Search

Search Results (395686 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-66575 2026-09-17 5.3 Medium
Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.
CVE-2024-58384 1 Tornadoweb 1 Tornado 2026-09-17 5.4 Medium
Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.
CVE-2026-91924 1 Sosedoff 1 Pgweb 2026-09-17 8.5 High
pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, allowing attackers to supply arbitrary database connection strings. Attackers can bypass the resource-to-database mapping by providing a custom session identifier and connection URL to access unauthorized databases and internal services.
CVE-2026-91925 1 Polyaxon 1 Polyaxon 2026-09-17 8.8 High
Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code. Attackers can submit runs with Jinja2 payloads in queue, namespace, conditions, presets, or dependencies fields to execute operating system commands in the scheduler process context, exposing database credentials and service tokens.
CVE-2026-91997 2 Cs-technologies, Evolution-foundation 2 Evolution, Evolution-api 2026-09-17 5.3 Medium
evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restrictions to access sensitive metrics disclosing server version, database client name, configured server URL, and WhatsApp instance details.
CVE-2026-92031 1 Mozilla 1 Firefox 2026-09-17 6.1 Medium
Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
CVE-2026-92032 1 Mozilla 1 Firefox 2026-09-17 6.1 Medium
Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
CVE-2026-92033 1 Mozilla 1 Firefox 2026-09-17 8.8 High
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
CVE-2026-92034 1 Mozilla 1 Firefox 2026-09-17 7.5 High
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
CVE-2026-92035 1 Mozilla 1 Firefox 2026-09-17 7.5 High
Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-92036 1 Mozilla 1 Firefox 2026-09-17 7.5 High
Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
CVE-2026-92037 1 Mozilla 1 Firefox 2026-09-17 7.5 High
Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
CVE-2026-92038 1 Mozilla 1 Firefox 2026-09-17 7.5 High
Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-92039 1 Mozilla 1 Firefox 2026-09-17 6.1 Medium
Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
CVE-2026-25282 1 Qualcomm 1 Snapdragon 2026-09-17 7.9 High
Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
CVE-2026-66578 2 Propertyhive, Wordpress 2 Propertyhive, Wordpress 2026-09-17 6.5 Medium
Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.
CVE-2026-66608 2 Unlimited-elements, Wordpress 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Wordpress 2026-09-17 6.4 Medium
Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.
CVE-2026-72987 1 Microsoft 14 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 11 more 2026-09-17 8.1 High
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-72979 1 Microsoft 14 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 11 more 2026-09-17 9.8 Critical
Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-72967 1 Microsoft 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more 2026-09-17 7.8 High
Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.