Export limit exceeded: 387392 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (387392 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-50628 | 1 Apache | 1 Cxf | 2026-08-07 | 9.8 Critical |
| A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue. | ||||
| CVE-2026-50627 | 1 Apache | 1 Cxf | 2026-08-07 | 9.1 Critical |
| The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue. | ||||
| CVE-2026-50623 | 1 Apache | 1 Cxf | 2026-08-07 | 4.8 Medium |
| An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated network attacker. However note that this is a safeguard only in the case that someone forgot to enable authentication on the service. Users are recommended to upgrade to version 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue. | ||||
| CVE-2026-49875 | 1 Apache | 1 Cxf | 2026-08-07 | 6.5 Medium |
| Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue. | ||||
| CVE-2026-55031 | 1 Microsoft | 17 365 Apps, Excel, Excel 2016 and 14 more | 2026-08-07 | 7.8 High |
| Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-55029 | 1 Microsoft | 17 365 Apps, Excel, Excel 2016 and 14 more | 2026-08-07 | 7.8 High |
| Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-55047 | 1 Microsoft | 21 365 Apps, Microsoft 365, Microsoft 365 Apps For Enterprise and 18 more | 2026-08-07 | 5.5 Medium |
| Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-55141 | 1 Microsoft | 17 365 Apps, Excel, Excel 2016 and 14 more | 2026-08-07 | 7.8 High |
| Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-55055 | 1 Microsoft | 21 365 Apps, Microsoft 365, Microsoft 365 Apps For Enterprise and 18 more | 2026-08-07 | 7.8 High |
| Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-55132 | 1 Microsoft | 21 365 Apps, Microsoft 365, Microsoft 365 Apps For Enterprise and 18 more | 2026-08-07 | 7.8 High |
| Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-55043 | 1 Microsoft | 16 365 Apps, Microsoft 365, Microsoft 365 Apps For Enterprise and 13 more | 2026-08-07 | 7.8 High |
| Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-55949 | 1 Microsoft | 18 365 Apps, Excel, Excel 2016 and 15 more | 2026-08-07 | 7.8 High |
| Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-56184 | 1 Microsoft | 13 Windows 10 21h2, Windows 10 21h2, Windows 10 22h2 and 10 more | 2026-08-07 | 5.5 Medium |
| Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-56192 | 1 Microsoft | 20 365 Apps, Microsoft 365, Microsoft 365 Apps For Enterprise and 17 more | 2026-08-07 | 5.5 Medium |
| Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-54124 | 1 Microsoft | 16 Terminal, Windows 10 21h2, Windows 10 21h2 and 13 more | 2026-08-07 | 7.8 High |
| Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-57092 | 1 Microsoft | 24 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 21 more | 2026-08-07 | 9.9 Critical |
| Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-55121 | 1 Microsoft | 22 365 Apps, Microsoft 365, Microsoft 365 Apps For Enterprise and 19 more | 2026-08-07 | 5.5 Medium |
| Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-47300 | 4 Apple, Linux, Microsoft and 1 more | 9 Macos, Linux Kernel, .net and 6 more | 2026-08-07 | 8.8 High |
| Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-47302 | 4 Apple, Linux, Microsoft and 1 more | 22 Macos, Linux Kernel, .net and 19 more | 2026-08-07 | 7.5 High |
| Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-47303 | 4 Apple, Linux, Microsoft and 1 more | 9 Macos, Linux Kernel, .net and 6 more | 2026-08-07 | 8.8 High |
| Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | ||||