Export limit exceeded: 375075 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (375075 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-71215 | 1 Art-template | 1 Art-template | 2026-08-10 | 7.5 High |
| art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and extend template directives, resolves the target file path via path.resolve(root, filename) with no check afterward that the result remains inside root. | ||||
| CVE-2026-71214 | 1 Nasa-ammos | 1 Plandev (sequencing-server) | 2026-08-10 | 9.8 Critical |
| The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession, which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization header's JWT claims, with no verification that the request actually originated from Hasura. | ||||
| CVE-2026-71213 | 1 Typemill | 1 Typemill | 2026-08-10 | 9.1 Critical |
| Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configuration. An unauthenticated attacker can send unlimited password-guessing requests against any account, including administrators, with no throttling. | ||||
| CVE-2026-71212 | 1 Indravoyager | 1 Xidown | 2026-08-10 | 4.4 Medium |
| xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py) by appending the user-provided or scanned URL as a bare trailing positional argument, with no '--' end-of-options marker and no scheme validation anywhere in the codebase. | ||||
| CVE-2026-71211 | 1 Mlflow | 1 Mlflow | 2026-08-10 | 7.1 High |
| MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy endpoint (mlflow/server/gateway_api.py, raw_proxy) subsequently issues an HTTP request to that stored api_base plus a caller-supplied path and returns the full response body. | ||||
| CVE-2026-71210 | 1 Mealie-recipes | 1 Mealie | 2026-08-10 | 5.3 Medium |
| Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the resolved IP against private-range rules, but then issues the actual outbound HTTP request using the original hostname, which the underlying async transport re-resolves independently. | ||||
| CVE-2026-71209 | 1 Advplyr | 1 Audiobookshelf | 2026-08-10 | 7.5 High |
| audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cover or /authors/:id/image shape, where req.path retains %2F sequences URL-encoded. CacheManager.handleCoverCache then joins this decoded value into a cache file path and streams the result before any database-backed ownership check. | ||||
| CVE-2026-71208 | 1 Kubesphere | 1 Kubesphere | 2026-08-10 | 6.5 Medium |
| KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery.ServerVersion against the CRD-specified Kubernetes API endpoint, which is parsed only for URL syntax (url.Parse) with no allow/deny-list for loopback, RFC1918 private ranges, link-local, or cloud-metadata addresses (e.g. 169.254.169.254). | ||||
| CVE-2026-71207 | 1 Swapnilsahu | 1 Stock Management System | 2026-08-10 | 9.8 Critical |
| The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its authentication query by directly concatenating those session values into a SQL statement with no parameterization or escaping. The same script additionally contains hardcoded administrative credentials (admin/neola) in a post-login conditional check, providing a second, independent full-authentication-bypass path. | ||||
| CVE-2026-71206 | 1 Go-shiori | 1 Shiori | 2026-08-10 | 8.2 High |
| Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database. No session store or token-revocation mechanism exists in the codebase. | ||||
| CVE-2026-71205 | 1 Dgtlmoon | 1 Changedetection.io | 2026-08-10 | 6.5 Medium |
| changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting library is present in requirements.txt). | ||||
| CVE-2026-71204 | 1 Dgtlmoon | 1 Changedetection.io | 2026-08-10 | 6.3 Medium |
| changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update. | ||||
| CVE-2026-71203 | 1 Dgtlmoon | 1 Changedetection.io | 2026-08-10 | 5.3 Medium |
| changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get method carries neither @auth.check_token nor @validate_openapi_request. | ||||
| CVE-2026-71202 | 1 Kosinix | 1 Raster | 2026-08-10 | 7.5 High |
| The raster Rust crate's crop function (src/editor.rs) clamps the crop width/height against source dimensions but only clamps the offset_x/offset_y parameters against 0, never against the source width/height. | ||||
| CVE-2026-70378 | 1 Theotherphil | 1 Imagecli | 2026-08-10 | 7.5 High |
| imagecli's pipeline operation (Carve::apply in src/image_ops.rs) only asserts , never validating that the ratio is positive. A negative ratio (e.g. -5) causes the computed target width to saturate to 0 via Rust's defined float-to-uint cast, which is then passed to imageproc::seam_carving::shrink_width — a function that panics when given a width below 2, crashing the process. | ||||
| CVE-2026-70377 | 1 Theotherphil | 1 Imagecli | 2026-08-10 | 7.5 High |
| imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float with no range check. Any application embedding imagecli as a library and accepting user-controlled pipeline strings is remotely crashable with a single request. | ||||
| CVE-2026-70376 | 1 Pluck-cms | 1 Pluckcms | 2026-08-10 | 9.6 Critical |
| Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area. | ||||
| CVE-2026-70375 | 1 Hashbrowncms | 1 Hashbrown Cms | 2026-08-10 | 8.8 High |
| HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec, interpolating the configured branch value directly into a shell command with no escaping. | ||||
| CVE-2026-70374 | 1 Hashbrowncms | 1 Hashbrown Cms | 2026-08-10 | 8.8 High |
| HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail in src/Server/Entity/Resource/Media.js builds a temporary file path as 'thumbnail' + Path.extname(filename) and passes it, unescaped, into a shell command executed via AppService.exec ('convert ' + tempFile + ...). | ||||
| CVE-2026-70373 | 1 Koha-community | 1 Koha | 2026-08-10 | 8.8 High |
| Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-controlled request parameters directly into the SQL string. The PeriodTypeSel, PeriodDaySel, and PeriodMonthSel parameters are interpolated raw into single-quoted equality and function-comparison fragments, and the Filter slots plus the Line and Column identifiers are likewise interpolated with no whitelist and no placeholder binding. | ||||