Export limit exceeded: 376128 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (376128 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-15534 | 1 Leont | 1 Perl | 2026-08-11 | N/A |
| Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it. A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory. | ||||
| CVE-2026-66778 | 1 Sap Se | 1 Sap Business Ai Platform (approuter) | 2026-08-11 | 5.3 Medium |
| SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on integrity and availability. | ||||
| CVE-2026-66779 | 1 Sap Se | 1 Sap Netweaver Application Server For Abap | 2026-08-11 | 6.3 Medium |
| Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed and reflected within the DOM on the client side during page rendering, resulting in the execution of malicious content in the victim's browser context. Successful exploitation could result in a high impact to the confidentiality and a low impact to the integrity of the system, while availability remains unaffected. | ||||
| CVE-2026-58231 | 1 Sap Se | 2 Sap Commerce Cloud Data Hub Adapter, Sap Commerce Cloud Data Hub Adapter | 2026-08-11 | 10 Critical |
| SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application. | ||||
| CVE-2026-72919 | 1 Rocketchat | 1 Rocket.chat | 2026-08-11 | 4.3 Medium |
| Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the channels.convertToTeam REST endpoint allows an authenticated registered user with the create-team permission to convert an unrelated public channel by supplying channelName instead of channelId because the edit-room permission is checked only for channelId. This issue is fixed in versions 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1. | ||||
| CVE-2026-13133 | 1 Ly Corporation | 1 Line For Windows | 2026-08-11 | N/A |
| A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate System32 copy. | ||||
| CVE-2026-12570 | 1 Keras-team | 1 Keras | 2026-08-11 | 5.0 Medium |
| A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving/saving_lib.py does not validate the shape or size of datasets, leading to unbounded memory allocation. A specially crafted .keras file can exploit this flaw to trigger an out-of-memory (OOM) condition, causing the process to be terminated (exit code 137). This issue bypasses the fix for CVE-2026-0897, which only addressed a similar vulnerability in KerasFileEditor. The attack vector includes poisoned models from public repositories or malicious model registries, posing a risk to machine learning pipelines that process untrusted models. | ||||
| CVE-2026-64940 | 1 Nishishi Factory | 1 Tegalog -fumy Otegaru Memo Logger- | 2026-08-11 | 8.6 High |
| Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from the management console. | ||||
| CVE-2026-21075 | 1 Samsung Mobile | 1 My Galaxy | 2026-08-11 | N/A |
| Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information. | ||||
| CVE-2026-21081 | 1 Samsung Mobile | 1 Samsungpassautofill | 2026-08-11 | N/A |
| Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability. | ||||
| CVE-2026-66403 | 1 Ecovacs Robotics | 2 Deebot Pro K1vac, Deebot Pro M1 | 2026-08-11 | 7.5 High |
| DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved. | ||||
| CVE-2026-66404 | 1 Ecovacs Robotics | 2 Deebot Pro K1vac, Deebot Pro M1 | 2026-08-11 | 6.5 Medium |
| DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affected products may be retrieved. | ||||
| CVE-2026-66405 | 1 Ecovacs Robotics | 2 Deebot Pro K1vac, Deebot Pro M1 | 2026-08-11 | 8.8 High |
| DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products. | ||||
| CVE-2026-66406 | 1 Ecovacs Robotics | 2 Deebot Pro K1vac, Deebot Pro M1 | 2026-08-11 | 4.8 Medium |
| DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be executed with the administrative privilege. | ||||
| CVE-2026-66407 | 1 Ecovacs Robotics | 2 Deebot Pro K1vac, Deebot Pro M1 | 2026-08-11 | 8.1 High |
| DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered. | ||||
| CVE-2026-66408 | 1 Ecovacs Robotics | 2 Deebot Pro K1vac, Deebot Pro M1 | 2026-08-11 | 4.6 Medium |
| The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affected product may allow to obtain the password of the root account. | ||||
| CVE-2026-66409 | 1 Ecovacs Robotics | 2 Deebot Pro K1vac, Deebot Pro M1 | 2026-08-11 | 5.3 Medium |
| DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to connect to the access point of an affected robot. | ||||
| CVE-2026-66410 | 1 Ecovacs Robotics | 2 Android App "ecovacs Pro", Ios App "ecovacs Pro" | 2026-08-11 | 4.8 Medium |
| Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or altered. | ||||
| CVE-2026-66411 | 1 Ecovacs Robotics | 2 Deebot Pro K1vac, Deebot Pro M1 | 2026-08-11 | 5.3 Medium |
| DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unauthenticated attacker may connect and operate the affected robot. | ||||
| CVE-2026-19404 | 1 Redhat | 3 Directory Server, Enterprise Linux, Redhat Directory Server | 2026-08-11 | 6.5 Medium |
| A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to invoke them otherwise. This allows removal of a replica ID from replication metadata, purging of changelog records, and interruption of administrator-initiated cleanup, which can leave replication inconsistent or unavailable. | ||||