Search

Search Results (393166 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-13046 1 Watchguard 1 Fireware Os 2026-09-29 N/A
A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on the appliance to execute arbitrary code in the context of the samld service by causing samld to load a maliciously crafted session file.
CVE-2026-86131 1 Watchguard 1 Fireware Os 2026-09-29 N/A
A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
CVE-2026-13224 1 Watchguard 1 Fireware Os 2026-09-29 N/A
A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request.
CVE-2026-86133 1 Watchguard 1 Fireware Os 2026-09-29 N/A
An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, resulting in a denial of service.
CVE-2026-90441 1 Watchguard 1 Fireware Os 2026-09-29 N/A
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.
CVE-2026-18105 1 Watchguard 1 Fireware Os 2026-09-29 N/A
An uncontrolled resource consumption vulnerability in Fireware OS's diagnostic tasks feature allows a low-privileged, authenticated user to cause a denial of service of the system's diagnostic tools by repeatedly starting and aborting a specially crafted diagnostic task through the web UI.
CVE-2026-86105 1 Watchguard 1 Fireware Os 2026-09-29 N/A
An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.
CVE-2026-86136 1 Watchguard 1 Fireware Os 2026-09-29 N/A
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.
CVE-2026-86132 1 Watchguard 1 Fireware Os 2026-09-29 N/A
An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher suite.
CVE-2026-86128 1 Watchguard 1 Fireware Os 2026-09-29 N/A
A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted IPv6 packet.
CVE-2026-81433 1 Watchguard 1 Fireware Os 2026-09-29 N/A
A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted DHCP packet.
CVE-2026-103048 2026-09-29 N/A
URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - Collection extension allows Fake the Source of Data. This issue affects Mediawiki - Collection extension: before 1.46.1, 1.45.5, 1.43.10.
CVE-2026-95353 1 Google 1 Chrome 2026-09-29 8.8 High
Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95363 1 Google 1 Chrome 2026-09-29 5.4 Medium
UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95354 1 Google 1 Chrome 2026-09-29 8.3 High
Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
CVE-2026-95323 1 Google 1 Chrome 2026-09-29 5.4 Medium
UI misrepresentation in Chromium in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95312 1 Google 1 Chrome 2026-09-29 3.1 Low
Information leak in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-95334 1 Google 1 Chrome 2026-09-29 8.3 High
Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-95319 1 Google 1 Chrome 2026-09-29 8.3 High
Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-95326 1 Google 1 Chrome 2026-09-29 N/A
Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)