Export limit exceeded: 385178 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (385178 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-83596 | 1 Redhat | 1 Enterprise Linux | 2026-08-31 | 8.8 High |
| A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling. | ||||
| CVE-2026-59287 | 2 Spring, Vmware | 2 Spring For Graphql, Spring For Graphql | 2026-08-31 | 5.9 Medium |
| Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive enabled. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.3.0 - 1.3.9 | ||||
| CVE-2026-51368 | 2026-08-31 | 9.8 Critical | ||
| An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a remote attacker to execute arbitrary code via a crafted request to the console/heimdall endpoint | ||||
| CVE-2026-30063 | 1 Free5gc | 1 Free5gc | 2026-08-31 | 7.5 High |
| An issue in the NF Discovery endpoint of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted snssais query. | ||||
| CVE-2026-30070 | 1 Free5gc | 1 Free5gc | 2026-08-31 | 7.5 High |
| An issue in the HandleGetSharedData function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | ||||
| CVE-2026-59288 | 2 Spring, Vmware | 2 Spring For Graphql, Spring For Graphql | 2026-08-31 | 7.4 High |
| The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7 | ||||
| CVE-2026-81779 | 2026-08-31 | 10 Critical | ||
| Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48. | ||||
| CVE-2026-20288 | 1 Cisco | 4 Cisco Unified Computing System E-series Software, Unified Computing System, Unified Computing System E-series Software and 1 more | 2026-08-31 | 6.5 Medium |
| A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root. | ||||
| CVE-2026-81892 | 2026-08-31 | 8.1 High | ||
| EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem::linkToRoute()), swaps the executed controller based on the routeName query parameter on the kernel.controller event. The swap happens after Symfony's security firewall has already evaluated access_control against the original dashboard URL, and the routeName value was not validated. As a result, a path-based access_control rule protecting the target route was never evaluated, so a low-privilege backend user who can reach a single EasyAdmin URL and knows a target route's name can execute that route's controller, bypassing the path-based rule. Only path-based protections are bypassed. Routes whose controller enforces its own authorization with #[IsGranted] or denyAccessUnlessGranted() remain protected because those checks are recomputed against the swapped-in controller. This issue is fixed in versions 4.29.16 and 5.5.1. | ||||
| CVE-2026-20200 | 1 Cisco | 2 Unified Computing System, Unified Computing System Manager | 2026-08-31 | 8.8 High |
| A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. | ||||
| CVE-2026-82346 | 2026-08-31 | N/A | ||
| A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls. | ||||
| CVE-2026-81891 | 2026-08-31 | 8.1 High | ||
| elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeTypeNormalize(). Because the .phtml, .phar, .php5, and .php3 extensions are absent from mime.types, the staticMimeMap entries that map them to text/x-php are not applied, and allowPutMime() permits extraction even when uploadDeny blocks text/x-php. An attacker with ZIP upload permission can extract PHP-executable files into a web-accessible files/ directory and achieve remote code execution when the server executes those extensions. This issue is fixed in version 2.1.70. | ||||
| CVE-2026-81765 | 2026-08-31 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions. | ||||
| CVE-2026-81764 | 2026-08-31 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions. | ||||
| CVE-2026-81763 | 2026-08-31 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions. | ||||
| CVE-2026-81762 | 2026-08-31 | 6.5 Medium | ||
| Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions. | ||||
| CVE-2026-81758 | 2026-08-31 | 6.3 Medium | ||
| Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions. | ||||
| CVE-2026-81756 | 2026-08-31 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. | ||||
| CVE-2026-81298 | 2026-08-31 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions. | ||||
| CVE-2026-81280 | 2026-08-31 | 6.5 Medium | ||
| Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions. | ||||