Export limit exceeded: 396483 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (396483 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-75721 | 1 Adobe | 1 Campaign Classic | 2026-09-22 | 10 Critical |
| Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. | ||||
| CVE-2026-75728 | 1 Adobe | 1 Campaign Classic | 2026-09-22 | 9.1 Critical |
| Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. | ||||
| CVE-2026-82009 | 1 Adobe | 1 Campaign Classic | 2026-09-22 | 9.1 Critical |
| Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary SQL commands. Exploitation of this issue does not require user interaction. Scope is changed. | ||||
| CVE-2026-83660 | 1 Adobe | 1 Campaign Classic | 2026-09-22 | 9.9 Critical |
| Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed. | ||||
| CVE-2026-69713 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-22 | 4.4 Medium |
| Dependency on vulnerable third-party component in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | ||||
| CVE-2026-94424 | 1 Moore Threads | 1 Mtt S80 Driver Package | 2026-09-22 | 8.8 High |
| A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-95272 | 1 Dgtlmoon | 1 Changedetection.io | 2026-09-22 | 3.7 Low |
| A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affects the function static_content of the file changedetectionio/flask_app.py of the component Screenshot Handler. Performing a manipulation of the argument filename results in path traversal. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-25294 | 1 Qualcomm | 151 Cologne, Cologne Firmware, Congo and 148 more | 2026-09-22 | 7.4 High |
| Transient DOS while parsing frame during channel usage. | ||||
| CVE-2026-25290 | 1 Qualcomm | 15 Cologne, Cologne Firmware, Fastconnect 7800 and 12 more | 2026-09-22 | 7.8 High |
| Memory Corruption when validating large data buffers from external sources using addition to check buffer length. | ||||
| CVE-2026-25284 | 1 Qualcomm | 15 Cologne, Cologne Firmware, Fastconnect 7800 and 12 more | 2026-09-22 | 7.3 High |
| Information Disclosure when a pointer is reused after being deallocated. | ||||
| CVE-2026-25283 | 1 Qualcomm | 15 Cologne, Cologne Firmware, Fastconnect 7800 and 12 more | 2026-09-22 | 8.8 High |
| Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size. | ||||
| CVE-2026-25282 | 1 Qualcomm | 15 Cologne, Cologne Firmware, Fastconnect 7800 and 12 more | 2026-09-22 | 7.9 High |
| Transient DOS when processing unverified data from a neighboring system causes out of bound memory access. | ||||
| CVE-2026-25281 | 1 Qualcomm | 15 Cologne, Cologne Firmware, Fastconnect 7800 and 12 more | 2026-09-22 | 7.4 High |
| Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation. | ||||
| CVE-2026-83419 | 1 Oracle | 1 Communications Cloud Native Core Security Edge Protection Proxy | 2026-09-22 | 5.4 Medium |
| Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as unauthorized read access to a subset of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N). | ||||
| CVE-2026-88593 | 2026-09-22 | 6.1 Medium | ||
| kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes the user-controlled page and kkagent request parameters to FreeMarker templates without sanitization, and the templates insert these values into raw JavaScript contexts. | ||||
| CVE-2026-79079 | 2026-09-22 | 7.8 High | ||
| An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components | ||||
| CVE-2026-88409 | 2026-09-22 | 8.8 High | ||
| FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix function (/v19/decode_matrix.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. | ||||
| CVE-2026-75510 | 1 Novu | 1 Novu | 2026-09-22 | N/A |
| Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu's @novu/js In-App Inbox and the @novu/react Inbox component accept a notification call-to-action redirect.url from the v1 cta.data object and pass it through apps/api/src/app/inbox/utils/notification-mapper.ts and packages/js/src/ui/components/Notification/DefaultNotification.tsx to the navigate function in packages/js/src/ui/context/InboxContext.tsx without validating its URL scheme. An authenticated organization member or environment API-key holder can store a javascript: redirect with target _self in an in-app workflow. When a recipient using a Chromium-based browser clicks the notification, window.open executes the redirect in the current inbox-hosting origin, which can expose session material and permit authenticated actions in a customer application or the self-hosted Novu dashboard. This issue is fixed in version 3.18.0. | ||||
| CVE-2026-76802 | 1 Projectdiscovery | 1 Nuclei | 2026-09-22 | 4.7 Medium |
| Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned code-template signature check before accepting a template that contains both a fuzzing: block and an unsigned code: block. When an operator enables -dast, an untrusted multiprotocol template can place an unsigned code request into the execution queue and run arbitrary shell commands even without -code or a valid cryptographic signature. The issue affects CLI DAST scans and SDK integrations that enable DAST while accepting attacker-supplied templates. This issue is fixed in version 3.10.0. | ||||
| CVE-2026-85288 | 1 Notepad-plus-plus | 1 Notepad++ | 2026-09-22 | 6.7 Medium |
| Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ incompletely enforces shortcuts.xml HMAC validation because WM_MACRODLGRUNMACRO, the Run a Macro Multiple Times entry point, calls macroPlayback() without the validation used by command(). A tampered shortcuts.xml macro that is blocked through the Macro menu or a shortcut key can therefore execute through the multi-run dialog and invoke internal Notepad++ commands, including commands that launch external programs, in the current user context. This issue is fixed in version 8.9.8. | ||||
