Search Results (43609 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-102726 1 Eclipse 1 Netx Duo 2026-09-30 N/A
Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read
CVE-2026-61519 1 Liberu Software 1 Liberu Crm 2026-09-30 8.8 High
Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a pending team invitation to invite additional attacker-controlled accounts with elevated privileges by exploiting a flawed authorization predicate in TeamPolicy::addTeamMember() that grants invitation rights based solely on the existence of a pending invitation email match. Attackers can send a POST request to the team-invitations route specifying the admin role for a second account, bypassing privilege-level validation in InviteTeamMember, causing the second account upon invitation acceptance to be attached to the team with full admin-level create, read, update, and delete access over all team-scoped data.
CVE-2026-72510 1 Toptech Systems 2 Tms7, Tophat 2026-09-30 9 Critical
The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection.
CVE-2026-63713 1 Toptech Systems 2 Tms7, Tophat 2026-09-30 9 Critical
The "search" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability.
CVE-2026-68954 1 Toptech Systems 2 Tms7, Tophat 2026-09-30 9 Critical
The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability.
CVE-2026-68068 1 Toptech Systems 2 Tms7, Tophat 2026-09-30 9 Critical
The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability.
CVE-2026-72507 1 Toptech Systems 2 Tms7, Tophat 2026-09-30 9 Critical
The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability.
CVE-2026-97150 1 Basercms Users Community 1 Bcaddonmigrator 2026-09-30 N/A
When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user.
CVE-2026-96342 2 Amauri, Wordpress-extensions 2 Wpmobile.app, Wpmobile.app 2026-09-30 N/A
Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83.
CVE-2026-82307 1 Dolusoft Software Technologies 1 Soplog 2026-09-30 9.8 Critical
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1.
CVE-2026-18782 1 Trex Digital Smart Manufacturing 1 Trex Mes 2026-09-30 9.8 Critical
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29.
CVE-2026-103443 1 Wikimedia 1 Mediawiki-collection (book) Extension 2026-09-30 N/A
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Collection (Book) extension allows XSS Targeting Non-Script Elements. This issue affects MediaWiki Collection (Book) extension: 1.46, 1.45, and 1.43.
CVE-2026-103444 1 Wikimedia 1 Mediawiki Wikiforum Extension 2026-09-30 N/A
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki WikiForum extension allows Stored XSS. This issue affects MediaWiki WikiForum extension: master.
CVE-2026-81841 1 Grafana 2 Grafana, Grafana Enterprise 2026-09-30 5.3 Medium
Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a paused shared dashboard could still retrieve, without authenticating, the configuration of the dashboard's data sources, including stored credentials for data sources using browser access (missing authorization). Deleting the shared dashboard does revoke the token.
CVE-2026-81842 1 Grafana 2 Grafana, Grafana Enterprise 2026-09-30 4.3 Medium
An authenticated user with edit permission on one folder can move a library panel into another folder where they only have view permission, through the library elements API or the equivalent App Platform resource. The update path did not check library panel create permission on the destination folder (incorrect authorization). No data from the destination folder is disclosed, and existing content there cannot be changed.
CVE-2026-47559 1 Nvidia 6 Geforce, Guest Driver, Nvs and 3 more 2026-09-30 7.8 High
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could access memory belonging to another user's process. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
CVE-2026-95310 1 Google 1 Chrome 2026-09-30 9.6 Critical
Use after free in AdFilter in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-95371 2 Apple, Google 2 Macos, Chrome 2026-09-30 5.4 Medium
Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-76111 1 Dell 13 Powerstore 1000t, Powerstore 1200t, Powerstore 3000t and 10 more 2026-09-30 8.8 High
Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation.
CVE-2026-95306 1 Google 1 Chrome 2026-09-30 8.8 High
Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)