Total
397439 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-61758 | 1 Nvidia | 1 Nemo Megatron Bridge | 2026-09-02 | N/A | 7.8 HIGH |
| NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |||||
| CVE-2026-61759 | 1 Nvidia | 1 Nemo Megatron Bridge | 2026-09-02 | N/A | 7.8 HIGH |
| NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |||||
| CVE-2026-66758 | 2 Gimp, Redhat | 2 Gimp, Enterprise Linux | 2026-09-02 | N/A | 7.8 HIGH |
| A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service. | |||||
| CVE-2026-58380 | 2 Gimp, Redhat | 2 Gimp, Enterprise Linux | 2026-09-02 | N/A | 7.3 HIGH |
| A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. | |||||
| CVE-2026-84218 | 2026-09-02 | N/A | 8.1 HIGH | ||
| A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolokia POST request and passes it to `JMXServiceURL` and `JMXConnectorFactory` for establishing the remote JMX connection. The existing denylist only rejects URLs matching `service:jmx:rmi:///jndi/ldap:.*`, which can be bypassed using alternative valid JMX service URL forms, including `ldaps://` schemes or LDAP URLs with a non-empty JMX host component. These URLs are accepted as valid `JMXServiceURL` objects and can cause the Jolokia agent JVM to perform a JNDI lookup against an attacker-controlled LDAP endpoint. This can result in server-side request forgery (SSRF), forwarding of supplied JMX credentials to the remote endpoint, and potentially remote code execution depending on the classes and configuration available in the target JVM. | |||||
| CVE-2026-59691 | 2026-09-02 | N/A | 7.1 HIGH | ||
| A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption. | |||||
| CVE-2026-4378 | 2026-09-02 | N/A | 5.4 MEDIUM | ||
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Software Technologies Ltd. E-Commerce Pack allows Stored XSS. This issue affects E-Commerce Pack: from 4.5.001 before 4.6.001. | |||||
| CVE-2026-23591 | 2026-09-02 | N/A | N/A | ||
| Rejected reason: Withdrawn by requester. | |||||
| CVE-2026-23590 | 2026-09-02 | N/A | N/A | ||
| Rejected reason: Withdrawn by requester. | |||||
| CVE-2026-23589 | 2026-09-02 | N/A | N/A | ||
| Rejected reason: Withdrawn by requester. | |||||
| CVE-2026-23588 | 2026-09-02 | N/A | N/A | ||
| Rejected reason: Withdrawn by requester. | |||||
| CVE-2026-23587 | 2026-09-02 | N/A | N/A | ||
| Rejected reason: Withdrawn by requester. | |||||
| CVE-2026-23586 | 2026-09-02 | N/A | N/A | ||
| Rejected reason: Withdrawn by requester. | |||||
| CVE-2026-23585 | 2026-09-02 | N/A | N/A | ||
| Rejected reason: Withdrawn by requester. | |||||
| CVE-2026-23584 | 2026-09-02 | N/A | N/A | ||
| Rejected reason: Withdrawn by requester. | |||||
| CVE-2026-23583 | 2026-09-02 | N/A | N/A | ||
| Rejected reason: Withdrawn by requester. | |||||
| CVE-2026-79687 | 2026-09-02 | N/A | 9.0 CRITICAL | ||
| Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access. | |||||
| CVE-2026-79686 | 2026-09-02 | N/A | 8.8 HIGH | ||
| Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges. | |||||
| CVE-2026-79683 | 2026-09-02 | N/A | 8.8 HIGH | ||
| Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content to arbitrary filesystem paths. | |||||
| CVE-2026-79682 | 2026-09-02 | N/A | 8.8 HIGH | ||
| Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges. | |||||
