Export limit exceeded: 385090 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 385090 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 385090 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (385090 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-81779 | 2026-08-31 | 10 Critical | ||
| Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48. | ||||
| CVE-2026-59289 | 2 Spring, Vmware | 2 Spring For Graphql, Spring For Graphql | 2026-08-31 | 7.5 High |
| Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust application memory or place significant, prolonged load on the underlying datastore, resulting in a Denial of Service. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.2.0 - 1.3.9 | ||||
| CVE-2026-20288 | 1 Cisco | 4 Cisco Unified Computing System E-series Software, Unified Computing System, Unified Computing System E-series Software and 1 more | 2026-08-31 | 6.5 Medium |
| A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root. | ||||
| CVE-2026-81892 | 2026-08-31 | 8.1 High | ||
| EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem::linkToRoute()), swaps the executed controller based on the routeName query parameter on the kernel.controller event. The swap happens after Symfony's security firewall has already evaluated access_control against the original dashboard URL, and the routeName value was not validated. As a result, a path-based access_control rule protecting the target route was never evaluated, so a low-privilege backend user who can reach a single EasyAdmin URL and knows a target route's name can execute that route's controller, bypassing the path-based rule. Only path-based protections are bypassed. Routes whose controller enforces its own authorization with #[IsGranted] or denyAccessUnlessGranted() remain protected because those checks are recomputed against the swapped-in controller. This issue is fixed in versions 4.29.16 and 5.5.1. | ||||
| CVE-2026-82852 | 2026-08-31 | 5.4 Medium | ||
| Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions. | ||||
| CVE-2026-81297 | 2026-08-31 | 7.5 High | ||
| Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions. | ||||
| CVE-2026-81291 | 2026-08-31 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions. | ||||
| CVE-2026-20200 | 1 Cisco | 2 Unified Computing System, Unified Computing System Manager | 2026-08-31 | 8.8 High |
| A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. | ||||
| CVE-2026-82346 | 2026-08-31 | N/A | ||
| A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls. | ||||
| CVE-2026-81891 | 2026-08-31 | 8.1 High | ||
| elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeTypeNormalize(). Because the .phtml, .phar, .php5, and .php3 extensions are absent from mime.types, the staticMimeMap entries that map them to text/x-php are not applied, and allowPutMime() permits extraction even when uploadDeny blocks text/x-php. An attacker with ZIP upload permission can extract PHP-executable files into a web-accessible files/ directory and achieve remote code execution when the server executes those extensions. This issue is fixed in version 2.1.70. | ||||
| CVE-2026-81765 | 2026-08-31 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions. | ||||
| CVE-2026-81764 | 2026-08-31 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions. | ||||
| CVE-2026-81763 | 2026-08-31 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions. | ||||
| CVE-2026-81762 | 2026-08-31 | 6.5 Medium | ||
| Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions. | ||||
| CVE-2026-81758 | 2026-08-31 | 6.3 Medium | ||
| Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions. | ||||
| CVE-2026-81756 | 2026-08-31 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. | ||||
| CVE-2026-81298 | 2026-08-31 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions. | ||||
| CVE-2026-81280 | 2026-08-31 | 6.5 Medium | ||
| Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions. | ||||
| CVE-2026-82909 | 1 Quantumnous | 1 New-api | 2026-08-31 | 4.3 Medium |
| A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler. Executing a manipulation can lead to session expiration. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.0.0-rc.17 can resolve this issue. This patch is called 0d5995eb63f8801d32eb32fbe74b75b68752bfa9. The affected component should be upgraded. | ||||
| CVE-2026-51680 | 1 Totolink | 1 T6 | 2026-08-31 | 9.1 Critical |
| Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | ||||