Export limit exceeded: 393724 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (393724 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-87048 1 Tanium 1 Comply 2026-09-16 5.4 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87033 1 Tanium 1 Comply 2026-09-16 5.4 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87030 1 Tanium 1 Comply 2026-09-16 8.5 High
Tanium addressed a path traversal vulnerability in Comply.
CVE-2026-87025 1 Tanium 1 Comply 2026-09-16 5.4 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87817 2 Gitpython-developers, Gitpython Project 2 Gitpython, Gitpython 2026-09-16 8.8 High
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.
CVE-2026-87023 1 Tanium 1 Comply 2026-09-16 8.5 High
Tanium addressed a path traversal vulnerability in Comply.
CVE-2026-87021 1 Tanium 1 Comply 2026-09-16 7.2 High
Tanium addressed an unauthorized code execution vulnerability in Comply.
CVE-2026-61908 2 Cyrus, Cyrusimap 2 Imap, Cyrus Imap 2026-09-16 3.1 Low
An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the end of the internal blob_headers array during download, exposing adjacent heap memory.
CVE-2026-87019 1 Tanium 1 Comply 2026-09-16 4.3 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87047 1 Tanium 1 Comply 2026-09-16 6.3 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-61909 2 Cyrus, Cyrusimap 2 Imap, Cyrus Imap 2026-09-16 3.5 Low
An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT.
CVE-2026-69413 1 Microsoft 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more 2026-09-16 7 High
Use after free in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
CVE-2026-87046 1 Tanium 1 Comply 2026-09-16 4.3 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87037 1 Tanium 1 Comply 2026-09-16 5.4 Medium
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87036 1 Tanium 1 Comply 2026-09-16 8.1 High
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87035 1 Tanium 1 Comply 2026-09-16 4.3 Medium
Tanium addressed an information disclosure vulnerability in Comply.
CVE-2026-61910 2 Cyrus, Cyrusimap 2 Imap, Cyrus Imap 2026-09-16 3.5 Low
An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This could allow the sharee to change the shared mailbox to perform the archived, snoozed, or other role, which might cause mail mail to be written to the shared mailbox, sharing more content than intended. (This is likely to be an unusual situation, made more unusual because if the target already has an non-shared mailbox with that role, role duplication suppression will prevent the update.)
CVE-2026-61911 2 Cyrus, Cyrusimap 2 Imap, Cyrus Imap 2026-09-16 4.3 Medium
An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch fired during LMTP delivery.
CVE-2026-61915 2 Cyrus, Cyrusimap 2 Imap, Cyrus Imap 2026-09-16 4.2 Medium
An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.
CVE-2026-87034 1 Tanium 1 Comply 2026-09-16 8.3 High
Tanium addressed a SQL injection vulnerability in Comply.