Vulnerabilities (CVE)

Total 398874 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-4037 2 Debian, Linux 2 Debian Linux, Linux Kernel 2026-08-10 N/A 4.4 MEDIUM
A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS.
CVE-2026-66885 1 Livebook 1 Livebook 2026-08-10 N/A 6.5 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's browser session under the attacker's own Livebook Teams identity. When Livebook is configured to use Livebook Teams for identity, Livebook.ZTA.LivebookTeams.handle_request/4 in lib/livebook/zta/livebook_teams.ex handles the OAuth-style callback carrying a teams_identity marker and a code parameter. The clause exchanges that code for an access token and writes the token into the browser session without verifying any value that ties the callback to the browser session that started the login. No state or nonce is generated when the flow is initiated: Livebook.Teams.Requests.create_auth_request/1 in lib/livebook/teams/requests.ex sends an empty request body, so no per-attempt value is ever registered, and the callback clause has nothing to compare against. An attacker who holds membership in the same Livebook Teams organisation as the target instance can therefore begin the login flow themselves, retain the resulting authorization code without redeeming it, and induce a victim to open a crafted URL carrying that code. The victim's browser completes the exchange and the resulting session is bound to the attacker's identity rather than the victim's. The victim is not required to hold any particular privilege, and no credential belonging to the victim is involved. The vulnerability does not allow the attacker to authenticate as the victim. The consequence is that a user believes they are working in their own authenticated session while they are in fact operating as another identity. Work performed in that session is attributed to the attacker's account, and secrets, uploaded data, or notebook results the victim produces are exposed to the attacker rather than kept in the victim's own account. The authorization code must be redeemed within a short window after the login flow begins, which constrains the timing of the attack but not its feasibility. This issue affects livebook: from 0.15.0 before 0.18.7 and from 0.19.0 before 0.19.9.
CVE-2026-68746 1 Livebook 1 Livebook 2026-08-10 N/A 8.8 HIGH
Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to obtain full access to a Livebook server that enforces identity through Livebook Teams. A Livebook Agent or App Server connected to Livebook Teams caches the identifier of the deployment group it belongs to, and resolves that identifier against a locally cached list of deployment groups on every request in order to decide whether Teams identity enforcement is active. Livebook.Hubs.TeamClient.handle_call/3 in lib/livebook/hubs/team_client.ex does not distinguish a deployment group that could not be resolved from one that was resolved with identity enforcement switched off: the clause matches only the case where a group was found with enforcement enabled, and falls through to a catch-all that reports enforcement as switched off for everything else. The two neighbouring functions that decide user and application access resolve the same identifier and treat the same unresolved result as a denial. When the identity status is reported as switched off, Livebook.ZTA.LivebookTeams.authenticate/3 in lib/livebook/zta/livebook_teams.ex returns empty identity metadata and allows the request to continue instead of halting it. LivebookWeb.UserPlug.build_current_user/3 merges that empty metadata into a newly built user, whose access type defaults to full access, and LivebookWeb.AuthPlug.authorized?/1 grants access to any user holding full access. The cached identifier becomes unresolvable when the deployment group it refers to is deleted while the agent is not connected to receive the change, most concretely when a deployment group is deleted during the window in which an agent is disconnected or reconnecting. The client removes the group from its cached list without clearing the identifier that refers to it. Any client able to reach the affected server over the network is then granted the same access as a fully privileged member of the organisation, including the ability to read notebooks and configured secrets, execute code on the server's runtime, and disrupt its operation. This issue affects livebook: from 0.19.7 before 0.19.9.
CVE-2026-15656 1 Ibm 1 Maximo Application Suite 2026-08-10 N/A 4.3 MEDIUM
IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
CVE-2026-40417 1 Microsoft 1 Dynamics 365 Business Central 2026-08-10 N/A 7.8 HIGH
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
CVE-2025-8361 1 Config Pages Project 1 Config Pages 2026-08-10 N/A 7.6 HIGH
Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing. This issue affects Config Pages: from 0.0.0 before 2.18.0.
CVE-2025-6999 2026-08-10 N/A N/A
An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting (XSS) attack. WatchGuard does not believe there is a practical exploit chain with a meaningful security impact for this vulnerability.
CVE-2025-29821 1 Microsoft 3 Dynamics 365 Business Central 2023, Dynamics 365 Business Central 2024, Dynamics 365 Business Central 2025 2026-08-10 N/A 5.5 MEDIUM
Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.
CVE-2025-1549 2026-08-10 N/A N/A
A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileges on the Windows system. This vulnerability is an additional unmitigated attack path for CVE-2024-4944. This vulnerability is resolved in the Mobile VPN with SSL client for Windows version 12.11.5
CVE-2025-12196 1 Watchguard 34 Firebox M270, Firebox M290, Firebox M370 and 31 more 2026-08-10 N/A 7.2 HIGH
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.
CVE-2025-12195 1 Watchguard 34 Firebox M270, Firebox M290, Firebox M370 and 31 more 2026-08-10 N/A 7.2 HIGH
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via specially crafted IPSec configuration CLI commands.
CVE-2025-12026 1 Watchguard 34 Firebox M270, Firebox M290, Firebox M370 and 31 more 2026-08-10 N/A 7.2 HIGH
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands.
CVE-2024-43496 1 Microsoft 1 Edge Chromium 2026-08-10 N/A 6.5 MEDIUM
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2024-43492 1 Microsoft 1 Autoupdate 2026-08-10 N/A 7.8 HIGH
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
CVE-2024-43489 1 Microsoft 1 Edge Chromium 2026-08-10 N/A 6.5 MEDIUM
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2024-43487 1 Microsoft 8 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 5 more 2026-08-10 N/A 6.5 MEDIUM
Windows Mark of the Web Security Feature Bypass Vulnerability
CVE-2024-43482 1 Microsoft 1 Outlook 2026-08-10 N/A 6.5 MEDIUM
Microsoft Outlook for iOS Information Disclosure Vulnerability
CVE-2024-43479 1 Microsoft 1 Power Automate 2026-08-10 N/A 8.5 HIGH
Microsoft Power Automate Desktop Remote Code Execution Vulnerability
CVE-2024-43476 1 Microsoft 1 Dynamics 365 2026-08-10 N/A 7.6 HIGH
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-43475 1 Microsoft 1 Windows Server 2008 2026-08-10 N/A 7.3 HIGH
Microsoft Windows Admin Center Information Disclosure Vulnerability