Export limit exceeded: 388850 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 388850 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (388850 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-80231 | 1 Curl | 1 Curl | 2026-09-08 | 7.5 High |
| A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created. | ||||
| CVE-2026-80230 | 1 Curl | 1 Curl | 2026-09-08 | 7.5 High |
| When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected. | ||||
| CVE-2026-80181 | 1 Apache | 1 Allura | 2026-09-08 | 9.1 Critical |
| Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue. | ||||
| CVE-2026-80089 | 1 Microsoft | 8 365 Apps, Office 2016, Office 2019 and 5 more | 2026-09-08 | 6.5 Medium |
| Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-80084 | 1 Microsoft | 5 365 Apps, Office 2016, Office 2019 and 2 more | 2026-09-08 | 6.5 Medium |
| Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-80079 | 1 Microsoft | 5 365 Apps, Office 2019, Office 2021 and 2 more | 2026-09-08 | 6.5 Medium |
| Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-79904 | 2026-09-08 | 5 Medium | ||
| Photoshop Mobile is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||||
| CVE-2026-79721 | 2026-09-08 | N/A | ||
| Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project. | ||||
| CVE-2026-79569 | 2026-09-08 | 9.8 Critical | ||
| Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. | ||||
| CVE-2026-79426 | 1 Crmeb | 1 Crmeb | 2026-09-08 | 7.2 High |
| An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafted POST request. | ||||
| CVE-2026-79376 | 1 Bestechnic | 1 Bes2300 | 2026-09-08 | 8.8 High |
| An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet. | ||||
| CVE-2026-77492 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2026-09-08 | 5.5 Medium |
| Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-75650 | 1 Adobe | 6 Adobe Commerce, Adobe Commerce B2b, Commerce and 3 more | 2026-09-08 | 10 Critical |
| Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. | ||||
| CVE-2026-75156 | 2026-09-08 | 9.1 Critical | ||
| Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are fetched from Microsoft's **multi-tenant** JWKS endpoint, an `id_token` minted in *any* Azure tenant — including one the attacker creates — passes signature verification, and the username and role assignments are then read from that attacker-controlled token. Anyone able to register an Azure tenant can therefore authenticate to the Airflow UI with no prior access to the deployment. The fix for **CVE-2026-59243** was incomplete, and this advisory closes the remaining gap: that fix made the provider verify the `id_token` signature, but did not add issuer or audience checks. Operators who already applied the CVE-2026-59243 fix are **still affected and must upgrade again** — 3.7.3 is the release that shipped that fix, so every version containing it falls inside this affected range. Upgrade to apache-airflow-providers-fab `3.8.1` or later. | ||||
| CVE-2026-72978 | 1 Microsoft | 8 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 5 more | 2026-09-08 | 5.9 Medium |
| Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-72965 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2026-09-08 | 7.8 High |
| Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-72937 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2026-09-08 | 5.5 Medium |
| Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-71341 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2026-09-08 | 5.5 Medium |
| Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-70091 | 1 Microsoft | 8 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 5 more | 2026-09-08 | 5.9 Medium |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-69771 | 1 Microsoft | 4 Windows 11 23h2, Windows 11 24h2, Windows 11 25h2 and 1 more | 2026-09-08 | 4.7 Medium |
| Improper link resolution before file access ('link following') in Windows Container Manager Service allows an authorized attacker to bypass a security feature locally. | ||||
