Export limit exceeded: 390035 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (390035 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-59691 | 2 Gstreamer, Redhat | 9 Gstreamer, Enterprise Linux, Enterprise Linux Eus and 6 more | 2026-09-10 | 7.1 High |
| A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption. | ||||
| CVE-2026-80091 | 1 Microsoft | 17 365 Apps, Microsoft 365, Microsoft 365 Apps For Enterprise and 14 more | 2026-09-10 | 6.5 Medium |
| Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-59692 | 2 Gstreamer, Redhat | 9 Gstreamer, Enterprise Linux, Enterprise Linux Eus and 6 more | 2026-09-10 | 7.5 High |
| A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service. | ||||
| CVE-2026-88005 | 2026-09-10 | 6.5 Medium | ||
| Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allowlist that the normal OAuth login callback enforces. An account whose email domain the login callback would refuse could still obtain a working session through this endpoint. This issue is fixed in version 0.9.0. | ||||
| CVE-2026-81986 | 3 Adobe, Apple, Microsoft | 5 Acrobat, Acrobat Dc, Acrobat Reader Dc and 2 more | 2026-09-10 | 7.8 High |
| Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||||
| CVE-2026-69778 | 1 Microsoft | 8 365 Apps, Access, Access 2016 and 5 more | 2026-09-10 | 8.8 High |
| Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69529 | 1 Microsoft | 7 365 Apps, Access, Access 2016 and 4 more | 2026-09-10 | 8.8 High |
| Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69477 | 1 Microsoft | 7 365 Apps, Access, Access 2016 and 4 more | 2026-09-10 | 7.3 High |
| Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally. | ||||
| CVE-2023-54390 | 1 Pmmp | 1 Pocketmine-mp | 2026-09-10 | 7.5 High |
| PocketMine-MP versions before 5.3.1 and 4.23.1 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper null value handling in arrays. Attackers can send malformed JSON with unexpected null elements in LoginPacket to crash the server. | ||||
| CVE-2025-71418 | 1 Pmmp | 1 Pocketmine-mp | 2026-09-10 | 5.3 Medium |
| PocketMine-MP versions before 5.25.2 fail to limit the explode() function in packet parsing, allowing malicious clients to waste server resources. Attackers can send crafted packets with excessive delimiters to consume CPU and memory through sign editing, JWT parsing, and command parsing endpoints. | ||||
| CVE-2026-22590 | 1 Eprosima | 1 Fast Dds | 2026-09-10 | 9.1 Critical |
| eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Versions prior to 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 have a remotely triggerable Out-of-Bounds Read while processing RTPS `DATA_FRAG` submessages. An attacker can craft a `DATA_FRAG` with a large `sampleSize` but a small actual payload, and set `fragmentsInSubmessage` such that the receiver treats the packet as the LAST fragment**. In this LAST-fragment path, Fast-DDS computes `incoming_length` based on `sampleSize` and calls `memcpy()` without validating `incoming_data.length >= incoming_length`. As a result, `CacheChange_t::add_fragments()` reads past the received UDP datagram buffer and into adjacent heap memory, copying those bytes into the reassembly buffer. In a Discovery Server deployment, the resulting `CacheChange_t` can be relayed to other participants, meaning that a newly joining participant may receive leaked heap memory (e.g., pointer values that could aid ASLR bypass). Versions 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 fix the issue. | ||||
| CVE-2026-47888 | 2 Spring, Vmware | 2 Spring Framework, Spring Framework | 2026-09-10 | 7.5 High |
| A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.0.RELEASE - 5.2.25.RELEASE | ||||
| CVE-2026-47886 | 2 Spring, Vmware | 2 Spring Framework, Spring Framework | 2026-09-10 | 7.5 High |
| Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier | ||||
| CVE-2026-84816 | 2026-09-10 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions. | ||||
| CVE-2026-81800 | 2026-09-10 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions. | ||||
| CVE-2026-81793 | 2026-09-10 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions. | ||||
| CVE-2026-81786 | 2026-09-10 | 7.5 High | ||
| Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions. | ||||
| CVE-2026-81275 | 2026-09-10 | 6.5 Medium | ||
| Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions. | ||||
| CVE-2026-47887 | 2 Spring, Vmware | 2 Spring Framework, Spring Framework | 2026-09-10 | 6.1 Medium |
| A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier | ||||
| CVE-2026-88069 | 1 Pandora-analysis | 1 Pandora | 2026-09-10 | N/A |
| Pandora contains a path traversal vulnerability in its archive extraction worker. When processing a specially crafted archive or disk image, attacker-controlled file paths could be used without ensuring that the resulting destination remained within the intended extraction directory. An attacker able to submit a malicious file for analysis could use path traversal sequences or crafted paths to cause extracted content to be written outside the designated extraction directory, potentially overwriting files accessible to the Pandora worker process. Successful exploitation could result in unauthorized modification of application or system files, denial of service, and potentially further compromise depending on the permissions of the Pandora process and the files that can be overwritten. The vulnerability is addressed by resolving each extraction destination path before writing and verifying that it remains below the expected extraction directory. Extraction attempts resolving outside this directory are rejected and reported as path traversal attempts. | ||||