Export limit exceeded: 394989 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (394989 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-92014 | 1 Mozilla | 1 Firefox | 2026-09-16 | 8.8 High |
| Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 115.41, Firefox ESR 140.16, and Thunderbird 140.16. | ||||
| CVE-2026-92006 | 1 Mozilla | 1 Firefox | 2026-09-16 | 8.8 High |
| Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. | ||||
| CVE-2026-91742 | 1 Google | 1 Chrome | 2026-09-16 | N/A |
| Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic. (Chromium security severity: Medium) | ||||
| CVE-2026-89156 | 1 Pcre | 1 Pcre2 | 2026-09-16 | 2.9 Low |
| PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data. | ||||
| CVE-2026-69646 | 1 Microsoft | 4 Skype For Business Server, Skype For Business Server 2015, Skype For Business Server 2019 and 1 more | 2026-09-16 | 8.3 High |
| Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network. | ||||
| CVE-2026-69642 | 1 Microsoft | 4 Skype For Business Server, Skype For Business Server 2015, Skype For Business Server 2019 and 1 more | 2026-09-16 | 6.5 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | ||||
| CVE-2026-89157 | 1 Pcre | 1 Pcre2 | 2026-09-16 | 5.7 Medium |
| PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern. | ||||
| CVE-2026-66308 | 1 Microsoft | 4 Skype For Business Server, Skype For Business Server 2015, Skype For Business Server 2019 and 1 more | 2026-09-16 | 6.5 Medium |
| Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. | ||||
| CVE-2026-66307 | 1 Microsoft | 4 Skype For Business Server, Skype For Business Server 2015, Skype For Business Server 2019 and 1 more | 2026-09-16 | 7.5 High |
| Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-66306 | 1 Microsoft | 4 Skype For Business Server, Skype For Business Server 2015, Skype For Business Server 2019 and 1 more | 2026-09-16 | 6.5 Medium |
| Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-66305 | 1 Microsoft | 4 Skype For Business Server, Skype For Business Server 2015, Skype For Business Server 2019 and 1 more | 2026-09-16 | 7.1 High |
| Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network. | ||||
| CVE-2026-89158 | 1 Pcre | 1 Pcre2 | 2026-09-16 | 6.5 Medium |
| PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write. | ||||
| CVE-2026-66304 | 1 Microsoft | 4 Skype For Business Server, Skype For Business Server 2015, Skype For Business Server 2019 and 1 more | 2026-09-16 | 7.5 High |
| Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-66303 | 1 Microsoft | 4 Skype For Business Server, Skype For Business Server 2015, Skype For Business Server 2019 and 1 more | 2026-09-16 | 6.5 Medium |
| Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. | ||||
| CVE-2026-66302 | 1 Microsoft | 4 Skype For Business Server, Skype For Business Server 2015, Skype For Business Server 2019 and 1 more | 2026-09-16 | 9.8 Critical |
| External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-63523 | 1 Microsoft | 4 Skype For Business Server, Skype For Business Server 2015, Skype For Business Server 2019 and 1 more | 2026-09-16 | 6.5 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | ||||
| CVE-2026-92234 | 1 Webkul | 1 Qloapps | 2026-09-16 | 5.4 Medium |
| QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute injected JavaScript in their administrative session via the child_features parameter. | ||||
| CVE-2026-92216 | 1 A2ui-project | 1 A2ui | 2026-09-16 | 4.3 Medium |
| A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component Binder. The manipulation results in open redirect. It is possible to launch the attack remotely. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-92114 | 1 A2ui-project | 1 A2ui | 2026-09-16 | 5.3 Medium |
| A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of the file renderers/web_core/src/v0_9/basic_catalog/functions/safe_regex.ts of the component Basic Catalog. Such manipulation leads to inefficient regular expression complexity. The attack can be launched remotely. | ||||
| CVE-2026-85756 | 2026-09-16 | 7.5 High | ||
| SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into the command used to run scp on the server, and the default RemotePathTransformation.DoubleQuote transformation cannot safely quote every remote command interpreter. When an application passes an attacker-controlled path to a shell-based server, shell metacharacters not neutralized by the active IRemotePathTransformation can execute commands as the authenticated SSH user. Exploitation requires a shell-based server and a path crafted for that shell's parsing rules; non-shell servers and paths fully neutralized by the selected transformation are not affected. RemotePathTransformation.ShellQuote is available for POSIX shells, while SftpClient avoids a remote shell entirely. This issue is fixed in version 2026.0.0. | ||||