Export limit exceeded: 389564 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (389564 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-12855 2026-09-09 8.2 High
Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.
CVE-2026-9216 2026-09-09 3.5 Low
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.
CVE-2026-6485 2026-09-09 8.2 High
UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
CVE-2026-9215 2026-09-09 6.7 Medium
A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.
CVE-2026-19398 1 Asus 2 Fa507nu, Fa507nv 2026-09-09 N/A
An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local  administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the '  Security Update for ASUS FA507NV / FA507NU BIOS   ' section on the ASUS Security Advisory for more information.
CVE-2026-19797 2026-09-09 6.1 Medium
The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_group_section' parameter in all versions up to, and including, 2.3.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVE-2026-77187 2026-09-09 6.4 Medium
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-11814 1 Netgear 52 Be9300, Be9300 Firmware, Mr60 and 49 more 2026-09-09 6.8 Medium
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
CVE-2026-11738 1 Netgear 55 Be9300, Be9300 Firmware, Mr60 and 52 more 2026-09-09 4.4 Medium
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
CVE-2026-9214 1 Netgear 2 R7000, R7000 Firmware 2026-09-09 4.5 Medium
Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
CVE-2026-11739 1 Netgear 54 Mr60, Mr60 Firmware, Mr70 and 51 more 2026-09-09 6.4 Medium
A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.
CVE-2026-11737 1 Netgear 26 Rax20, Rax20 Firmware, Rax41 and 23 more 2026-09-09 4.5 Medium
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality.
CVE-2026-11733 1 Netgear 22 Rax41, Rax41 Firmware, Rax41v2 and 19 more 2026-09-09 4.9 Medium
A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.
CVE-2026-11734 1 Netgear 30 Mr70, Mr70 Firmware, Mr90 and 27 more 2026-09-09 2.7 Low
A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.
CVE-2026-11736 1 Netgear 38 Rax20, Rax20 Firmware, Rax35v2 and 35 more 2026-09-09 4.9 Medium
A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.
CVE-2026-11735 1 Netgear 40 R7000, R7000 Firmware, Rax20 and 37 more 2026-09-09 4.9 Medium
A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.
CVE-2026-15141 1 Tp-link 3 Td-w8961n, Tl-wr820n, Tl-wr820n Firmware 2026-09-09 5.7 Medium
The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic. Successful exploitation may allow an adjacent attacker with access to the web management interface to obtain device configuration details and other sensitive information.
CVE-2026-20504 2 Mediatek, Mediatek, Inc. 39 Mt2735, Mt2735 Firmware, Mt6833 and 36 more 2026-09-09 5.3 Medium
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865.
CVE-2026-20503 2 Mediatek, Mediatek, Inc. 115 Mt2716, Mt2716 Firmware, Mt2735 and 112 more 2026-09-09 5.3 Medium
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01371002; Issue ID: MSV-9020.
CVE-2026-20502 2 Mediatek, Mediatek, Inc. 107 Mt2718, Mt2718 Firmware, Mt6580 and 104 more 2026-09-09 8.4 High
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196.