Export limit exceeded: 389842 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (389842 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-78837 | 1 Appnitro | 1 Machform | 2026-09-10 | 7.5 High |
| A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 allows attackers to access sensitive database information via a crafted SQL statement. | ||||
| CVE-2026-79571 | 2026-09-10 | 9.1 Critical | ||
| Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cancel orders, and modify categories without authentication. | ||||
| CVE-2026-81957 | 1 Microsoft | 15 365 Apps, Excel, Excel 2016 and 12 more | 2026-09-10 | 7.8 High |
| Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-87491 | 1 Google | 1 Chrome | 2026-09-10 | 8.8 High |
| Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-85384 | 2026-09-10 | N/A | ||
| A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution. Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability. | ||||
| CVE-2026-49883 | 2026-09-10 | N/A | ||
| In checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-20079 | 1 Cisco | 1 Secure Firewall Management Center | 2026-09-10 | 10 Critical |
| A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. | ||||
| CVE-2026-75161 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-10 | 8.8 High |
| An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to inject arbitrary code into the dpcheck system utility executed as root. | ||||
| CVE-2026-75165 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-10 | 6.5 Medium |
| An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to invoke hidden network diagnostic methods (ugw-ping, ugw-traceroute) that are not exposed in the web UI, allowing attackers to obtain sensitive information. | ||||
| CVE-2026-75169 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-10 | 8.8 High |
| An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with Admin role to upload files with arbitrary content to hardcoded paths. | ||||
| CVE-2026-75170 | 1 Hubcore | 1 Hubcore | 2026-09-10 | 6.1 Medium |
| Cross-site scripting (XSS) vulnerability in the /loginController/doLogin endpoint of the HubCore platform (version 14.1.1) allows a remote unauthenticated attacker to inject arbitrary JavaScript into the application's response via the language POST parameter. | ||||
| CVE-2026-79574 | 2026-09-10 | 9.8 Critical | ||
| An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message. | ||||
| CVE-2026-79570 | 2026-09-10 | 9.8 Critical | ||
| mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. | ||||
| CVE-2026-30754 | 2026-09-10 | 8.8 High | ||
| A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encoding process. In the nal_send function in libavformat/rtpenc_h264_hevc.c, a negative size parameter (size=-3) is passed to memcpy when transmitting H.264/HEVC streams via RTP using a crafted input file. This was detected using AddressSanitizer. | ||||
| CVE-2026-78741 | 2026-09-10 | 6.1 Medium | ||
| Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature. | ||||
| CVE-2026-78742 | 2026-09-10 | 6.1 Medium | ||
| Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction. | ||||
| CVE-2026-75438 | 1 Open5gs | 1 Open5gs | 2026-09-10 | 7.5 High |
| Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function | ||||
| CVE-2026-50894 | 1 Zhongshaofa | 1 Easyadmin | 2026-09-10 | 9.8 Critical |
| easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload. | ||||
| CVE-2026-71626 | 1 Invoiceninja | 1 Invoice Ninja | 2026-09-10 | 7.5 High |
| An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components | ||||
| CVE-2026-79391 | 2026-09-10 | 9.8 Critical | ||
| No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a remote attacker with network access to establish an MQTT session and perform unauthorized publish or subscribe operations. | ||||
