Export limit exceeded: 377502 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (377502 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73551 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 5.3 Medium |
| No description is available for this CVE. | ||||
| CVE-2026-73552 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.5 High |
| No description is available for this CVE. | ||||
| CVE-2026-73553 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.5 High |
| No description is available for this CVE. | ||||
| CVE-2026-18765 | 1 Teracity | 1 E-osb | 2026-09-02 | 9.8 Critical |
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects E-OSB: before V02.26.07.08.01. | ||||
| CVE-2026-84149 | 1 Manacle Technologies | 1 Multi-tenant Erp System | 2026-09-02 | N/A |
| This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit this vulnerability by accessing the exposed .git directory and retrieving repository metadata and associated files, which could allow reconstruction of the application's source code. | ||||
| CVE-2026-18808 | 1 Klemsan Electrical Electronics | 1 Kio (klemsan Internet Objects) | 2026-09-02 | 9.8 Critical |
| Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO (Klemsan Internet Objects): before v1.9. | ||||
| CVE-2026-18210 | 1 Trtek | 1 Products Store | 2026-09-02 | 9.8 Critical |
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection. This issue affects Products's Store: before 030631b2. | ||||
| CVE-2026-18771 | 1 Tmt Machine | 1 Talassoft Industrial Management Software | 2026-09-02 | 7.5 High |
| Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass. This issue affects Talassoft Industrial Management Software: from V4 before V.16. | ||||
| CVE-2026-18780 | 1 Tmt Machine | 1 Talassoft Industrial Management Software | 2026-09-02 | 7.1 High |
| Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery. This issue affects Talassoft Industrial Management Software: from V.4 before V.16. | ||||
| CVE-2026-18630 | 1 Tmt Machine | 1 Talassoft Industrial Management Software | 2026-09-02 | 8.8 High |
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows SQL Injection. This issue affects Talassoft Industrial Management Software: from V.4 before V.16. | ||||
| CVE-2026-18931 | 1 Tmt Machine | 1 Talassoft Industrial Management Software | 2026-09-02 | 9.1 Critical |
| Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Embedded Sensitive Data. This issue affects Talassoft Industrial Management Software: from V.4 before V.16. | ||||
| CVE-2026-84201 | 1 Argneshu | 1 Appium-mcp-server | 2026-09-02 | 7.1 High |
| appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, allowing attackers to write files outside the intended PROJECT_ROOT directory. Attackers can supply absolute paths or relative paths with parent directory segments to overwrite arbitrary files with the server user's privileges, including shell profiles and configuration files in the home directory. | ||||
| CVE-2026-10195 | 2 Fs-code, Wordpress | 2 Fs Poster - Wordpress Social Media Auto Poster & Scheduler [facebook, Instagram, Twitter, Pinterest], Wordpress | 2026-09-02 | 8.8 High |
| The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. This is due to insufficient input sanitization of the FFmpeg path parameter before passing it to the exec() function, combined with missing authorization checks on the REST API endpoints. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary commands on the underlying server. | ||||
| CVE-2026-19590 | 1 Openai | 2 Codex Desktop, Codex Desktop (microsoft Store Package) | 2026-09-02 | N/A |
| OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath setting. If a user opens an attacker-prepared repository whose preserved .git/config points core.hooksPath to an attacker-controlled directory, Codex can run a malicious hook while processing the repository. The hook executes outside Codex's command sandbox, without user approval, and with the user's privileges, allowing it to read, change, or delete the user's files and access other resources available to the user's account. An ordinary Git clone does not preserve the attacker-controlled repository-local configuration required for exploitation. | ||||
| CVE-2026-19593 | 1 Openai | 2 Codex Desktop, Codex Desktop (microsoft Store Package) | 2026-09-02 | 9.8 Critical |
| OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process filter can cause Git to run an attacker-controlled program. The program runs outside Codex's command sandbox with the signed-in user's privileges, without a workspace-trust prompt, command approval, or interaction with a model. The attacker can read, modify, or delete files and access credentials available to that user. Exploitation requires Git to be available on PATH and the user to open the attacker-prepared repository with its local Git configuration intact. An ordinary Git clone does not copy the source repository's .git/config and is not sufficient by itself. | ||||
| CVE-2026-8712 | 1 Ohf-voice | 1 Wyoming | 2026-09-02 | 8.3 High |
| Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitrary targets by supplying a malicious `uri` query parameter to the HTTP API. Attackers can pass arbitrary `tcp://` or `unix://` URIs to affected endpoints including /api/info, /api/speech-to-text, and /api/text-to-speech to override the server-configured backend and redirect connections to attacker-chosen hosts. | ||||
| CVE-2026-19766 | 1 Hewlett Packard Enterprise (hpe) | 1 Fabric Composer | 2026-09-02 | 9.6 Critical |
| An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the AFC host. | ||||
| CVE-2026-73700 | 2 Arubanetworks, Hewlett Packard Enterprise (hpe) | 2 Fabric Composer, Fabric Composer | 2026-09-02 | 9 Critical |
| A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. | ||||
| CVE-2026-73701 | 2 Arubanetworks, Hewlett Packard Enterprise (hpe) | 2 Fabric Composer, Fabric Composer | 2026-09-02 | 9 Critical |
| An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the HPE Networking Fabric Composer host. | ||||
| CVE-2026-73702 | 2 Arubanetworks, Hewlett Packard Enterprise (hpe) | 2 Fabric Composer, Fabric Composer | 2026-09-02 | 8.8 High |
| A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrative user, leading to complete system compromise. | ||||