Export limit exceeded: 381188 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381188 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-76647 | 1 Leantime | 1 Json-rpc Api | 2026-08-20 | N/A |
| Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JSON-RPC dispatcher in app/Domain/Api/Controllers/Jsonrpc.php. The dispatcher does not enforce authorization before invoking service-layer methods, allowing an authenticated user to call methods or act on resources outside their intended permissions. For example, the editOwn method accepts a user-supplied user ID without verifying that it belongs to the caller, allowing an attacker to modify another user's account and set a new password, resulting in account takeover. This vulnerability is distinct from CVE-2026-59712 and CVE-2026-15509 because the root cause is the lack of centralized authorization enforcement in the JSON-RPC dispatcher rather than the behavior of an individual exposed method. | ||||
| CVE-2026-19505 | 1 Rdk | 1 Rdk-b Webui | 2026-08-20 | N/A |
| Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to bypass authentication and obtain administrative access via a forged JWT containing an invalid RSA signature. | ||||
| CVE-2026-19507 | 1 Rdk | 1 Rdk-b Webui | 2026-08-20 | N/A |
| Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause denial of service via excessively large password values. | ||||
| CVE-2026-22049 | 1 Netapp | 2 Ontap, Ontap 9 | 2026-08-20 | 8.8 High |
| ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA. | ||||
| CVE-2026-18482 | 2026-08-20 | N/A | ||
| Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution when an AI agent is induced to invoke these tools. Commit 88c77fc fixes these vulnerabilities. | ||||
| CVE-2026-19508 | 1 Rdk | 1 Rdk-b Webui | 2026-08-20 | N/A |
| Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause memory corruption and denial of service, and potentially execute arbitrary code, via a crafted multipart/form-data request. | ||||
| CVE-2026-21784 | 2026-08-20 | 4.8 Medium | ||
| HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized external interaction and potential exploitation. | ||||
| CVE-2026-77085 | 1 N8n | 1 N8n | 2026-08-20 | N/A |
| n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The tool sent requests to the user-supplied API URL using a raw HTTP client that did not route through n8n's centralized SSRF protection. On instances with N8N_SSRF_PROTECTION_ENABLED=true, an authenticated user with permission to create SearXNG credentials and configure a personal agent could set the API URL to an internal host, causing the n8n server to connect to that host and return the response content through the Agent chat output. | ||||
| CVE-2025-62299 | 2026-08-20 | 6.6 Medium | ||
| HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges. | ||||
| CVE-2026-76987 | 1 Liftoff-sr | 1 Cipster | 2026-08-20 | 7.3 High |
| A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. The impacted element is the function CipAttribute::GetAttrData/CipAttribute::SetAttrData of the file ciptypes.h of the component Generic Attribute Logic. Performing a manipulation results in memory corruption. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The patch is named e745d9d4a8ca3a13689066983a1269fe1e567674. It is suggested to install a patch to address this issue. | ||||
| CVE-2025-62300 | 2026-08-20 | 5.9 Medium | ||
| HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable behavior. | ||||
| CVE-2026-7485 | 1 Checkmk | 1 Checkmk | 2026-08-20 | N/A |
| Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of hosts and services they are not authorized to see. | ||||
| CVE-2025-62306 | 2026-08-20 | 5 Medium | ||
| HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response. | ||||
| CVE-2026-66581 | 2026-08-20 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. | ||||
| CVE-2026-66609 | 2026-08-20 | 9.3 Critical | ||
| Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. | ||||
| CVE-2026-66598 | 2026-08-20 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions. | ||||
| CVE-2026-68564 | 2026-08-20 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions. | ||||
| CVE-2026-66672 | 2026-08-20 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. | ||||
| CVE-2025-15637 | 2026-08-20 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. | ||||
| CVE-2025-62307 | 2026-08-20 | 5.4 Medium | ||
| HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing. | ||||