Export limit exceeded: 389339 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (389339 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-69598 1 Microsoft 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more 2026-09-08 8.8 High
Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.
CVE-2026-83948 1 Microsoft 1 Azure Cli 2026-09-08 8 High
Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to execute code over a network.
CVE-2026-77897 1 Microsoft 2 Power Automate Agent For Virtual Desktops, Power Automate For Desktop 2026-09-08 7 High
Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
CVE-2026-81393 1 Microsoft 9 365 Apps, Excel 2016, Office 2016 and 6 more 2026-09-08 5.5 Medium
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81353 1 Microsoft 1 Heif Image Extension 2026-09-08 7.8 High
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
CVE-2026-78520 1 Microsoft 8 365 Apps, Office 2019, Office 2021 and 5 more 2026-09-08 6.5 Medium
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-86510 1 D-link 1 Dir-822a 2026-09-08 9.9 Critical
A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2026-86296 1 D-link 1 Dir-822a 2026-09-08 10 Critical
A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-86274 1 Projeto-siga 1 Siga 2026-09-08 5.3 Medium
A security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1. This affects the function ExAutenticacaoController.autenticar of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExAutenticacaoController.java of the component Authentication Flow. Such manipulation of the argument cod/jwt leads to missing authorization. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-85613 1 Openpanel 1 Openpanel 2026-09-08 8.2 High
OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SVG file URL. Attackers can host malicious SVG files with embedded scripts that execute in the victim's browser on the API origin, enabling same-origin credentialed requests to authenticated endpoints.
CVE-2026-85604 1 Getgrav 1 Grav 2026-09-08 8.8 High
Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|reduce, |sort accepts a plain function name inside the sandbox; the remaining denylist misses spl_autoload, which performs a PHP include. An authenticated user with only page-write rights (admin.pages or api.pages.write) can supply a crafted payload (e.g., via form frontmatter rendered by the Email plugin) that invokes spl_autoload through the sort filter, resulting in arbitrary PHP execution as the web server user.
CVE-2026-85599 1 Getgrav 1 Grav 2026-09-08 7.2 High
Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping. Attackers with page-edit access can inject arbitrary HTML and JavaScript that executes in the browsers of all page visitors, including administrators.
CVE-2026-80176 2026-09-08 4.7 Medium
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
CVE-2026-74235 1 Gfi Software 1 Gfi Exinda Ai 2026-09-08 4.9 Medium
GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() function accepts parameters prefixed with v_del_ and appends their values directly to the base configuration directory path without sanitizing for directory traversal sequences. An authenticated attacker with Admin privileges can read arbitrary files from the system in the context of root.
CVE-2026-78457 1 Microsoft 5 Windows 11 24h2, Windows 11 25h2, Windows 11 26h1 and 2 more 2026-09-08 7 High
Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally.
CVE-2026-78451 1 Microsoft 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more 2026-09-08 6.8 Medium
Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-78447 1 Microsoft 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more 2026-09-08 7.8 High
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-78444 1 Microsoft 4 Windows 10 1809, Windows Server 2019, Windows Server 2022 and 1 more 2026-09-08 8.1 High
Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.
CVE-2026-78449 1 Microsoft 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more 2026-09-08 8.1 High
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
CVE-2026-77905 1 Microsoft 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more 2026-09-08 7 High
Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.