Search Results (91169 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-71453 1 Johnson Controls 1 Easyio Fs32 2026-10-02 N/A
- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63.
CVE-2026-103097 2 Geovision, Geovision Inc. 2 Gv-eye, Gv-eye 2026-10-02 7.5 High
An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
CVE-2026-103096 2 Geovision, Geovision Inc. 2 Gv-eye, Gv-eye 2026-10-02 7.5 High
API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
CVE-2026-63133 1 Cisagov 1 Malcolm 2026-10-02 6.5 Medium
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count, directory depth, total entries, or output size. A small malicious archive containing a large number of directory or file entries causes the filebeat processing container to create an unbounded number of filesystem objects, exhausting inodes or filesystem metadata and denying service to the processing pipeline and any service sharing the same mount. Version 26.07.0 fixes the issue.
CVE-2026-95275 1 Google 1 Chrome 2026-10-02 6.5 Medium
Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-97062 1 Webkul 1 Aureus Erp 2026-10-02 5.4 Medium
Aureus ERP through 1.6.0, fixed in commit 53ad76d, stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft SVG files with script elements that execute in the application's origin when the file URL is opened directly, enabling session cookie theft and CSRF token exfiltration.
CVE-2026-97286 2026-10-02 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Strong Testimonials strong-testimonials allows Stored XSS.This issue affects Strong Testimonials: from n/a through 3.3.11.
CVE-2026-63996 1 Linux 1 Linux Kernel 2026-10-02 7.8 High
In the Linux kernel, the following vulnerability has been resolved: ethtool: cmis: require exact CDB reply length Malicious SFP module could respond with rpl_len longer than what cmis_cdb_process_reply() expected, leading to OOB writes. Malicious HW is a bit theoretical but some modules may just be buggy and/or the reads may occasionally get corrupted, so let's protect the kernel. The existing check protects from short replies. We need to protect from long ones, too. All callers that pass a non-zero rpl_exp_len cast the reply payload to a fixed-layout struct and read fields at fixed offsets, with no version negotiation or short-reply handling: - cmis_cdb_validate_password() - cmis_cdb_module_features_get() - cmis_fw_update_fw_mng_features_get() so let's assume that responses longer than expected do not have to be handled gracefully here. Add a warning message to make the debug easier in case my understanding is wrong... Note that page_data->length (argument of kmalloc) comes from last arg to ethtool_cmis_page_init() which is rpl_exp_len. Note2 that AIs also like to point out overflows in args->req.payload itself (which is a fixed-size 120 B buffer, on the stack), but callers should be reading structs defined by the standard, so protecting from requests for more data than max seem like defensive programming.
CVE-2026-71486 2 Vllm, Vllm-project 2 Vllm, Vllm 2026-10-02 4.3 Medium
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender endpoints accept caller-supplied GenerateResponse objects whose generate_responses, choices, token_ids, prompt_logprobs, logprobs.content, top_logprobs, and routed_experts structures are processed by OnlineDerenderer and tokenizer.decode before max_model_len, max_tokens, max_num_seqs, or response-size limits are enforced, allowing an authenticated API client to consume excessive CPU and memory and produce oversized responses. This issue is fixed in version 0.26.0.
CVE-2026-93698 1 Webpros 2 Cpanel, Wp Squared 2026-10-02 N/A
Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
CVE-2026-93697 1 Webpros 2 Cpanel, Wp Squared 2026-10-02 N/A
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
CVE-2026-71452 1 Johnson Controls 1 Easyio Fs32 2026-10-02 N/A
- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63.
CVE-2026-71451 1 Johnson Controls 1 Easyio Fs32 2026-10-02 N/A
- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0b63.
CVE-2026-27874 1 Johnson Controls 1 Easyio Fs32 2026-10-02 N/A
: Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63.
CVE-2026-27873 1 Johnson Controls 2 Easy Io Fg, Easyio Fg 2026-10-02 N/A
- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52.
CVE-2026-104123 1 Sourcecodester 1 Online Reviewer Management System 2026-10-02 7.3 High
A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation of the argument Title results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
CVE-2026-104053 2 Itsourcecode, Sourcecodester 2 Pet Shop Management System, Petshop Management System 2026-10-02 6.3 Medium
A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
CVE-2026-102626 1 Limesurvey 1 Limesurvey 2026-10-02 N/A
An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time question. When another user renders the affected question, LimeSurvey inserts the stored value into a single-quoted inline JavaScript literal without JavaScript-context encoding.
CVE-2026-104414 1 Ghost 1 Ghost 2026-10-02 8.1 High
Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. Attackers can host malicious oEmbed photo responses so that embedding their URL stores scripts that run in the Ghost editor, published site, and newsletter emails, compromising staff admin sessions.
CVE-2026-93029 1 Webpros 2 Cpanel, Wp Squared 2026-10-02 N/A
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.