Total
396587 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-85505 | 2026-09-09 | N/A | 7.5 HIGH | ||
| ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions). | |||||
| CVE-2026-54422 | 2026-09-09 | N/A | 5.5 MEDIUM | ||
| In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it. | |||||
| CVE-2025-61478 | 2026-09-09 | N/A | 7.5 HIGH | ||
| An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via Spoofed SYN packets. | |||||
| CVE-2026-75464 | 2026-09-09 | N/A | 8.1 HIGH | ||
| OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link(). | |||||
| CVE-2026-56136 | 2026-09-09 | N/A | 4.7 MEDIUM | ||
| In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting a malicious NTFS image. This read operation is triggered by creation of a file with a crafted name. | |||||
| CVE-2026-52491 | 2026-09-09 | N/A | 8.4 HIGH | ||
| An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component | |||||
| CVE-2026-17469 | 1 Ibm | 1 I | 2026-09-09 | N/A | 5.3 MEDIUM |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser. | |||||
| CVE-2026-77104 | 3 Commvault, Linux, Microsoft | 3 Commvault, Linux Kernel, Windows | 2026-09-09 | N/A | 7.5 HIGH |
| CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe. | |||||
| CVE-2026-77103 | 3 Commvault, Linux, Microsoft | 3 Commvault, Linux Kernel, Windows | 2026-09-09 | N/A | 7.5 HIGH |
| CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe. | |||||
| CVE-2026-77102 | 3 Commvault, Linux, Microsoft | 3 Commvault, Linux Kernel, Windows | 2026-09-09 | N/A | 7.5 HIGH |
| CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe. | |||||
| CVE-2026-77101 | 3 Commvault, Linux, Microsoft | 3 Commvault, Linux Kernel, Windows | 2026-09-09 | N/A | 7.5 HIGH |
| CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe. | |||||
| CVE-2026-13739 | 1 Commvault | 1 Commvault | 2026-09-09 | N/A | 9.8 CRITICAL |
| A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center. | |||||
| CVE-2026-38821 | 2026-09-09 | N/A | 7.1 HIGH | ||
| A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c. | |||||
| CVE-2026-38822 | 2026-09-09 | N/A | 7.6 HIGH | ||
| In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name. | |||||
| CVE-2026-38820 | 2026-09-09 | N/A | 8.3 HIGH | ||
| openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh. | |||||
| CVE-2026-38819 | 2026-09-09 | N/A | 5.3 MEDIUM | ||
| Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes. | |||||
| CVE-2026-13737 | 1 Commvault | 1 Commvault | 2026-09-09 | N/A | 9.8 CRITICAL |
| CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X. | |||||
| CVE-2026-38348 | 2026-09-09 | N/A | 7.5 HIGH | ||
| An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file. | |||||
| CVE-2026-38350 | 2026-09-09 | N/A | 7.5 HIGH | ||
| An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. | |||||
| CVE-2026-38343 | 2026-09-09 | N/A | 6.5 MEDIUM | ||
| An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file. | |||||
