Export limit exceeded: 393988 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (393988 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-83166 | 1 Oracle | 1 Customer Interaction History | 2026-09-17 | 7.7 High |
| Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Interaction History. While the vulnerability is in Oracle Customer Interaction History, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Customer Interaction History accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N). | ||||
| CVE-2026-92616 | 1 Error311 | 1 Filerise | 2026-09-17 | 6.8 Medium |
| FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session isolation between the WebDAV interface and the web application session context. Attackers can combine valid Basic-Auth credentials with an active admin PHPSESSID cookie to bypass authorization boundaries, as the WebDAV layer incorrectly inherits elevated privileges from an ambient web session rather than enforcing independent stateless authentication per RFC 4918. | ||||
| CVE-2026-25294 | 2026-09-17 | 7.4 High | ||
| Transient DOS while parsing frame during channel usage. | ||||
| CVE-2026-25290 | 2026-09-17 | 7.8 High | ||
| Memory Corruption when validating large data buffers from external sources using addition to check buffer length. | ||||
| CVE-2026-25284 | 2026-09-17 | 7.3 High | ||
| Information Disclosure when a pointer is reused after being deallocated. | ||||
| CVE-2026-25283 | 2026-09-17 | 8.8 High | ||
| Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size. | ||||
| CVE-2026-25282 | 2026-09-17 | 7.9 High | ||
| Transient DOS when processing unverified data from a neighboring system causes out of bound memory access. | ||||
| CVE-2026-25281 | 2026-09-17 | 7.4 High | ||
| Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation. | ||||
| CVE-2026-25280 | 2026-09-17 | 7.8 High | ||
| Memory corruption when processing escape handling flow with insufficient user buffer sizes. | ||||
| CVE-2026-25278 | 2026-09-17 | 7.8 High | ||
| Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying. | ||||
| CVE-2026-25275 | 2026-09-17 | 7.5 High | ||
| Transient DOS when processing authentication frames with invalid FILS information element header lengths. | ||||
| CVE-2026-25261 | 2026-09-17 | 6.7 Medium | ||
| Memory corruption while processing rear sensor IOCTL calls. | ||||
| CVE-2026-24081 | 2026-09-17 | 7.4 High | ||
| Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled. | ||||
| CVE-2026-24075 | 2026-09-17 | 7.8 High | ||
| Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions. | ||||
| CVE-2026-24074 | 2026-09-17 | 7.8 High | ||
| Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations. | ||||
| CVE-2026-24073 | 2026-09-17 | 7.8 High | ||
| Memory corruption when processing decode statistics due to insufficient validation of offset against structure size. | ||||
| CVE-2025-59607 | 2026-09-17 | 7.8 High | ||
| Memory Corruption when copying large input data exceeds normal allocation limits. | ||||
| CVE-2026-50604 | 2026-09-17 | N/A | ||
| A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially allowing access to functionality that should be restricted. | ||||
| CVE-2026-50603 | 2026-09-17 | N/A | ||
| A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions. | ||||
| CVE-2026-83041 | 1 Oracle | 1 Webcenter Portal | 2026-09-17 | 7.7 High |
| Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N). | ||||
