Search

Search Results (400207 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100553 1 Openclaw 1 Openclaw 2026-09-29 4.3 Medium
OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feishu unpin feature, so unpin requests can bypass the shared same-provider cross-context target check. When tools.message.crossContext.allowWithinProvider is disabled, an admitted (authenticated) sender can remove a pin from another Feishu group that the sender and the configured account are otherwise permitted to access, bypassing the intended cross-context message mutation policy. Feishu membership and group authorization still apply, and the demonstrated impact is limited to message mutation (pin removal). The issue is fixed in 2026.8.1.
CVE-2026-100549 1 Openclaw 1 Openclaw 2026-09-29 5.4 Medium
OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filenames are decoded twice, allowing encoded traversal segments to reappear after sanitization. Attackers can supply crafted voice attachments that write files outside the intended staging directory to other process-writable locations.
CVE-2026-100545 1 Openclaw 1 Openclaw 2026-09-29 5.3 Medium
OpenClaw (npm package `openclaw`) before 2026.8.1 incorrectly enforces sender tool policies during session-memory filename generation. In affected versions, filename generation created an embedded helper that retained tools which the originating sender's policy had removed. When session-memory filename generation was enabled for an agent reachable by lower-trust senders, model-mediated instructions could cause the helper to invoke tools outside that sender's effective policy; the demonstrated impact was the creation of persistent scheduled work. Exploitability depends on the model acting on the injected instruction and on which tools the helper exposes. The issue is fixed in 2026.8.1; as a workaround, disable session-memory filename generation for agents reachable by lower-trust senders.
CVE-2026-96418 1 Wireshark 1 Wireshark 2026-09-29 5.5 Medium
TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-96417 1 Wireshark 1 Wireshark 2026-09-29 5.5 Medium
RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-95394 1 Wireshark 1 Wireshark 2026-09-29 4.7 Medium
Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-101266 1 Pretix 1 Pretix 2026-09-29 N/A
A logic flaw in the checkout flow allows users to bypass validations performed during the check-in by skipping entire check-in steps.
CVE-2026-101267 1 Pretix 1 Pretix 2026-09-29 N/A
A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.
CVE-2026-101268 1 Pretix 1 Pretix 2026-09-29 N/A
If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account. If the victim does not notice this, this might lead to their order details being stored into the attacker's account. The attack only works when the event is available on a different domain than the organizer page.
CVE-2026-101269 1 Pretix 1 Pretix 2026-09-29 N/A
The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users. Since API-uploaded files are refered to by randomly generated UUIDs and only exist for a day, there is virtually no risk, but it renders the added protection mechanism useless.
CVE-2026-101270 1 Pretix 1 Pretix 2026-09-29 N/A
Malicious HTML content could be injected into the help texts of various fields with organizer permissions.
CVE-2026-101271 1 Pretix 1 Pretix 2026-09-29 N/A
OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.
CVE-2026-93402 1 Rsyslog 1 Rsyslog 2026-09-29 3.1 Low
A flaw was found in rsyslog. When using the imdtls input module configured for name or fingerprint authentication, permitted-peer identity checks are not enforced after a successful DTLS handshake. A remote attacker possessing a valid certificate signed by the listener's trusted Certificate Authority could bypass peer restrictions and inject unauthorized syslog records into the input stream.
CVE-2026-65129 2 Linux, Nvidia 3 Linux Kernel, Infra Controller, Infrastructure Controller 2026-09-29 6.7 Medium
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
CVE-2026-100748 1 Svenbluege.de 1 Event Gallery For Joomla 2026-09-29 N/A
Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0
CVE-2026-97164 1 Svenbluege.de 1 Event Gallery For Joomla 2026-09-29 N/A
Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extension < 6.5.0 - Using the `images` parameter of the `cache.process` task, you can recursively delete any directories that the web server is authorized to write to.
CVE-2026-67364 1 Balbooa.com 1 Balbooa.com Balbooa Forms Extension For Joomla 2026-09-29 N/A
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting an unauthenticated attacker inject arbitrary PHP that executes server-side. The CSRF token needed to reach the endpoint is itself disclosed anonymously via a separate task, so it provides no real protection. Exploitability requires the form to have a custom-PHP handler configured (a documented builder feature) referencing that shortcode, and no reCAPTCHA on the submit button.
CVE-2026-102796 2026-09-29 N/A
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wikimedia Foundation Mediawiki - UserPageViewTracker Extension allows SQL Injection. This issue affects Mediawiki - UserPageViewTracker Extension: from * before 1.46.1, 1.45.5, 1.43.10.
CVE-2026-88022 1 Mongodb 2 Laravel Mongodb, Laravel Mongodb (php) 2026-09-29 7.7 High
Improper neutralization of special elements in data query logic in the MongoDB integration for Laravel can cause an array supplied to an explicit equality filter to be interpreted as a query condition rather than as a literal value. This affects the three-argument `where` method when the operator is `=` or `eq`, as well as the `find` and `delete` methods that use that code path. An attacker who can cause an affected application to supply an operator-shaped array to one of these APIs may obtain a document other than the intended target or delete documents beyond the intended target.
CVE-2026-63498 2 Grokability, Snipeitapp 2 Snipe-it, Snipe-it 2026-09-29 8.7 High
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML and XSLT attachments and request them with the inline=true parameter. The app/Http/Controllers/Api/UploadedFilesController.php show() path does not apply the safe-inline allowlist used by the equivalent web controller, so the browser can process an attacker-controlled xml-stylesheet reference and execute JavaScript generated by the stylesheet in the Snipe-IT origin. A victim who is authorized to view the object must open the attachment URL, after which the script can read same-origin data and perform authenticated actions with the victim's privileges. This issue is fixed in version 8.7.0.