Export limit exceeded: 395618 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (395618 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-78741 | 2026-09-10 | 6.1 Medium | ||
| Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature. | ||||
| CVE-2026-78742 | 2026-09-10 | 6.1 Medium | ||
| Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction. | ||||
| CVE-2026-75438 | 1 Open5gs | 1 Open5gs | 2026-09-10 | 7.5 High |
| Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function | ||||
| CVE-2026-50894 | 1 Zhongshaofa | 1 Easyadmin | 2026-09-10 | 9.8 Critical |
| easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload. | ||||
| CVE-2026-71626 | 1 Invoiceninja | 1 Invoice Ninja | 2026-09-10 | 7.5 High |
| An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components | ||||
| CVE-2026-79391 | 2026-09-10 | 9.8 Critical | ||
| No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a remote attacker with network access to establish an MQTT session and perform unauthorized publish or subscribe operations. | ||||
| CVE-2026-52486 | 2026-09-10 | 6.6 Medium | ||
| An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument module | ||||
| CVE-2026-18851 | 1 Ivanti | 1 Endpoint Manager Mobile | 2026-09-10 | 8.8 High |
| Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin. | ||||
| CVE-2026-81401 | 1 Microsoft | 13 365, 365 Apps, Excel and 10 more | 2026-09-10 | 5.5 Medium |
| Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-81388 | 1 Microsoft | 18 365, 365 Apps, Excel and 15 more | 2026-09-10 | 7.8 High |
| Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-20512 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-09-10 | 6.7 Medium |
| In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087540; Issue ID: MSV-8246. | ||||
| CVE-2026-79588 | 2026-09-10 | 4.3 Medium | ||
| U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP. | ||||
| CVE-2026-83527 | 1 Ivanti | 1 Sentry | 2026-09-10 | 8.1 High |
| An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access. | ||||
| CVE-2026-81391 | 1 Microsoft | 14 365 Apps, Excel, Excel 2016 and 11 more | 2026-09-10 | 5.5 Medium |
| Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-81393 | 1 Microsoft | 14 365 Apps, Excel, Excel 2016 and 11 more | 2026-09-10 | 5.5 Medium |
| Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-78512 | 1 Microsoft | 12 365 Apps, Microsoft 365, Microsoft Office Ltsc For Mac 2021 and 9 more | 2026-09-10 | 8.8 High |
| Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-68878 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2026-09-10 | 8 High |
| Stack-based buffer overflow in Windows Fast FAT Driver allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69279 | 1 Microsoft | 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more | 2026-09-10 | 7 High |
| Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69734 | 1 Microsoft | 12 365, 365 Apps, Microsoft 365 and 9 more | 2026-09-10 | 6.5 Medium |
| Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-17084 | 1 Python | 1 Cpython | 2026-09-10 | N/A |
| The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0. | ||||