Export limit exceeded: 380887 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (380887 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-19507 | 2026-08-19 | N/A | ||
| Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause denial of service via excessively large password values. | ||||
| CVE-2026-16825 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-19 | 4.2 Medium |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds write. | ||||
| CVE-2026-76647 | 2026-08-19 | N/A | ||
| Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JSON-RPC dispatcher in app/Domain/Api/Controllers/Jsonrpc.php. The dispatcher does not enforce authorization before invoking service-layer methods, allowing an authenticated user to call methods or act on resources outside their intended permissions. For example, the editOwn method accepts a user-supplied user ID without verifying that it belongs to the caller, allowing an attacker to modify another user's account and set a new password, resulting in account takeover. This vulnerability is distinct from CVE-2026-59712 and CVE-2026-15509 because the root cause is the lack of centralized authorization enforcement in the JSON-RPC dispatcher rather than the behavior of an individual exposed method. | ||||
| CVE-2026-16824 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-19 | 7.5 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to unbounded recursion. | ||||
| CVE-2026-74228 | 2026-08-19 | N/A | ||
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||||
| CVE-2026-74227 | 2026-08-19 | N/A | ||
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||||
| CVE-2026-68899 | 2026-08-19 | 8.7 High | ||
| Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation.js used the Unix file command for content-based MIME detection, but detectMimeFromFile() silently returned undefined when that binary was unavailable and the validation fell back to the attacker-controlled fileObj.type supplied through server/routes/attachmentApi.js. On deployments with WITH_API=true and no file binary, an authenticated board member could label HTML containing JavaScript as image/png, bypass the dangerous MIME check, and store active content under the Wekan origin for execution when another user opened it. Version 9.90 adds looksLikeDangerousMarkup() to inspect file bytes and force dangerous-content scanning when MIME detection is unavailable. This issue is fixed in version 9.90. | ||||
| CVE-2026-74226 | 2026-08-19 | N/A | ||
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||||
| CVE-2026-16822 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-19 | 9.3 Critical |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC policy server and modify traffic due to improper certificate validation. | ||||
| CVE-2026-22306 | 2026-08-19 | 10 Critical | ||
| Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs. This issue affects OZOLS: before 1.1.1233. | ||||
| CVE-2026-33327 | 1 Libvips | 1 Libvips | 2026-08-19 | 7.8 High |
| libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1. | ||||
| CVE-2021-26858 | 1 Microsoft | 1 Exchange Server | 2026-08-19 | 7.8 High |
| Microsoft Exchange Server Remote Code Execution Vulnerability | ||||
| CVE-2021-42292 | 1 Microsoft | 10 365 Apps, Excel, Excel 2013 and 7 more | 2026-08-19 | 7.8 High |
| Microsoft Excel Security Feature Bypass Vulnerability | ||||
| CVE-2021-42287 | 1 Microsoft | 11 Windows Server 2004, Windows Server 2008, Windows Server 2008 R2 and 8 more | 2026-08-19 | 7.5 High |
| Active Directory Domain Services Elevation of Privilege Vulnerability | ||||
| CVE-2021-27065 | 1 Microsoft | 1 Exchange Server | 2026-08-19 | 7.8 High |
| Microsoft Exchange Server Remote Code Execution Vulnerability | ||||
| CVE-2021-27059 | 1 Microsoft | 4 Excel, Office, Office 2013 and 1 more | 2026-08-19 | 7.6 High |
| Microsoft Office Remote Code Execution Vulnerability | ||||
| CVE-2021-26857 | 1 Microsoft | 1 Exchange Server | 2026-08-19 | 7.8 High |
| Microsoft Exchange Server Remote Code Execution Vulnerability | ||||
| CVE-2021-26411 | 1 Microsoft | 17 Edge, Internet Explorer, Windows 10 1507 and 14 more | 2026-08-19 | 8.8 High |
| Internet Explorer Memory Corruption Vulnerability | ||||
| CVE-2020-25576 | 1 Rust-random | 1 Rand | 2026-08-19 | 9.8 Critical |
| An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints. | ||||
| CVE-2026-33328 | 1 Libvips | 1 Libvips | 2026-08-19 | 5.5 Medium |
| libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.18.0, the `gifload` operation could incorrectly determine dimensions leading to an integer overflow. This has been patched in version 8.18.1. | ||||