Total
395763 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-39039 | 2026-09-15 | N/A | N/A | ||
| In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT authentication token, full user object, and session ID in the browser's localStorage, which is fully accessible to any JavaScript running on the page. | |||||
| CVE-2026-36989 | 2026-09-15 | N/A | 5.8 MEDIUM | ||
| A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php. | |||||
| CVE-2026-20353 | 2026-09-15 | N/A | 9.8 CRITICAL | ||
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20353 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664. | |||||
| CVE-2025-70820 | 2026-09-15 | N/A | 3.5 LOW | ||
| Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder. | |||||
| CVE-2025-32910 | 2026-09-15 | N/A | 6.5 MEDIUM | ||
| A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash. | |||||
| CVE-2025-32909 | 2026-09-15 | N/A | 5.3 MEDIUM | ||
| A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the libsoup client to crash. | |||||
| CVE-2023-54398 | 2026-09-15 | N/A | 9.8 CRITICAL | ||
| Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via POST request. Attackers can exploit the doAction method, which passes raw HTTP request body data directly to ObjectInputStream.readObject() without filtering, to achieve remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-02-13. | |||||
| CVE-2026-84653 | 1 Jenkins | 1 Jenkins | 2026-09-15 | N/A | 3.5 LOW |
| Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to. | |||||
| CVE-2026-84655 | 1 Jenkins | 1 Jenkins | 2026-09-15 | N/A | 4.3 MEDIUM |
| Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses. | |||||
| CVE-2026-84656 | 1 Jenkins | 1 Jenkins | 2026-09-15 | N/A | 4.3 MEDIUM |
| A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they have no access to. | |||||
| CVE-2026-84657 | 1 Jenkins | 1 Jenkins | 2026-09-15 | N/A | 4.2 MEDIUM |
| In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users. | |||||
| CVE-2026-3416 | 1 Wso2 | 2 Api Control Plane, Api Manager | 2026-09-15 | N/A | 5.9 MEDIUM |
| The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future secrets. This enables malicious actors to forge event payloads with valid HMAC signatures, bypassing the API Gateway's authenticity verification. Successful exploitation could allow an attacker to predict shared secrets used for Webhook HMAC validation and forge event payloads with valid signatures. This may enable bypassing API Gateway authenticity checks, leading to unauthorized event injection, data manipulation, or downstream system compromise. | |||||
| CVE-2026-75049 | 1 Jetbrains | 1 Youtrack | 2026-09-15 | N/A | 6.5 MEDIUM |
| In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint | |||||
| CVE-2026-75048 | 1 Jetbrains | 1 Youtrack | 2026-09-15 | N/A | 8.2 HIGH |
| In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible | |||||
| CVE-2026-75047 | 1 Jetbrains | 1 Youtrack | 2026-09-15 | N/A | 6.5 MEDIUM |
| In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint | |||||
| CVE-2026-75046 | 1 Jetbrains | 1 Youtrack | 2026-09-15 | N/A | 4.3 MEDIUM |
| In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint | |||||
| CVE-2026-75044 | 1 Jetbrains | 1 Youtrack | 2026-09-15 | N/A | 8.1 HIGH |
| In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint | |||||
| CVE-2026-75045 | 1 Jetbrains | 1 Youtrack | 2026-09-15 | N/A | 9.1 CRITICAL |
| In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature | |||||
| CVE-2026-75050 | 1 Jetbrains | 1 Youtrack | 2026-09-15 | N/A | 7.1 HIGH |
| In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters | |||||
| CVE-2026-84538 | 1 Apple | 1 Macos | 2026-09-15 | N/A | 6.5 MEDIUM |
| A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause a denial-of-service. | |||||
