Export limit exceeded: 372323 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 372323 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 372323 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 372323 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372323 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-17661 | 1 Google | 1 Chrome | 2026-07-31 | 8.8 High |
| Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-58066 | 1 Rocket.chat | 1 Rocket.chat | 2026-07-31 | N/A |
| Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity attributes alongside any valid signature made by the trusted IdP certificate, and log in as an arbitrary user. | ||||
| CVE-2026-17948 | 1 Google | 1 Chrome | 2026-07-31 | 7.5 High |
| Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low) | ||||
| CVE-2026-58557 | 1 Huawei | 1 Harmonyos | 2026-07-31 | 4.8 Medium |
| Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2026-58559 | 1 Huawei | 2 Emui, Harmonyos | 2026-07-31 | 6.5 Medium |
| DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2026-59838 | 1 Fortinet | 1 Fortisiem | 2026-07-31 | 5.3 Medium |
| A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.2.0 through 7.2.6, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions, FortiSIEM 6.4 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here> | ||||
| CVE-2026-56687 | 1 Dell | 1 Thinos | 2026-07-31 | 7.8 High |
| Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Feature in UI vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. | ||||
| CVE-2025-45870 | 2026-07-31 | 6.5 Medium | ||
| LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated user to exploit path traversal flaws in the fileExt parameter, enabling unauthorized access to sensitive files outside the designated directories. | ||||
| CVE-2025-45868 | 2026-07-31 | 8.8 High | ||
| LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via crafted input. | ||||
| CVE-2024-32387 | 2026-07-31 | 5.7 Medium | ||
| An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the community string component. | ||||
| CVE-2024-34268 | 2026-07-31 | 7.1 High | ||
| EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connections. This vulnerability allows attackers to gain full access to the device without authentication. | ||||
| CVE-2026-38158 | 2026-07-31 | 9.8 Critical | ||
| A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statements. | ||||
| CVE-2024-32385 | 2026-07-31 | 4.3 Medium | ||
| An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via a boardID and revisionID components | ||||
| CVE-2021-27137 | 1 Dd-wrt | 1 Dd-wrt | 2026-07-31 | 8.1 High |
| An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request). | ||||
| CVE-2026-58221 | 1 Samba | 1 Samba | 2026-07-31 | 8.8 High |
| A flaw was found in Samba Active Directory Domain Controller (AD DC). Improper authorization checks allow an authenticated low-privilege domain user to modify internal LDB special records through LDAP. By altering the DSDB module configuration, an attacker can bypass directory ACL enforcement on new LDAP connections and elevate privileges, potentially leading to complete domain compromise. | ||||
| CVE-2026-6511 | 1 Lenovo | 1 Smart Connect | 2026-07-31 | 5.5 Medium |
| During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated user to access files owned by a different user on the same system. | ||||
| CVE-2026-9046 | 1 Lenovo | 2 App Store, Legion Zone | 2026-07-31 | 7 High |
| A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code. | ||||
| CVE-2026-13103 | 1 Lenovo | 1 App Store | 2026-07-31 | 7.3 High |
| A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code. | ||||
| CVE-2026-13104 | 1 Lenovo | 1 App Store | 2026-07-31 | 7.3 High |
| A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privileges. | ||||
| CVE-2026-14371 | 1 Lenovo | 1 Xclarity Integrator For Microsoft Windows Admin Center | 2026-07-31 | N/A |
| The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands. | ||||