Export limit exceeded: 25806 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 389515 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (389515 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-21107 | 2026-09-09 | N/A | ||
| Out-of-bounds write in Samsung Notes prior to version 4.4.45.5 allows local attackers to write out-of-bounds memory. | ||||
| CVE-2026-21112 | 2026-09-09 | N/A | ||
| Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege. User interaction is required for triggering this vulnerability. | ||||
| CVE-2026-81646 | 2026-09-09 | 5.9 Medium | ||
| Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2026-81647 | 2026-09-09 | 5.3 Medium | ||
| Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2026-49315 | 2026-09-09 | 7.1 High | ||
| DoS vulnerability in the input device module. Impact: Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2026-41987 | 2026-09-09 | 6.2 Medium | ||
| Permission control vulnerability in the app management module. Impact: Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2026-49309 | 2026-09-09 | 4.8 Medium | ||
| Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||||
| CVE-2026-49313 | 2026-09-09 | 5.5 Medium | ||
| Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||||
| CVE-2026-87736 | 2026-09-09 | 4.3 Medium | ||
| An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points. | ||||
| CVE-2026-21085 | 2026-09-09 | N/A | ||
| Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory. | ||||
| CVE-2026-21086 | 2026-09-09 | N/A | ||
| Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration. | ||||
| CVE-2026-21087 | 2026-09-09 | N/A | ||
| Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege. | ||||
| CVE-2026-87820 | 1 Cyberpanel | 1 Cyberpanel | 2026-09-09 | 5.3 Medium |
| CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated AI Scanner debugging endpoints that disclose administrator usernames, API-key prefixes, scan identifiers, target domains, and account metadata. Unauthenticated attackers can enumerate panel administrators and recent scanner activity to inventory multi-tenant installations and facilitate follow-on attacks. | ||||
| CVE-2026-87819 | 1 Gitpython Project | 1 Gitpython | 2026-09-09 | 7.5 High |
| GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU resources for over two minutes per commit access. | ||||
| CVE-2026-87817 | 1 Gitpython Project | 1 Gitpython | 2026-09-09 | 8.8 High |
| GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository. | ||||
| CVE-2026-87815 | 1 B3log | 1 Siyuan | 2026-09-09 | 8.7 High |
| SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter. An authenticated administrator can supply path traversal sequences to delete arbitrary .deck and .cards files outside the workspace directory. | ||||
| CVE-2026-87814 | 1 B3log | 1 Siyuan | 2026-09-09 | 7.3 High |
| SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset preview feature that fails to escape indexed asset content before inserting it into the DOM using innerHTML. Attackers who can place crafted text assets in a workspace can execute JavaScript in the SiYuan origin when victims preview the assets, enabling authenticated API requests and workspace manipulation. | ||||
| CVE-2026-87812 | 1 B3log | 1 Siyuan | 2026-09-09 | 6.8 Medium |
| SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in Bazaar package cards where the iconURL metadata is inserted directly into HTML img src attributes without escaping. Attackers can inject malicious URLs with event handlers that execute JavaScript in the authenticated SiYuan origin when users view Bazaar listings, enabling API requests and application state manipulation. | ||||
| CVE-2026-87810 | 1 B3log | 1 Siyuan | 2026-09-09 | 5.3 Medium |
| Siyuan before v3.8.2 contains an information disclosure vulnerability in the POST /api/search/fullTextSearchBlock endpoint that filters private blocks from results but returns unfiltered match counts. Unauthenticated publish-mode readers can submit arbitrary search terms to learn whether matching content exists in hidden or unpublished documents and determine the number of matching blocks and pages. | ||||
| CVE-2026-87809 | 1 B3log | 1 Siyuan | 2026-09-09 | 6.5 Medium |
| Siyuan before v3.8.2 fails to apply publish-access filtering to embedded blocks before rendering in the /api/export/preview and /api/lute/copyStdMarkdown endpoints. Attackers with reader access can retrieve the full rendered content of private, hidden, or publish-disabled blocks by accessing public documents containing embed queries that select those blocks. | ||||