Export limit exceeded: 389539 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 389539 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (389539 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-40635 | 2026-09-09 | 5.4 Medium | ||
| Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to denial of service and information tampering. | ||||
| CVE-2026-19233 | 2026-09-09 | N/A | ||
| CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized command execution and disclosure of server data when an attacker with a privileged account sends crafted, unvalidated parameters to a server endpoint. | ||||
| CVE-2026-77120 | 2026-09-09 | N/A | ||
| CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause privilege escalation to root and unauthorized execution of administrative functions when an authenticated user with SSH enabled interacts with the operating system console that improperly processes user-controlled input. | ||||
| CVE-2026-87620 | 1 Google | 1 Chrome | 2026-09-09 | 6.5 Medium |
| Observable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-87623 | 1 Google | 1 Chrome | 2026-09-09 | 6.5 Medium |
| Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87474 | 1 Google | 1 Chrome | 2026-09-09 | 9.6 Critical |
| Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-69417 | 1 Microsoft | 1 Sharepoint Server | 2026-09-09 | 7.3 High |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||||
| CVE-2026-87476 | 1 Google | 1 Chrome | 2026-09-09 | 6.5 Medium |
| Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87874 | 1 Redhat | 2 Ceph Storage, Openstack | 2026-09-09 | 8.1 High |
| A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach a network-exposed or shared memcached instance can write a crafted pickle payload that is deserialized and executed on the Ansible controller when the poisoned fact cache is next read, leading to remote code execution. | ||||
| CVE-2026-87823 | 2026-09-09 | 8.2 High | ||
| zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets. Attackers can supply negative offset values near Integer.MIN_VALUE to read unmapped memory, causing JVM termination or extracting arbitrary frame size data from unintended memory locations. | ||||
| CVE-2026-87766 | 1 Redhat | 2 Enterprise Linux, Hummingbird | 2026-09-09 | 8.8 High |
| A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0. | ||||
| CVE-2026-87088 | 2026-09-09 | 7 High | ||
| Tanium addressed an unauthorized code execution vulnerability in Enforce. | ||||
| CVE-2026-87084 | 2026-09-09 | 7.7 High | ||
| Tanium addressed a server-side request forgery vulnerability in Enforce. | ||||
| CVE-2026-87075 | 2026-09-09 | 8.1 High | ||
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87073 | 2026-09-09 | 6.5 Medium | ||
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87072 | 2026-09-09 | 7.1 High | ||
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87048 | 2026-09-09 | 5.4 Medium | ||
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87047 | 2026-09-09 | 6.3 Medium | ||
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87046 | 2026-09-09 | 4.3 Medium | ||
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87037 | 2026-09-09 | 5.4 Medium | ||
| Tanium addressed an improper access controls vulnerability in Comply. | ||||