Search

Search Results (400207 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100286 1 Devolutions 1 Server 2026-09-30 6.5 Medium
Missing authorization in the data source settings API in Devolutions ServerĀ 2026.3.5.0 and earlier allows an authenticated non-administrative user to disclose integration secrets via a crafted API request.
CVE-2026-103042 1 Modeltc 1 Lightllm 2026-09-30 7.5 High
LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposed_set_value method to store unbounded key-value pairs without size limits, causing the worker process to crash and triggering node failure.
CVE-2026-102843 1 Gedelumbung 1 Hospitalmanagement 2026-09-30 4.7 Medium
A security flaw has been discovered in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This affects the function hapus of the file application/modules/admin/controllers/data_galeri.php of the component Endpoint. Performing a manipulation of the argument gbr results in path traversal. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-100289 1 Devolutions 1 Server 2026-09-30 5 Medium
Missing authorization in the gateway network scan token API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to generate a network scan token and perform internal network discovery and port scanning through the gateway via a crafted API request.
CVE-2026-95390 1 Wireshark 1 Wireshark 2026-09-30 5.5 Medium
PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of service
CVE-2026-49243 1 Webmin 1 Webmin 2026-09-30 N/A
Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.650, Webmin users who click on a malicious link to their server are vulnerable to this XSS vulnerability that could be used to execute attacker-controlled commands. This issue has been patched in version 2.650.
CVE-2026-102630 2 Unopim, Webkul 2 Unopim, Unopim 2026-09-30 4.7 Medium
UnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies and honor the X-Forwarded-Host header without validation, allowing unauthenticated attackers to inject arbitrary origins into admin layout pages. Attackers can set X-Forwarded-Host to redirect JavaScript asset loading to their server, and when responses are cached by shared proxies, subsequent administrators execute attacker-supplied code in their authenticated sessions.
CVE-2026-100315 1 Mathurvishal 1 Cloudclassroom-php-project 2026-09-30 7.3 High
A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file mydetailsfaculty.php. The manipulation of the argument myfid results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-100312 1 Mathurvishal 1 Cloudclassroom-php-project 2026-09-30 6.3 Medium
A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file /updateguest.php. Performing a manipulation of the argument gname/editassid results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-102720 1 Eclipse 1 Threadx Netx Duo 2026-09-30 N/A
A DHCP server, or anyone on the LAN who answers a DISCOVER first, can make the client read about a kilobyte past the end of the received message. The option walk keeps a pointer and an offset in step, and the only bound check uses the offset: ```c /* addons/dhcp/nxd_dhcp_client.c:7538, 7572 */ while (i < length - 1) { ... size = *(++data); /* data moves 1: type -> length byte */ data += size + 1; /* data moves size + 1 more */ i += size + 1; /* i moves only size + 1 */ } ``` A TLV option occupies size + 2 bytes. `data` is advanced by size + 2 in total, `i` by size + 1, so the offset falls one byte behind the real read position for every option the walk skips. After enough skipped options the check `i < length - 1` still holds while `data` is already past the end of the message, and the subsequent read of the type and length bytes comes from whatever follows. A single OFFER carrying a long run of skippable options is enough: ``` ERROR: AddressSanitizer: heap-buffer-overflow READ of size 1 at 0x61b000000794 thread T5 #0 _nx_dhcp_search_buffer addons/dhcp/nxd_dhcp_client.c:7541 #1 _nx_dhcp_get_option_value addons/dhcp/nxd_dhcp_client.c:7082 0x61b000000794 is located 164 bytes to the right of 1648-byte region ``` A well formed OFFER through the same path is handled normally, the client records the offer and moves to REQUESTING, so the difference is the option layout rather than the harness. The read runs in the DHCP client thread while the client is still unconfigured, so it happens on every boot in reach of a hostile DHCP responder. The values read are used to configure the interface, which is how the disclosed bytes become observable. Advance `i` by size + 2, or derive the bound from `data` rather than keeping a second counter.
CVE-2026-102300 1 Google 1 Chrome 2026-09-30 4.3 Medium
Uninitialized resource in WebGPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
CVE-2026-102805 1 Nothings 1 Stb 2026-09-30 6.5 Medium
A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead to integer overflow. The attack can be executed remotely. The exploit has been published and may be used.
CVE-2026-102757 1 Eclipse 1 Threadx 2026-09-30 N/A
An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode, and can use that to clear the MPU enable bit and remove its own isolation boundary. The Module Manager decided whether a privileged service could dereference an object address a module named by asking only whether that address fell outside the module. The manager's object pool is outside every module, so the test was satisfied by an address shifted into the interior of one of the module's own privileged allocations, which denotes no object at all. The bytes such an address presents as a control block are bytes the module put there through ordinary create and set services, so the control block ID at the front of them could be made to read as any type the module chose, and the `_txe_` layer's ID test then agreed. The reported chain uses that to reach a privileged `memset` across an attacker-chosen range.
CVE-2026-95365 1 Google 1 Chrome 2026-09-30 8.8 High
Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-100417 1 Rustdesk 1 Rustdesk 2026-09-30 3.1 Low
RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard. Attackers can send FormatDataRequest and FileContentsRequest messages to retrieve copied files by guessing the FileGroupDescriptorW format identifier.
CVE-2026-100388 1 Rustdesk 1 Rustdesk 2026-09-30 5.4 Medium
RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. Authenticated remote peers with disabled file transfer permissions can place files onto the host clipboard and retrieve copied files and contents from the process-wide clipboard cache.
CVE-2026-100368 1 Alastairlundy 1 Cliinvoke.specializations 2026-09-30 8.4 High
CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide specialized wrappers for shells such as PowerShell and Windows Command Prompt. `CliInvoke.Specializations` versions 2.2.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, 3.0.0-alpha.1 through 3.0.0-alpha.4, and 3.0.0-alpha.8 through 3.0.0-alpha.10, as well as `AlastairLundy.CliInvoke.Specializations` versions 1.0.0-rc.1 through 1.6.1.1, contain an OS command injection vulnerability in their PowerShell and Cmd wrappers. The wrappers pass a caller-controlled target and arguments to `pwsh -Command` or `cmd /c` using a single `ProcessStartInfo.Arguments` string, allowing a double quote in untrusted input to break operating-system-level quoting and cause the shell to execute an additional command with the host process's privileges. The vulnerability is patched in `CliInvoke.Specializations` versions 2.8.5, 2.9.4, 2.10.5, and 3.0.0-beta.1, and in `AlastairLundy.CliInvoke.Specializations` version 2.0.2. No complete workaround is available; users unable to upgrade should reject or remove double quotes from target paths and arguments, additionally reject shell metacharacters in versions 2.2.0 through 2.9.2 and 3.0.0-alpha.1 through 3.0.0-alpha.4, or bypass the PowerShell and Cmd wrappers and invoke target processes directly when handling untrusted input.
CVE-2026-100310 1 Gnu 1 Libextractor 2026-09-30 7 High
GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious plugin that executes arbitrary code with elevated privileges when loaded by a setuid or setgid program.
CVE-2026-100303 1 Tduckcloud 1 Tduck-survey-form 2026-09-30 5.4 Medium
TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories. Authenticated non-admin users can add, modify, or delete themes and theme categories affecting forms owned by other users.
CVE-2026-53626 1 Glpi-project 1 Glpi 2026-09-30 N/A
GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. A user can use an unrelated item that the user is permitted to view to read a document linked to an inaccessible item. This issue is fixed in version 11.0.8.