Export limit exceeded: 389668 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (389668 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-75170 | 1 Hubcore | 1 Hubcore | 2026-09-10 | 6.1 Medium |
| Cross-site scripting (XSS) vulnerability in the /loginController/doLogin endpoint of the HubCore platform (version 14.1.1) allows a remote unauthenticated attacker to inject arbitrary JavaScript into the application's response via the language POST parameter. | ||||
| CVE-2026-79574 | 2026-09-10 | 9.8 Critical | ||
| An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message. | ||||
| CVE-2026-79570 | 2026-09-10 | 9.8 Critical | ||
| mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. | ||||
| CVE-2026-30754 | 2026-09-10 | 8.8 High | ||
| A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encoding process. In the nal_send function in libavformat/rtpenc_h264_hevc.c, a negative size parameter (size=-3) is passed to memcpy when transmitting H.264/HEVC streams via RTP using a crafted input file. This was detected using AddressSanitizer. | ||||
| CVE-2026-78741 | 2026-09-10 | 6.1 Medium | ||
| Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature. | ||||
| CVE-2026-78742 | 2026-09-10 | 6.1 Medium | ||
| Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction. | ||||
| CVE-2026-75438 | 1 Open5gs | 1 Open5gs | 2026-09-10 | 7.5 High |
| Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function | ||||
| CVE-2026-50894 | 1 Zhongshaofa | 1 Easyadmin | 2026-09-10 | 9.8 Critical |
| easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload. | ||||
| CVE-2026-71626 | 1 Invoiceninja | 1 Invoice Ninja | 2026-09-10 | 7.5 High |
| An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components | ||||
| CVE-2026-79391 | 2026-09-10 | 9.8 Critical | ||
| No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a remote attacker with network access to establish an MQTT session and perform unauthorized publish or subscribe operations. | ||||
| CVE-2026-52486 | 2026-09-10 | 6.6 Medium | ||
| An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument module | ||||
| CVE-2026-77089 | 1 Commvault | 1 Commvault | 2026-09-10 | N/A |
| Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center. | ||||
| CVE-2026-18851 | 1 Ivanti | 1 Endpoint Manager Mobile | 2026-09-10 | 8.8 High |
| Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin. | ||||
| CVE-2026-12744 | 1 Ivanti | 1 Neurons For Itsm | 2026-09-10 | 9.8 Critical |
| A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server. | ||||
| CVE-2026-81401 | 1 Microsoft | 13 365, 365 Apps, Excel and 10 more | 2026-09-10 | 5.5 Medium |
| Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-81388 | 1 Microsoft | 18 365, 365 Apps, Excel and 15 more | 2026-09-10 | 7.8 High |
| Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-20512 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-09-10 | 6.7 Medium |
| In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087540; Issue ID: MSV-8246. | ||||
| CVE-2026-12650 | 1 Ivanti | 1 Neurons For Itsm | 2026-09-10 | 9.9 Critical |
| A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. | ||||
| CVE-2026-15019 | 2026-09-10 | 7.5 High | ||
| The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The product ownership check only verifies that some free, virtual, downloadable product exists on the site — not that the requested file path belongs to that product's configured downloads — making exploitation viable on any WooCommerce site with at least one such product. | ||||
| CVE-2026-14873 | 2026-09-10 | 8 High | ||
| The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their details like arbitrary user passwords, including administrator passwords, to a known plugin-configured custom value, enabling full account takeover of the site. This makes it possible for authenticated attackers, with subscriber-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account. | ||||