Export limit exceeded: 389924 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (389924 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-78519 | 1 Microsoft | 11 365 Apps, Microsoft 365 Apps For Enterprise, Microsoft Office 2016 and 8 more | 2026-09-10 | 8.8 High |
| Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-80096 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-10 | 8.8 High |
| Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-81354 | 1 Microsoft | 15 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 12 more | 2026-09-10 | 8.2 High |
| Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-81385 | 1 Microsoft | 7 365 Apps, Microsoft 365 Apps For Enterprise, Office 2019 and 4 more | 2026-09-10 | 8.8 High |
| Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-81399 | 1 Microsoft | 20 365 Apps, Excel, Excel 2016 and 17 more | 2026-09-10 | 5.5 Medium |
| Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-81956 | 1 Microsoft | 21 365 Apps, Excel, Excel 2016 and 18 more | 2026-09-10 | 7.8 High |
| Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-49883 | 1 Google | 1 Android Wear | 2026-09-10 | N/A |
| In checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-81992 | 3 Adobe, Apple, Microsoft | 7 Acrobat, Acrobat 2024, Acrobat Dc and 4 more | 2026-09-10 | 7.8 High |
| Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||||
| CVE-2026-81987 | 3 Adobe, Apple, Microsoft | 7 Acrobat, Acrobat 2024, Acrobat Dc and 4 more | 2026-09-10 | 7.8 High |
| Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||||
| CVE-2026-79324 | 1 Mageplaza | 2 Gdpr, Module-gdpr | 2026-09-10 | 7.5 High |
| Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by iterating the address id, via a GET request to /customer/address/delete/id/{id}. The controller extends the legacy Action class instead of AbstractAccount, so no authentication, ownership or form key check is enforced. | ||||
| CVE-2026-79322 | 1 Mageplaza | 2 Magento 2 Blog Extension, Mageplaza Blog | 2026-09-10 | 8.6 High |
| SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id parameter to /mpblog/post/view. | ||||
| CVE-2026-79513 | 1 Gpac | 1 Gpac | 2026-09-10 | 6.5 Medium |
| A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640. | ||||
| CVE-2026-87073 | 1 Tanium | 1 Comply | 2026-09-10 | 6.5 Medium |
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87084 | 1 Tanium | 1 Enforce | 2026-09-10 | 7.7 High |
| Tanium addressed a server-side request forgery vulnerability in Enforce. | ||||
| CVE-2026-13359 | 2 Bestweblayout, Wordpress | 2 Contact Form To Db By Bestwebsoft – Messages Database Plugin For Wordpress, Wordpress | 2026-09-10 | 7.2 High |
| The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter in all versions up to, and including, 1.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload executes in the context of an administrator's browser session when they visit the plugin's message manager page at /wp-admin/admin.php?page=cntctfrmtdb_manager, making it possible to compromise administrator-level sessions via a simple unauthenticated contact form submission. | ||||
| CVE-2026-19802 | 2 Stylemix, Wordpress | 2 Checkout Custom Fields Builder For Woocommerce, Wordpress | 2026-09-10 | 4.3 Medium |
| The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to install and activate an arbitrary attacker-hosted plugin, resulting in remote code execution on the server. The required nonce is emitted inline on all admin pages accessible to subscribers when WooCommerce is inactive, meaning any subscriber-level user can harvest it and trigger the exploit without any additional privileges. | ||||
| CVE-2026-14359 | 2 Wordpress, Yith | 2 Wordpress, Yith Woocommerce Waitlist Premium | 2026-09-10 | 8.8 High |
| The YITH WooCommerce Waitlist Premium plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.35.0. This is due to the add_user_in_waiting_list() function registered on the wp_ajax_yith_wcwtl_add_user action being missing both a capability check and a nonce verification, and using parse_str() + extract() to import attacker-controlled variables from $_POST['params'] that are then passed to wp_create_user() and $user->set_role(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator by creating a new user account and assigning it the administrator role. | ||||
| CVE-2026-79617 | 1 Tubitak Bilgem Software Technologies Research Institute | 1 Pardus Lightdm Greeter | 2026-09-10 | 7.1 High |
| Incorrect Permission Assignment for Critical Resource vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus LightDM Greeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pardus LightDM Greeter: before 0.4.15. | ||||
| CVE-2026-87853 | 2 Redhat, Sssd | 4 Enterprise Linux, Openshift, Openshift Container Platform and 1 more | 2026-09-10 | 7.5 High |
| A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP identifier is a strict prefix of a target user's identifier can authenticate as the target user. | ||||
| CVE-2026-87875 | 2 Openprinting, Redhat | 6 Cups, Enterprise Linux, Hardened Images and 3 more | 2026-09-10 | 4.3 Medium |
| The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content. | ||||