Export limit exceeded: 376110 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 376110 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (376110 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-71993 | 1 Msi | 1 Radix Axe6600 | 2026-08-11 | 9.8 Critical |
| MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system. | ||||
| CVE-2026-66774 | 1 Sap Se | 1 Sap Business Ai Platform (approuter) | 2026-08-11 | 3.7 Low |
| SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly complex, as it depends on conditions outside the attacker's control. This could result in a low impact on availability. There is no impact on confidentiality and integrity. | ||||
| CVE-2026-66775 | 1 Sap Se | 1 Sap Business Ai Platform (approuter) | 2026-08-11 | 4.3 Medium |
| SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link and trick a victim into following it. Successful exploitation could allow the attacker to bind the victim's session to an attacker-controlled identity, resulting in a low impact on integrity. There is no impact on confidentiality and availability. | ||||
| CVE-2026-20187 | 1 Cisco | 3 Cisco Roomos Software, Roomos, Roomos Cloud | 2026-08-11 | 7.5 High |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20187 are related to improper handling of exceptional conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-703. | ||||
| CVE-2026-66776 | 1 Sap Se | 1 Sap Business Ai Platform (approuter) | 2026-08-11 | 5.9 Medium |
| SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack complex to execute. This could result in a high impact on confidentiality and a low impact on integrity. There is no impact on availability. | ||||
| CVE-2026-66777 | 1 Sap Se | 1 Sap Business Ai Platform (approuter) | 2026-08-11 | 5.9 Medium |
| SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the required conditions, an attacker with low privileges could send specially crafted requests to bypass authorization checks and reach protected resources beyond their assigned scope. Successful exploitation could allow the attacker to read sensitive data and perform limited modifications on protected resources, resulting in a high impact on confidentiality and a low impact on integrity. There is no impact on availability. | ||||
| CVE-2026-15534 | 1 Leont | 1 Perl | 2026-08-11 | N/A |
| Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it. A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory. | ||||
| CVE-2026-66778 | 1 Sap Se | 1 Sap Business Ai Platform (approuter) | 2026-08-11 | 5.3 Medium |
| SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on integrity and availability. | ||||
| CVE-2026-66779 | 1 Sap Se | 1 Sap Netweaver Application Server For Abap | 2026-08-11 | 6.3 Medium |
| Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed and reflected within the DOM on the client side during page rendering, resulting in the execution of malicious content in the victim's browser context. Successful exploitation could result in a high impact to the confidentiality and a low impact to the integrity of the system, while availability remains unaffected. | ||||
| CVE-2026-58231 | 1 Sap Se | 2 Sap Commerce Cloud Data Hub Adapter, Sap Commerce Cloud Data Hub Adapter | 2026-08-11 | 10 Critical |
| SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application. | ||||
| CVE-2026-72919 | 1 Rocketchat | 1 Rocket.chat | 2026-08-11 | 4.3 Medium |
| Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the channels.convertToTeam REST endpoint allows an authenticated registered user with the create-team permission to convert an unrelated public channel by supplying channelName instead of channelId because the edit-room permission is checked only for channelId. This issue is fixed in versions 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1. | ||||
| CVE-2026-13133 | 1 Ly Corporation | 1 Line For Windows | 2026-08-11 | N/A |
| A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate System32 copy. | ||||
| CVE-2026-12570 | 1 Keras-team | 1 Keras | 2026-08-11 | 5.0 Medium |
| A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving/saving_lib.py does not validate the shape or size of datasets, leading to unbounded memory allocation. A specially crafted .keras file can exploit this flaw to trigger an out-of-memory (OOM) condition, causing the process to be terminated (exit code 137). This issue bypasses the fix for CVE-2026-0897, which only addressed a similar vulnerability in KerasFileEditor. The attack vector includes poisoned models from public repositories or malicious model registries, posing a risk to machine learning pipelines that process untrusted models. | ||||
| CVE-2026-64940 | 1 Nishishi Factory | 1 Tegalog -fumy Otegaru Memo Logger- | 2026-08-11 | 8.6 High |
| Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from the management console. | ||||
| CVE-2026-21075 | 1 Samsung Mobile | 1 My Galaxy | 2026-08-11 | N/A |
| Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information. | ||||
| CVE-2026-21081 | 1 Samsung Mobile | 1 Samsungpassautofill | 2026-08-11 | N/A |
| Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability. | ||||
| CVE-2026-66403 | 1 Ecovacs Robotics | 2 Deebot Pro K1vac, Deebot Pro M1 | 2026-08-11 | 7.5 High |
| DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved. | ||||
| CVE-2026-66404 | 1 Ecovacs Robotics | 2 Deebot Pro K1vac, Deebot Pro M1 | 2026-08-11 | 6.5 Medium |
| DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affected products may be retrieved. | ||||
| CVE-2026-66405 | 1 Ecovacs Robotics | 2 Deebot Pro K1vac, Deebot Pro M1 | 2026-08-11 | 8.8 High |
| DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products. | ||||
| CVE-2026-66406 | 1 Ecovacs Robotics | 2 Deebot Pro K1vac, Deebot Pro M1 | 2026-08-11 | 4.8 Medium |
| DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be executed with the administrative privilege. | ||||