026-09-02 | 6.5 Medium |
| Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: High) | ||||
| CVE-2026-84356 | 1 Google | 1 Chrome | 2026-09-02 | 4.3 Medium |
| UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-82641 | 1 Keploy | 1 Keploy | 2026-09-02 | 8.6 High |
| Keploy versions 3.1.0 through 3.6.25, fixed in 3.6.26, bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retrieve NSS keylog lines and decrypt recorded TLS traffic, or invoke /agent/stop and /agent/storemocks to manipulate recording sessions. | ||||
| CVE-2026-81269 | 1 Drupal | 1 Data Field | 2026-09-02 | 5.3 Medium |
| Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13. | ||||
| CVE-2026-81168 | 1 Drupal | 1 Captcha Protected Page | 2026-09-02 | 3.7 Low |
| Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2. | ||||
| CVE-2026-81166 | 1 Drupal | 1 Digital Signage Framework | 2026-09-02 | 5.3 Medium |
| Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1. | ||||
| CVE-2026-81165 | 1 Drupal | 1 Blazy | 2026-09-02 | 5.3 Medium |
| Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18. | ||||