CVE.report search for "CVE-2026-92299"
Listed below are 50 relevant search results for "CVE-2026-92299" based on Vendor, Software, and CVE description
These results are gathered from attempted matches with listed vendor and software data, as well as a keyword search in the description of all known CVEs.
If you notice a "Not Listed" in either the vendor or software columns, the underlying source record does not currently include normalized affected-product data.
Search Results
| CVE ID | Vendor | Software | Description |
|---|---|---|---|
| CVE-2026-106586 | In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding ... | ||
| CVE-2026-106505 | Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-nod... | ||
| CVE-2026-106446 | Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() ... | ||
| CVE-2026-106442 | Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate()... | ||
| CVE-2026-106219 | In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading local repositories on the serv... | ||
| CVE-2026-106218 | In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible | ||
| CVE-2026-105747 | Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem... | ||
| CVE-2026-105488 | Missing authorization in the global vault in Devolutions Server 2026.3.7.0 and earlier allows an authenticated user with only... | ||
| CVE-2026-105485 | Authentication bypass OAuth device authorization flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker t... | ||
| CVE-2026-105051 | Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on A... | ||
| CVE-2026-104977 | Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw, an SSRF ... | ||
| CVE-2026-104975 | Plane is an open-source project management tool. Prior to 1.4.0, Plane's dashboard asset endpoints in plane/app/views/asset/v... | ||
| CVE-2026-104973 | Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-30242 validates webhook IP addresses on... | ||
| CVE-2026-104905 | FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that al... | ||
| CVE-2026-104887 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78409. Reason: This candidate is a dupli... | ||
| CVE-2026-104886 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78410. Reason: This candidate is a dupli... | ||
| CVE-2026-104851 | fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.im... | ||
| CVE-2026-104846 | Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 un... | ||
| CVE-2026-104721 | Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerabil... | ||
| CVE-2026-104120 | A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4.... | ||
| CVE-2026-103831 | CVE-2026-103831: Insecure deserialization vulnerability in the Psr16CacheAdapter component of the TrueLayer Magento 2 Plugin,... | ||
| CVE-2026-103512 | Perforce P4 Search prior to 2026.4.2 trusts a client-supplied address when validating certain authentication requests. An a... | ||
| CVE-2026-103511 | Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension installation feature. An attack... | ||
| CVE-2026-103510 | P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affected configurations... | ||
| CVE-2026-103507 | Perforce P4 Search prior to 2026.4.2 does not restrict file paths written through its logging configuration interface. An att... | ||
| CVE-2026-103497 | Jetbrains | Youtrack | In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration |
| CVE-2026-103496 | Jetbrains | Youtrack | In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications |
| CVE-2026-103495 | Jetbrains | Youtrack | In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs |
| CVE-2026-103494 | Jetbrains | Youtrack | In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes |
| CVE-2026-103493 | Jetbrains | Youtrack | In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible |
| CVE-2026-103492 | Jetbrains | Youtrack | In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments |
| CVE-2026-103491 | Jetbrains | Youtrack | In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues |
| CVE-2026-103490 | Jetbrains | Youtrack | In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links |
| CVE-2026-103489 | Jetbrains | Youtrack | In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible |
| CVE-2026-103488 | Jetbrains | Youtrack | In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project team... |
| CVE-2026-103432 | apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi,... | ||
| CVE-2026-103275 | Ghost 5.42.2 before 6.58.0 contains an information disclosure vulnerability in the Admin API bulk post and page edit and dele... | ||
| CVE-2026-103088 | Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix fo... | ||
| CVE-2026-102807 | OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped... | ||
| CVE-2026-102806 | OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that b... | ||
| CVE-2026-102795 | Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 throu... | ||
| CVE-2026-102675 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.... | ||
| CVE-2026-102628 | The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a pu... | ||
| CVE-2026-102510 | Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value ... | ||
| CVE-2026-102509 | Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java i... | ||
| CVE-2026-102422 | shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the ... | ||
| CVE-2026-101894 | The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API r... | ||
| CVE-2026-101884 | OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block... | ||
| CVE-2026-101883 | OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability ... | ||
| CVE-2026-101882 | OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accept... | ||