Base de données CVE
- CVE-2026-3502Élevée7.8
TrueConf Client télécharge le code de mise à jour de l'application et l'applique sans effectuer de vérification. Un attaquant capable d'influencer le chemin de distribution de la mise à jour peut substituer un payload de mise à jour falsifié. Si le payload est exécuté ou installé par le programme de mise à jour, cela peut entraîner une exécution de code arbitraire dans le contexte du processus de mise à jour ou de l'utilisateur.
- CVE-2026-5027Élevée8.8
L'endpoint 'POST /api/v2/files' n'assainit pas le paramètre 'filename' issu des données multipart form data, permettant à un attaquant d'écrire des fichiers dans des emplacements arbitraires du système de fichiers en utilisant des séquences de path traversal ('../').
- CVE-2026-33634Élevée8.8
Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This incident is a continuation of the supply chain attack that began in late February 2026. Following the initial disclosure on March 1, credential rotation was performed but was not atomic (not all credentials were revoked simultaneously). The attacker could have use a valid token to exfiltrate newly rotated secrets during the rotation window (which lasted a few days). This could have allowed the attacker to retain access and execute the March 19 attack. Affected components include the `aquasecurity/trivy` Go / Container image version 0.69.4, the `aquasecurity/trivy-action` GitHub Action versions 0.0.1 – 0.34.2 (76/77), and the`aquasecurity/setup-trivy` GitHub Action versions 0.2.0 – 0.2.6, prior to the recreation of 0.2.6 with a safe commit. Known safe versions include versions 0.69.2 and 0.69.3 of the Trivy binary, version 0.35.0 of trivy-action, and version 0.2.6 of setup-trivy. Additionally, take other mitigations to ensure the safety of secrets. If there is any possibility that a compromised version ran in one's environment, all secrets accessible to affected pipelines must be treated as exposed and rotated immediately. Check whether one's organization pulled or executed Trivy v0.69.4 from any source. Remove any affected artifacts immediately. Review all workflows using `aquasecurity/trivy-action` or `aquasecurity/setup-trivy`. Those who referenced a version tag rather than a full commit SHA should check workflow run logs from March 19–20, 2026 for signs of compromise. Look for repositories named `tpcp-docs` in one's GitHub organization. The presence of such a repository may indicate that the fallback exfiltration mechanism was triggered and secrets were successfully stolen. Pin GitHub Actions to full, immutable commit SHA hashes, don't use mutable version tags.
- CVE-2026-4368
Condition de concurrence dans NetScaler ADC et NetScaler Gateway lorsque l'appliance est configurée en tant que Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) ou serveur virtuel AAA entraînant une confusion des sessions utilisateur
- CVE-2026-3055Critique9.8
Validation insuffisante des entrées dans NetScaler ADC et NetScaler Gateway lorsqu'ils sont configurés comme SAML IDP entraînant une surlecture mémoire
- CVE-2026-33017Critique9.8
Langflow est un outil de création et de déploiement d'agents et de workflows alimentés par l'IA. Dans les versions antérieures à 1.9.0, le endpoint POST /api/v1/build_public_tmp/{flow_id}/flow permet de construire des flux publics sans nécessiter d'authentification. Lorsque le paramètre optionnel data est fourni, le endpoint utilise des données de flux contrôlées par l'attaquant (contenant du code Python arbitraire dans les définitions de nœuds) au lieu des données de flux stockées dans la base de données. Ce code est passé à exec() sans aucun sandboxing, ce qui entraîne une exécution de code à distance non authentifiée. Ceci est distinct de CVE-2025-3248, qui a corrigé /api/v1/validate/code en ajoutant une authentification. Le endpoint build_public_tmp est conçu pour être non authentifié (pour les flux publics) mais accepte à tort des données de flux fournies par l'attaquant contenant du code exécutable arbitraire. Ce problème a été corrigé dans la version 1.9.0.
- CVE-2026-22732Critique9.1
Lorsque les applications spécifient des en-têtes de réponse HTTP pour les applications servlet utilisant Spring Security, il est possible que les HTTP Headers ne soient pas écrits. Ce problème affecte les applications Spring Security Servlet utilisant l'écriture lazy (par défaut) des HTTP Headers : : de 5.7.0 à 5.7.21, de 5.8.0 à 5.8.23, de 6.3.0 à 6.3.14, de 6.4.0 à 6.4.14, de 6.5.0 à 6.5.8, de 7.0.0 à 7.0.3.
- CVE-2026-32194Critique9.8
Neutralisation incorrecte des éléments spéciaux utilisés dans une commande ('command injection') dans Microsoft Bing Images permet à un attaquant non autorisé d'exécuter du code sur un réseau.
- CVE-2026-32191Critique9.8
Neutralisation impropre des éléments spéciaux utilisés dans une commande OS (« OS command injection ») dans Microsoft Bing Images permet à un attaquant non autorisé d'exécuter du code sur un réseau.
- CVE-2026-3910Élevée8.8
Implémentation inappropriée dans V8 dans Google Chrome antérieur à 146.0.7680.75 a permis à un attaquant distant d'exécuter du code arbitraire à l'intérieur d'un bac à sable via une page HTML spécialement conçue. (Gravité de sécurité Chromium : Haute)
- CVE-2026-3909Élevée8.8
Écriture hors limites dans Skia dans Google Chrome avant 146.0.7680.75 a permis à un attaquant distant d'effectuer un accès mémoire hors limites via une page HTML spécialement conçue. (Gravité de sécurité Chromium : Haute)
- CVE-2025-67038Critique9.8
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
- CVE-2026-3545Critique9.6
Validation insuffisante des données dans Navigation dans Google Chrome avant 145.0.7632.159 a permis à un attaquant distant d'effectuer potentiellement une évasion de bac à sable via une page HTML spécialement conçue. (Gravité de sécurité Chromium : Haute)
- CVE-2026-20131Critique10.0
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.
- CVE-2026-20079Critique10.0
Une vulnérabilité dans l'interface web de Cisco Secure Firewall Management Center (FMC) Software pourrait permettre à un attaquant distant non authentifié de contourner l'authentification et d'exécuter des fichiers de script sur un appareil affecté afin d'obtenir un accès root au système d'exploitation sous-jacent. Cette vulnérabilité est due à un processus système inapproprié qui est créé au démarrage. Un attaquant pourrait exploiter cette vulnérabilité en envoyant des requêtes HTTP spécialement conçues à un appareil affecté. Une exploitation réussie pourrait permettre à l'attaquant d'exécuter divers scripts et commandes permettant un accès root à l'appareil.
- CVE-2026-21385Élevée7.8
Memory corruption while using alignments for memory allocation.
- CVE-2026-22719Élevée8.1
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001 Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001
- CVE-2026-20133Moyenne6.5
A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.
- CVE-2026-20128Élevée7.5
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.
- CVE-2026-20127Critique10.0
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
This product uses the NVD API but is not endorsed or certified by the NVD.