Search

Search Results (400941 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-67075 1 Hcltech 1 Digital Experience 2026-10-01 6.5 Medium
HCL Digital Experience is affected by improper input sanitation.  This can result in HTML injection which could be leveraged in content spoofing from a trusted domain. Apply HCL Digital Experience 9.5 CF238 or later to address this.
CVE-2026-34190 1 Pandora Fms 1 Pandora Fms 2026-10-01 N/A
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands via sequential, unvalidated GET requests when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
CVE-2026-34189 1 Pandora Fms 1 Pandora Fms 2026-10-01 N/A
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
CVE-2026-12855 1 Insyde Software 1 Insydeh2o 2026-10-01 8.2 High
Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.
CVE-2026-103687 1 Rhukster 1 Dom-sanitizer 2026-10-01 7.3 High
A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.16 is sufficient to fix this issue. The name of the patch is 139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a. Upgrading the affected component is recommended.
CVE-2026-103664 1 Misp 1 Misp 2026-10-01 N/A
MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, was passed directly into inline JavaScript within the rendered HTML response without any sanitization or type enforcement. An attacker who can convince an authenticated MISP user to navigate to a crafted URL (for example, via a phishing link) can inject arbitrary JavaScript that executes in the victim's browser context. This may allow the attacker to read session tokens, manipulate the page, or perform actions on behalf of the victim. Preconditions: - The victim must be authenticated to MISP and access the analyst data view for an attribute or object. - The attacker must supply a malicious seed value in the URL path. Impact: - Execution of arbitrary JavaScript in the victim's browser session. - Potential theft of session credentials or sensitive data visible in the page. - Manipulation of the analyst data interface. Affected: MISP versions prior to the fix (commit 58925dbf0, post v2.5.48).
CVE-2026-103662 1 Misp 1 Misp 2026-10-01 N/A
MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag). The affected forms echoed a user-supplied tag name value from the request unescaped into the rendered HTML output. An attacker who can induce a site administrator to visit a crafted URL containing a malicious tag name parameter can execute arbitrary JavaScript in the administrator's browser session. Preconditions: - The target must be running a MISP instance with the legacy taxonomy tag confirmation views enabled. - The victim must be an authenticated site administrator. - The victim must navigate to the attacker-crafted URL (e.g., via a phishing link). Security impact: - Execution of arbitrary client-side script in the context of the administrator's browser. - Potential theft of session tokens, CSRF tokens, or other sensitive data accessible from the page. - Potential for performing privileged actions on behalf of the administrator within the MISP interface. Affected versions: <2.5.48.
CVE-2026-103659 1 Misp 1 Misp 2026-10-01 N/A
MISP contains an authorization bypass in the event flattening feature. When a user requests an event with the flatten option enabled, the application removes the Object containment from the query and returns object attributes as top-level event attributes. In doing so, the object-level distribution and sharing-group access control check was not re-applied to those attributes. As a result, a user who can view a community-distributed event could retrieve attributes belonging to organisation-only objects (distribution level 0) or objects restricted to a specific sharing group, even though the user's organisation does not have access to those objects. This constitutes an unauthorized disclosure of sensitive threat intelligence data. A secondary issue was introduced by the initial remediation: the fix reused the full Object contain conditions (including soft-delete state) as the gate for flattened attributes, causing an event owner requesting deleted attributes to lose all attributes whose parent object was still live. The final fix isolates the distribution ACL condition as the sole gate. Preconditions: - An authenticated user with access to a community-distributed event - The event contains at least one object with a distribution level or sharing group that restricts access beyond the event's own distribution Impact: - Unauthorized disclosure of attributes belonging to restricted objects - Potential exposure of organisation-specific threat intelligence to other organisations Affected versions: <2.5.48
CVE-2026-103655 1 Misp 1 Misp 2026-10-01 N/A
MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system did not record whether a given TOTP period had already been consumed, the same code remained valid for its entire time window (typically 30 seconds). An attacker who captures a legitimate code during a user's login could replay it to authenticate a second session as that user. Preconditions: - The target user has TOTP-based two-factor authentication enabled. - The attacker is in a position to observe or intercept the TOTP code during a legitimate login (e.g., network-level interception, shoulder surfing, or a compromised client). - The replay must occur within the TOTP validity period. Security impact: - Unauthorized account access by replaying a captured one-time code. - Potential compromise of threat-intelligence data and administrative functions accessible to the targeted user. Affected versions: <v2.5.48.
CVE-2026-103587 1 Webkul 1 Qloapps 2026-10-01 5.4 Medium
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a malicious link containing JavaScript payload in these parameters that executes in an authenticated administrator's session when the victim follows the link.
CVE-2026-103585 1 Wikimedia 1 Mediawiki-mediasearch Extension 2026-10-01 N/A
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki MediaSearch extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki MediaSearch extension: 1.46, 1.45, and 1.43.
CVE-2026-103584 1 Wikimedia 1 Mediawiki-commonsmetadata Extension 2026-10-01 N/A
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki CommonsMetadata extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki CommonsMetadata extension: 1.46, 1.45, and 1.43.
CVE-2026-103493 1 Jetbrains 1 Youtrack 2026-10-01 8.1 High
In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
CVE-2026-16313 1 Redhat 10 Enterprise Linux, Enterprise Linux Eus, Openshift and 7 more 2026-10-01 7.6 High
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.
CVE-2026-103476 1 Yii2-starter-kit 1 Yii2-starter-kit 2026-10-01 5.3 Medium
yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate sequential attachment identifiers to retrieve files from unpublished articles without authentication or authorization checks.
CVE-2026-103431 2026-10-01 7.7 High
colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored host to inject escape sequences into the terminal of an operator running colmux, via a crafted process name (argv[0]).
CVE-2026-103286 1 Ghost 1 Ghost 2026-10-01 7.3 High
Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows low-privilege staff users to escalate to higher-privilege staff roles. Attackers with low-privilege staff access can exploit the notifications system to gain elevated privileges without proper authorization checks.
CVE-2026-103253 1 N8n 1 N8n 2026-10-01 8.7 High
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an SQL injection vulnerability in the Oracle Database node's Delete Table Drop operation. Attackers can inject single quotes in the table or schema fields to append arbitrary SQL statements and execute DDL or DML commands against the connected database with the credential's privileges.
CVE-2026-103113 1 Os4ed 1 Opensis-classic 2026-10-01 4.7 Medium
A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/students/Student.php of the component General Information Tab. Executing a manipulation of the argument students can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-102805 1 Nothings 1 Stb 2026-10-01 6.5 Medium
A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead to integer overflow. The attack can be executed remotely. The exploit has been published and may be used.