Search

Search Results (389560 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-69417 1 Microsoft 1 Sharepoint Server 2026-09-09 7.3 High
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-87476 1 Google 1 Chrome 2026-09-09 6.5 Medium
Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87874 1 Redhat 2 Ceph Storage, Openstack 2026-09-09 8.1 High
A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach a network-exposed or shared memcached instance can write a crafted pickle payload that is deserialized and executed on the Ansible controller when the poisoned fact cache is next read, leading to remote code execution.
CVE-2026-87823 2026-09-09 8.2 High
zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets. Attackers can supply negative offset values near Integer.MIN_VALUE to read unmapped memory, causing JVM termination or extracting arbitrary frame size data from unintended memory locations.
CVE-2026-87766 1 Redhat 2 Enterprise Linux, Hummingbird 2026-09-09 8.8 High
A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0.
CVE-2026-87088 2026-09-09 7 High
Tanium addressed an unauthorized code execution vulnerability in Enforce.
CVE-2026-87084 2026-09-09 7.7 High
Tanium addressed a server-side request forgery vulnerability in Enforce.
CVE-2026-87075 2026-09-09 8.1 High
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87073 2026-09-09 6.5 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87072 2026-09-09 7.1 High
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87048 2026-09-09 5.4 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87047 2026-09-09 6.3 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87046 2026-09-09 4.3 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87037 2026-09-09 5.4 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87036 2026-09-09 8.1 High
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87035 2026-09-09 4.3 Medium
Tanium addressed an information disclosure vulnerability in Comply.
CVE-2026-87034 2026-09-09 8.3 High
Tanium addressed a SQL injection vulnerability in Comply.
CVE-2026-87033 2026-09-09 5.4 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87032 2026-09-09 4.3 Medium
Tanium addressed an information disclosure vulnerability in Tanium Server.
CVE-2026-87030 2026-09-09 8.5 High
Tanium addressed a path traversal vulnerability in Comply.