Search

Search Results (390069 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-71626 1 Invoiceninja 1 Invoice Ninja 2026-09-10 7.5 High
An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components
CVE-2026-79391 2026-09-10 9.8 Critical
No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a remote attacker with network access to establish an MQTT session and perform unauthorized publish or subscribe operations.
CVE-2026-52486 2026-09-10 6.6 Medium
An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument module
CVE-2026-77089 1 Commvault 1 Commvault 2026-09-10 N/A
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
CVE-2026-18851 1 Ivanti 1 Endpoint Manager Mobile 2026-09-10 8.8 High
Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.
CVE-2026-12744 1 Ivanti 1 Neurons For Itsm 2026-09-10 9.8 Critical
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
CVE-2026-81401 1 Microsoft 13 365, 365 Apps, Excel and 10 more 2026-09-10 5.5 Medium
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81388 1 Microsoft 18 365, 365 Apps, Excel and 15 more 2026-09-10 7.8 High
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-20512 1 Mediatek, Inc. 1 Mediatek Chipset 2026-09-10 6.7 Medium
In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087540; Issue ID: MSV-8246.
CVE-2026-12650 1 Ivanti 1 Neurons For Itsm 2026-09-10 9.9 Critical
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
CVE-2026-78971 2026-09-10 N/A
In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions.
CVE-2026-79588 2026-09-10 4.3 Medium
U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP.
CVE-2026-83527 1 Ivanti 1 Sentry 2026-09-10 8.1 High
An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.
CVE-2026-12646 1 Ivanti 1 Neurons For Itsm 2026-09-10 9.9 Critical
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
CVE-2026-81391 1 Microsoft 14 365 Apps, Excel, Excel 2016 and 11 more 2026-09-10 5.5 Medium
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81393 1 Microsoft 14 365 Apps, Excel, Excel 2016 and 11 more 2026-09-10 5.5 Medium
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-12745 1 Ivanti 1 Neurons For Itsm 2026-09-10 9.8 Critical
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
CVE-2026-12651 1 Ivanti 1 Neurons For Itsm 2026-09-10 8.8 High
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
CVE-2026-12648 1 Ivanti 1 Neurons For Itsm 2026-09-10 8.8 High
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
CVE-2026-12645 1 Ivanti 1 Neurons For Itsm 2026-09-10 9.9 Critical
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.