Search

Search Results (400096 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-100841 1 Project-monai 1 Monai 2026-09-30 7.8 High
In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) to run torch.load(hashfile, weights_only=False). Related cache helpers in monai/data/utils.py also call pickle.loads on cached content and derive cache keys with hashlib.md5. As a result, a local user with write access to a shared or world-writable cache_dir (e.g. /tmp/monai_cache, HPC scratch, ~/.cache/monai) can place a malicious pickle file that is deserialized the next time another user's MONAI pipeline reads the cache, resulting in arbitrary code execution in that user's context. All released versions of the monai pip package are affected; no patched version is available as of the advisory.
CVE-2026-100257 2026-09-30 4.3 Medium
In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export
CVE-2026-100270 2026-09-30 3.3 Low
In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations
CVE-2026-100271 2026-09-30 2.7 Low
In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects
CVE-2026-100273 2026-09-30 8.2 High
In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution
CVE-2026-100275 2026-09-30 6.9 Medium
In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible
CVE-2025-50343 1 Matio Project 1 Matio 2026-09-30 9.8 Critical
An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the actual number of strings in the fields array. This leads to out-of-bounds reads and invalid memory frees during cleanup, potentially causing a segmentation fault or heap corruption. NOTE: Multiple third-parties note that the available evidence does not demonstrate a vulnerability exploitable through an attacker-controlled input path.
CVE-2026-103399 1 Redhat 1 Enterprise Linux 2026-09-30 5.3 Medium
A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the body is read, the server neither drains the declared body bytes nor closes the connection. On a keep-alive connection, those leftover bytes are interpreted as a subsequent HTTP request. A remote, unauthenticated attacker can place a complete HTTP request in the body and cause SoupServer to process that smuggled request, leading to unintended request handling.
CVE-2026-97265 2026-09-30 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.8.15.3.
CVE-2026-102392 2026-09-30 7.2 High
Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.
CVE-2026-102391 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions.
CVE-2026-102377 2026-09-30 8.8 High
Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.
CVE-2026-102376 2026-09-30 7.1 High
Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions.
CVE-2026-102375 2026-09-30 6.5 Medium
Subscriber Broken Access Control in Optimole <= 4.2.14 versions.
CVE-2026-100512 2026-09-30 9.8 Critical
Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
CVE-2026-100510 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.
CVE-2026-97291 2026-09-30 8.8 High
Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.
CVE-2026-97290 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions.
CVE-2026-97256 2026-09-30 7.2 High
Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.
CVE-2026-94171 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions.