Export limit exceeded: 389856 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (389856 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-69778 | 1 Microsoft | 8 365 Apps, Access, Access 2016 and 5 more | 2026-09-10 | 8.8 High |
| Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69614 | 1 Microsoft | 6 365 Apps, Access, Access 2016 and 3 more | 2026-09-10 | 8.8 High |
| Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69529 | 1 Microsoft | 7 365 Apps, Access, Access 2016 and 4 more | 2026-09-10 | 8.8 High |
| Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69477 | 1 Microsoft | 7 365 Apps, Access, Access 2016 and 4 more | 2026-09-10 | 7.3 High |
| Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally. | ||||
| CVE-2023-54390 | 1 Pmmp | 1 Pocketmine-mp | 2026-09-10 | 7.5 High |
| PocketMine-MP versions before 5.3.1 and 4.23.1 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper null value handling in arrays. Attackers can send malformed JSON with unexpected null elements in LoginPacket to crash the server. | ||||
| CVE-2025-71418 | 1 Pmmp | 1 Pocketmine-mp | 2026-09-10 | 5.3 Medium |
| PocketMine-MP versions before 5.25.2 fail to limit the explode() function in packet parsing, allowing malicious clients to waste server resources. Attackers can send crafted packets with excessive delimiters to consume CPU and memory through sign editing, JWT parsing, and command parsing endpoints. | ||||
| CVE-2026-22590 | 1 Eprosima | 1 Fast Dds | 2026-09-10 | 9.1 Critical |
| eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Versions prior to 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 have a remotely triggerable Out-of-Bounds Read while processing RTPS `DATA_FRAG` submessages. An attacker can craft a `DATA_FRAG` with a large `sampleSize` but a small actual payload, and set `fragmentsInSubmessage` such that the receiver treats the packet as the LAST fragment**. In this LAST-fragment path, Fast-DDS computes `incoming_length` based on `sampleSize` and calls `memcpy()` without validating `incoming_data.length >= incoming_length`. As a result, `CacheChange_t::add_fragments()` reads past the received UDP datagram buffer and into adjacent heap memory, copying those bytes into the reassembly buffer. In a Discovery Server deployment, the resulting `CacheChange_t` can be relayed to other participants, meaning that a newly joining participant may receive leaked heap memory (e.g., pointer values that could aid ASLR bypass). Versions 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 fix the issue. | ||||
| CVE-2026-47888 | 2 Spring, Vmware | 2 Spring Framework, Spring Framework | 2026-09-10 | 7.5 High |
| A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.0.RELEASE - 5.2.25.RELEASE | ||||
| CVE-2026-47886 | 2 Spring, Vmware | 2 Spring Framework, Spring Framework | 2026-09-10 | 7.5 High |
| Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier | ||||
| CVE-2026-84816 | 2026-09-10 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions. | ||||
| CVE-2026-81804 | 2026-09-10 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions. | ||||
| CVE-2026-81800 | 2026-09-10 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions. | ||||
| CVE-2026-81796 | 2026-09-10 | 7.3 High | ||
| Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions. | ||||
| CVE-2026-81793 | 2026-09-10 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions. | ||||
| CVE-2026-81789 | 2026-09-10 | 8.6 High | ||
| Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce <= 3.1.6 versions. | ||||
| CVE-2026-81786 | 2026-09-10 | 7.5 High | ||
| Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions. | ||||
| CVE-2026-81784 | 2026-09-10 | 8.1 High | ||
| Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions. | ||||
| CVE-2026-81275 | 2026-09-10 | 6.5 Medium | ||
| Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions. | ||||
| CVE-2026-66674 | 2026-09-10 | 5.6 Medium | ||
| Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions. | ||||
| CVE-2026-85310 | 2026-09-10 | 6.5 Medium | ||
| import_contacts Path Traversal in Groundhogg <= 4.7.1 versions. | ||||