Export limit exceeded: 377315 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (377315 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-18086 | 1 Ibm | 1 I | 2026-08-14 | 4.5 Medium |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking. | ||||
| CVE-2026-17502 | 1 Ibm | 1 I | 2026-08-14 | 8.6 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write. | ||||
| CVE-2026-17468 | 1 Ibm | 1 Documentation Offline | 2026-08-14 | 5.3 Medium |
| IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid session tokens due to the use of a hardcoded cryptographic key. | ||||
| CVE-2026-12743 | 2 Cservit, Wordpress | 2 Affiliate-toolkit – Multi-network Affiliate & Amazon Product Display, Wordpress | 2026-08-14 | 4.9 Medium |
| The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.8.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-62872 | 1 Microsoft | 15 .net, .net Framework, Windows 10 1607 and 12 more | 2026-08-14 | 8.8 High |
| Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-62886 | 1 Microsoft | 6 .net, Microsoft Visual Studio 2022, Microsoft Visual Studio 2026 and 3 more | 2026-08-14 | 7.8 High |
| Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | ||||
| CVE-2026-62897 | 1 Microsoft | 7 .net, .net Framework, Visual Studio 2022 and 4 more | 2026-08-14 | 7 High |
| Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-62899 | 3 Apple, Linux, Microsoft | 6 Macos, Linux Kernel, .net and 3 more | 2026-08-14 | 5.9 Medium |
| Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. | ||||
| CVE-2026-62900 | 3 Apple, Linux, Microsoft | 6 Macos, Linux Kernel, .net and 3 more | 2026-08-14 | 5.9 Medium |
| Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-62901 | 3 Apple, Linux, Microsoft | 6 Macos, Linux Kernel, .net and 3 more | 2026-08-14 | 7.5 High |
| Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-62902 | 1 Microsoft | 4 .net, Visual Studio 2022, Visual Studio 2026 and 1 more | 2026-08-14 | 6.5 Medium |
| Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-64917 | 1 Microsoft | 10 365 Apps, Microsoft 365, Office 2019 and 7 more | 2026-08-14 | 5.5 Medium |
| Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-62909 | 3 Apple, Linux, Microsoft | 6 Macos, Linux Kernel, .net and 3 more | 2026-08-14 | 7.8 High |
| Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-18085 | 1 Blackberry | 2 Uem, Unified Endpoint Manager | 2026-08-14 | 6.9 Medium |
| An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service. | ||||
| CVE-2026-64908 | 1 Microsoft | 6 365 Apps, Access, Access 2016 and 3 more | 2026-08-14 | 7.8 High |
| Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-18084 | 1 Blackberry | 2 Uem, Unified Endpoint Manager | 2026-08-14 | 6.1 Medium |
| Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). This issue affects UEM: 12.23.0 QF8 or earlier. | ||||
| CVE-2026-64915 | 1 Microsoft | 10 365 Apps, Microsoft 365, Office 2019 and 7 more | 2026-08-14 | 7.8 High |
| Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-72810 | 1 Siyuan | 1 Siyuan | 2026-08-14 | 8.6 High |
| SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSocket connection to the publish surface and passively receive real-time content events including password-protected and forbidden documents without authentication. | ||||
| CVE-2026-72811 | 1 Siyuan | 1 Siyuan | 2026-08-14 | 10 Critical |
| SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into a SQL MATCH/search statement while escaping only the double-quote character and not the single quote. A single quote in the client keyword (first-order, reachable by an anonymous or RoleReader user on the publish surface) or in stored document metadata (second-order) breaks out of the string literal. Because the query runs on the main read-write siyuan.db handle via a statement-stacking-capable driver, an attacker can execute arbitrary SQL, enabling cross-notebook read and write. Fixed in v3.7.4. | ||||
| CVE-2026-72812 | 1 Siyuan | 1 Siyuan | 2026-08-14 | 6.5 Medium |
| SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink endpoint that allows anonymous readers to trigger persistent server-side writes. Attackers can invoke the endpoint with an attacker-controlled block ID to flush transaction queues, scan all references globally, and enqueue database writes, bypassing read-only protections and enabling resource amplification attacks. | ||||