Export limit exceeded: 372951 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372951 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-49332 | 1 Redhat | 2 Openshift, Openshift Container Platform | 2026-08-20 | 8.5 High |
| A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application. | ||||
| CVE-2026-77077 | 1 N8n | 1 N8n | 2026-08-20 | N/A |
| n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape. The runner's prototype-freezing routine covers globalThis functions but not internal module constructors such as EventEmitter, allowing an authenticated user with Code node access to exploit prototype pollution to execute arbitrary commands within the runner container. Because the polluted prototype is a process-wide object, the corruption persists across other tenants' Code node executions on the same shared runner. On v1.x instances without task runners enabled, Code node JavaScript runs directly in the main n8n process, where the impact could be higher. | ||||
| CVE-2026-76926 | 1 Wireshark | 1 Wireshark | 2026-08-20 | 3.1 Low |
| BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-76924 | 1 Wireshark | 1 Wireshark | 2026-08-20 | 5.5 Medium |
| Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-76923 | 1 Wireshark | 1 Wireshark | 2026-08-20 | 5.5 Medium |
| Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-76918 | 1 Wireshark | 1 Wireshark | 2026-08-20 | 5.5 Medium |
| SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-76917 | 1 Wireshark | 1 Wireshark | 2026-08-20 | 5.5 Medium |
| Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-76891 | 1 Wireshark | 1 Wireshark | 2026-08-20 | 3.1 Low |
| Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-76885 | 1 Wireshark | 1 Wireshark | 2026-08-20 | 3.1 Low |
| Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-76880 | 1 Wireshark | 1 Wireshark | 2026-08-20 | 7.5 High |
| RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | ||||
| CVE-2026-75952 | 1 Cmsjunkie.com | 1 J-businessdirectory Extension For Joomla | 2026-08-20 | N/A |
| Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, messages, AI text generation, and several administrator actions (app install, demo-data wipe, cache/statistics archive, payment notification send, mobile push). Frontend CSRF needs a registered/listing-owner session; admin CSRF needs a backend admin session. | ||||
| CVE-2026-75114 | 2026-08-20 | N/A | ||
| Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 - The referer request parameter is passed straight to setRedirect() with no validation. | ||||
| CVE-2026-74804 | 2026-08-20 | N/A | ||
| Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is interpolated into the query as a.type = "..." and the type_filter array as a.type IN ("..."), with no quoting or escaping. | ||||
| CVE-2026-74803 | 2026-08-20 | N/A | ||
| Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group. | ||||
| CVE-2026-73390 | 2026-08-20 | 9.8 Critical | ||
| Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. | ||||
| CVE-2026-73389 | 2026-08-20 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. | ||||
| CVE-2026-73385 | 2026-08-20 | 7.5 High | ||
| Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions. | ||||
| CVE-2026-73384 | 2026-08-20 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions. | ||||
| CVE-2026-73347 | 2 Themetechmount, Wordpress | 2 Truebooker, Wordpress | 2026-08-20 | 9.8 Critical |
| Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions. | ||||
| CVE-2026-73185 | 2 Wordpress, Wpo-hr | 2 Wordpress, Ngg Smart Image Search | 2026-08-20 | 9.3 Critical |
| Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions. | ||||