Export limit exceeded: 386275 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 386275 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (386275 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-49509 | 1 Samsung Open Source | 1 Escargot | 2026-09-04 | 4.4 Medium |
| Out-of-bounds read vulnerability in Samsung Opensource Escargot allows Overread Buffers. This issue affects Escargot: 25648aef19187b3f87f4d9420b8d761453ad4630. | ||||
| CVE-2026-51767 | 1 Totolink | 1 T6 | 2026-09-04 | 9.8 Critical |
| Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pairing state and reboot the device via sending a crafted MQTT message to the cs_broker component. | ||||
| CVE-2026-85379 | 1 Light0011 | 1 Cms | 2026-09-04 | 7.3 High |
| A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects the function ChapterModel::searchChapter of the file App/Home/Controller/ChapterController.class.php of the component Query Builder. The manipulation of the argument content results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-67397 | 2026-09-03 | N/A | ||
| Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root. | ||||
| CVE-2026-67402 | 2026-09-03 | N/A | ||
| An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31. | ||||
| CVE-2026-67398 | 2026-09-03 | N/A | ||
| Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions. | ||||
| CVE-2026-85052 | 1 Google | 1 Chrome | 2026-09-03 | 3.1 Low |
| Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-85044 | 1 Google | 1 Chrome | 2026-09-03 | N/A |
| Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-16493 | 1 Redhat | 6 Ansible Automation Platform, Enterprise Linux, Satellite and 3 more | 2026-09-03 | 7.8 High |
| A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when installing collections from git sources. An attacker who provides a crafted collection source URI containing git argument injection payloads can achieve arbitrary command execution when a user runs 'ansible-galaxy collection install' with the malicious source. This is an incomplete fix for CVE-2026-11332, which hardened the role install path but missed the equivalent collection install code path. | ||||
| CVE-2026-11332 | 1 Redhat | 17 Acm, Ansible Automation Platform, Ansible Automation Platform Developer and 14 more | 2026-09-03 | 7.8 High |
| A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install. | ||||
| CVE-2026-64312 | 1 Linux | 1 Linux Kernel | 2026-09-03 | 7.5 High |
| In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - restore callback for non-parallel fallback pcrypt installs pcrypt_aead_done() on the child AEAD request before trying to submit it through padata. If padata_do_parallel() returns -EBUSY, pcrypt falls back to calling the child AEAD directly. That fallback must not keep the padata completion callback. Otherwise an asynchronous completion runs pcrypt_aead_done() even though the request was never enrolled in padata. Restore the original request callback and callback data before calling the child AEAD directly. This keeps the fallback path aligned with a direct AEAD request while leaving the parallel path unchanged. | ||||
| CVE-2026-85378 | 1 Light0011 | 1 Cms | 2026-09-03 | 7.3 High |
| A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function AuthController::_initialize of the file App/Admin/Controller/ChapterController.class.php of the component Chapter Controller. The manipulation leads to authorization bypass. The attack can be initiated remotely. The exploit is publicly available and might be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-62916 | 1 Microsoft | 1 Microsoft Entra Id | 2026-09-03 | 9.1 Critical |
| Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-65818 | 1 Microsoft | 1 Power Platform | 2026-09-03 | 8.5 High |
| Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69857 | 1 Microsoft | 1 Cosmos Db | 2026-09-03 | 8.5 High |
| Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network. | ||||
| CVE-2026-83711 | 1 Microsoft | 1 Azure Active Directory B2c | 2026-09-03 | 10 Critical |
| Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-80098 | 1 Microsoft | 1 Copilot Studio | 2026-09-03 | 9.3 Critical |
| Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-70352 | 1 Microsoft | 1 Azure Ai Language Authoring | 2026-09-03 | 10 Critical |
| Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-70178 | 1 Microsoft | 1 Microsoft Fabric | 2026-09-03 | 8.5 High |
| Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-62906 | 1 Microsoft | 1 Microsoft Discovery Studio | 2026-09-03 | 7.4 High |
| Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network. | ||||