Export limit exceeded: 381370 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 381370 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381370 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-28150 | 2 Uxper, Wordpress | 2 Golo Framework, Wordpress | 2026-08-20 | 8.1 High |
| Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions. | ||||
| CVE-2026-18102 | 1 Ibm | 1 I | 2026-08-20 | 3.5 Low |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memory due to an integer underflow during bounds checking. | ||||
| CVE-2026-17015 | 1 Ibm | 1 I | 2026-08-20 | 5.4 Medium |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read. | ||||
| CVE-2026-16932 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 8.8 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper validation of the ODMDIR environment variable. | ||||
| CVE-2026-16927 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 7.3 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-check to time-of-use (TOCTOU) race condition. | ||||
| CVE-2026-16925 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 7.1 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to improper authorization. | ||||
| CVE-2026-16924 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 7.5 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory offset during IPsec decapsulation. | ||||
| CVE-2026-16922 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 7 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-check to time-of-use (TOCTOU) race condition. | ||||
| CVE-2026-15706 | 2026-08-20 | 9.8 Critical | ||
| Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142. | ||||
| CVE-2026-14951 | 1 Frauscher Sensortechnik | 1 Fds 102 | 2026-08-20 | 8 High |
| An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages. | ||||
| CVE-2025-36398 | 1 Ibm | 4 Ds8900f, Ds8a00, System Storage Ds8900f and 1 more | 2026-08-20 | 5.4 Medium |
| IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename. | ||||
| CVE-2025-36255 | 1 Ibm | 4 Ds8900f, Ds8a00, System Storage Ds8900f and 1 more | 2026-08-20 | 7.5 High |
| IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a user with privileged user roles due to improper privileged defined with unsafe actions. | ||||
| CVE-2025-36254 | 1 Ibm | 4 Ds8900f, Ds8a00, System Storage Ds8900f and 1 more | 2026-08-20 | 7.4 High |
| IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security authentication due to improperly encoding of DSCLI command output to obtain sensitive information or cause a denial of service. | ||||
| CVE-2025-15688 | 2 Themegoods, Wordpress | 2 Capella, Wordpress | 2026-08-20 | 9.3 Critical |
| Unauthenticated SQL Injection in Capella <= 2.5.5 versions. | ||||
| CVE-2026-56088 | 1 Dell | 1 Openmanage Enterprise | 2026-08-20 | 7.1 High |
| Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. | ||||
| CVE-2026-70424 | 1 Dell | 1 Openmanage Enterprise | 2026-08-20 | 6.5 Medium |
| Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | ||||
| CVE-2026-54117 | 1 Microsoft | 7 Microsoft Sql Server 2025 (cu 2), Microsoft Sql Server 2025 For X64-based Systems (gdr), Sql Server 2016 and 4 more | 2026-08-20 | 9.8 Critical |
| Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-54118 | 1 Microsoft | 15 Microsoft Sql Server 2016 Service Pack 3 (gdr), Microsoft Sql Server 2016 Service Pack 3 Azure Connect Feature Pack, Microsoft Sql Server 2017 (cu 31) and 12 more | 2026-08-20 | 9.8 Critical |
| Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-72845 | 2026-08-20 | N/A | ||
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||||
| CVE-2026-15308 | 1 Python | 2 Cpython, Python | 2026-08-20 | 7.5 High |
| The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data. | ||||