Vulnerabilities (CVE)

Total 397439 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-61758 1 Nvidia 1 Nemo Megatron Bridge 2026-09-02 N/A 7.8 HIGH
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-61759 1 Nvidia 1 Nemo Megatron Bridge 2026-09-02 N/A 7.8 HIGH
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVE-2026-66758 2 Gimp, Redhat 2 Gimp, Enterprise Linux 2026-09-02 N/A 7.8 HIGH
A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.
CVE-2026-58380 2 Gimp, Redhat 2 Gimp, Enterprise Linux 2026-09-02 N/A 7.3 HIGH
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
CVE-2026-84218 2026-09-02 N/A 8.1 HIGH
A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolokia POST request and passes it to `JMXServiceURL` and `JMXConnectorFactory` for establishing the remote JMX connection. The existing denylist only rejects URLs matching `service:jmx:rmi:///jndi/ldap:.*`, which can be bypassed using alternative valid JMX service URL forms, including `ldaps://` schemes or LDAP URLs with a non-empty JMX host component. These URLs are accepted as valid `JMXServiceURL` objects and can cause the Jolokia agent JVM to perform a JNDI lookup against an attacker-controlled LDAP endpoint. This can result in server-side request forgery (SSRF), forwarding of supplied JMX credentials to the remote endpoint, and potentially remote code execution depending on the classes and configuration available in the target JVM.
CVE-2026-59691 2026-09-02 N/A 7.1 HIGH
A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption.
CVE-2026-4378 2026-09-02 N/A 5.4 MEDIUM
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Software Technologies Ltd. E-Commerce Pack allows Stored XSS. This issue affects E-Commerce Pack: from 4.5.001 before 4.6.001.
CVE-2026-23591 2026-09-02 N/A N/A
Rejected reason: Withdrawn by requester.
CVE-2026-23590 2026-09-02 N/A N/A
Rejected reason: Withdrawn by requester.
CVE-2026-23589 2026-09-02 N/A N/A
Rejected reason: Withdrawn by requester.
CVE-2026-23588 2026-09-02 N/A N/A
Rejected reason: Withdrawn by requester.
CVE-2026-23587 2026-09-02 N/A N/A
Rejected reason: Withdrawn by requester.
CVE-2026-23586 2026-09-02 N/A N/A
Rejected reason: Withdrawn by requester.
CVE-2026-23585 2026-09-02 N/A N/A
Rejected reason: Withdrawn by requester.
CVE-2026-23584 2026-09-02 N/A N/A
Rejected reason: Withdrawn by requester.
CVE-2026-23583 2026-09-02 N/A N/A
Rejected reason: Withdrawn by requester.
CVE-2026-79687 2026-09-02 N/A 9.0 CRITICAL
Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access.
CVE-2026-79686 2026-09-02 N/A 8.8 HIGH
Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges.
CVE-2026-79683 2026-09-02 N/A 8.8 HIGH
Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content to arbitrary filesystem paths.
CVE-2026-79682 2026-09-02 N/A 8.8 HIGH
Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.