Export limit exceeded: 96568 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (96568 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-78182 | 1 Shenzhen Gongji Technology | 1 Xbrother Dynamic Environment Monitoring System | 2026-08-24 | 7.3 High |
| A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300. The affected element is the function PlanController.getImmediatePlans of the file /xbreport/api/v1/plamange/plansImmediate. The manipulation of the argument order/sort leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. | ||||
| CVE-2026-78170 | 1 Utt | 1 Hiper 1200gw | 2026-08-24 | 8.8 High |
| A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. Executing a manipulation of the argument ssid can lead to buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. | ||||
| CVE-2026-78161 | 1 Warmcat | 1 Libwebsockets | 2026-08-24 | 7.3 High |
| A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as 1d44554a1bb262db63ff4e240152a9deecd99054. It is best practice to apply a patch to resolve this issue. | ||||
| CVE-2026-78157 | 1 Open5gs | 1 Open5gs | 2026-08-24 | 7.4 High |
| A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Request Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. The patch is named c18dc6938bf63cc7374315d3dca303d92066e746. To fix this issue, it is recommended to deploy a patch. | ||||
| CVE-2026-78143 | 1 Code-projects | 1 Barangay Resident Profiling Management System | 2026-08-24 | 7.3 High |
| A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident Search Functionality. This manipulation of the argument Search causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. | ||||
| CVE-2026-4671 | 1 Emilstenstrom | 1 Justhtml | 2026-08-24 | 7.5 High |
| justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selector-based transforms), run selector matching over very large untrusted documents, construct DOM trees from untrusted structure, or enable linkification over attacker-controlled text may consume disproportionate CPU or memory. Triggers include oversized selectors, large selector lists, oversized compound selectors, long combinator chains, deeply nested functional pseudo-classes, repeated token/positional matching, cyclic DOM graphs causing non-terminating traversal, and punctuation-heavy or trailing-bracket linkification input. These are availability-only concerns and do not by themselves allow script execution, data disclosure, or sanitizer bypass. Default JustHTML(sanitize=True) usage is not expected to be exposed, since selectors are normally supplied by application code. | ||||
| CVE-2021-21009 | 3 Adobe, Linux, Microsoft | 3 Campaign, Linux Kernel, Windows | 2026-08-24 | 8.6 High |
| Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Successful exploitation could allow an attacker to use the Campaign instance to issue unauthorized requests to internal or external resources. | ||||
| CVE-2026-66800 | 1 Microsoft | 1 Azure Data Factory | 2026-08-24 | 8.6 High |
| Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-59567 | 1 Zscaler | 1 Client Connector | 2026-08-24 | 8.8 High |
| Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context. | ||||
| CVE-2026-17121 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-24 | 7.5 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled recursion. | ||||
| CVE-2026-16946 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-24 | 7.8 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a heap buffer overflow. | ||||
| CVE-2026-16943 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-24 | 8.2 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a heap-based buffer overflow. | ||||
| CVE-2026-16937 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-24 | 7.8 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management. | ||||
| CVE-2026-16936 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-24 | 8.8 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow. | ||||
| CVE-2026-16934 | 1 Ibm | 3 Aix, Powervm Vios, Vios | 2026-08-24 | 8.8 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a heap-based buffer overflow. | ||||
| CVE-2026-0827 | 1 Lenovo | 3 Diagnostics, Hardware Scan, Vantage | 2026-08-24 | 7.1 High |
| During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file write with elevated privileges. | ||||
| CVE-2026-78317 | 1 Deltaww | 1 Diaenergie | 2026-08-24 | 8.8 High |
| SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | ||||
| CVE-2026-78316 | 1 Deltaww | 1 Diaenergie | 2026-08-24 | 8.8 High |
| SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | ||||
| CVE-2026-78315 | 1 Deltaww | 1 Diaenergie | 2026-08-24 | 8.8 High |
| SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | ||||
| CVE-2026-78314 | 1 Deltaww | 1 Diaenergie | 2026-08-24 | 8.8 High |
| SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | ||||