Search

Search Results (400208 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-51867 2026-09-30 N/A
agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.
CVE-2026-51869 2026-09-30 N/A
DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host.
CVE-2026-51870 2026-09-30 N/A
DeepTutor v1.4.0 is vulnerable to command execution in /tutorbot/agent/tools/shell.py:ExecTool.execute.
CVE-2026-47551 1 Nvidia 5 Geforce, Guest Driver, Rtx, Quadro, Nvs and 2 more 2026-09-30 7.8 High
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
CVE-2026-103592 2026-09-30 6.5 Medium
simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted addresses or evade blacklists, gaining access to IP-restricted routes.
CVE-2026-103591 2026-09-30 7.5 High
DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment checks and read any file accessible to the API process by specifying absolute file paths.
CVE-2026-103590 1 Webkul 1 Qloapps 2026-09-30 5.4 Medium
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payloads in restriction_min_los and restriction_max_los parameters, executing arbitrary JavaScript in the victim's administrative session.
CVE-2026-103589 1 Webkul 1 Qloapps 2026-09-30 5.4 Medium
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users to submit crafted POST requests with malicious payloads to execute arbitrary JavaScript in the victim's administrative session.
CVE-2026-103588 1 Webkul 1 Qloapps 2026-09-30 5.4 Medium
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that executes in an authenticated administrator's session when the victim follows the link.
CVE-2026-103587 1 Webkul 1 Qloapps 2026-09-30 5.4 Medium
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a malicious link containing JavaScript payload in these parameters that executes in an authenticated administrator's session when the victim follows the link.
CVE-2026-51871 2026-09-30 N/A
Devika v1.0 is vulnerable to Code Injection in the Runner.execute function in src/agents/runner/runner.py which allows an attacker to achieve arbitrary code execution by exploiting the direct execution of LLM-generated content.
CVE-2026-51872 2026-09-30 N/A
Devika v1.0 is vulnerable to Code Injection via the Runner.run_code function in src/agents/runner/runner.py.
CVE-2026-91072 2026-09-30 4.4 Medium
The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an attacker with Administrator-level access rename or delete existing WebP-derivative image files outside that scope, including, on a multisite network, files belonging to a different site they have no access to.
CVE-2026-102996 2026-09-30 7.5 High
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and consume excessive memory during operations such as text extraction. This issue is fixed in version 6.18.1.
CVE-2026-101276 2026-09-30 N/A
iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22.
CVE-2026-103001 2026-09-30 6.5 Medium
PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or decode_complete() call and changes verify_signature to true, the mapping can retain false values for expiration, not-before, issued-at, audience, issuer, subject, and JWT ID checks. A signed token with invalid registered claims can then be accepted without disabling signature verification, but applications that create a fresh options mapping for each call are not affected.
CVE-2026-101283 2026-09-30 N/A
iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22
CVE-2026-47592 1 Nvidia 8 Geforce, Guest Driver, Nvs and 5 more 2026-09-30 7.8 High
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
CVE-2026-47593 1 Nvidia 6 Geforce, Guest Driver, Nvs and 3 more 2026-09-30 7.8 High
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unprivileged user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and denial of service.
CVE-2026-47599 1 Nvidia 5 Geforce, Nvs, Quadro and 2 more 2026-09-30 7.8 High
NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module where an unprivileged local user could cause improper preservation of memory access permissions during DMA mapping. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.