Export limit exceeded: 386019 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 386019 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (386019 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73512 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.5 High |
| No description is available for this CVE. | ||||
| CVE-2026-73513 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.5 High |
| No description is available for this CVE. | ||||
| CVE-2026-73546 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.4 High |
| No description is available for this CVE. | ||||
| CVE-2026-73547 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.5 High |
| No description is available for this CVE. | ||||
| CVE-2026-73548 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.5 High |
| No description is available for this CVE. | ||||
| CVE-2026-73549 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 5.3 Medium |
| No description is available for this CVE. | ||||
| CVE-2026-73550 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.5 High |
| No description is available for this CVE. | ||||
| CVE-2026-73551 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 5.3 Medium |
| No description is available for this CVE. | ||||
| CVE-2026-73552 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.5 High |
| No description is available for this CVE. | ||||
| CVE-2026-73553 | 1 Envoyproxy | 1 Envoy | 2026-09-02 | 7.5 High |
| No description is available for this CVE. | ||||
| CVE-2026-18765 | 1 Teracity | 1 E-osb | 2026-09-02 | 9.8 Critical |
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects E-OSB: before V02.26.07.08.01. | ||||
| CVE-2026-84149 | 1 Manacle Technologies | 1 Multi-tenant Erp System | 2026-09-02 | N/A |
| This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit this vulnerability by accessing the exposed .git directory and retrieving repository metadata and associated files, which could allow reconstruction of the application's source code. | ||||
| CVE-2026-18808 | 1 Klemsan Electrical Electronics | 1 Kio (klemsan Internet Objects) | 2026-09-02 | 9.8 Critical |
| Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO (Klemsan Internet Objects): before v1.9. | ||||
| CVE-2026-18210 | 1 Trtek | 1 Products Store | 2026-09-02 | 9.8 Critical |
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection. This issue affects Products's Store: before 030631b2. | ||||
| CVE-2026-18771 | 1 Tmt Machine | 1 Talassoft Industrial Management Software | 2026-09-02 | 7.5 High |
| Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass. This issue affects Talassoft Industrial Management Software: from V4 before V.16. | ||||
| CVE-2026-18780 | 1 Tmt Machine | 1 Talassoft Industrial Management Software | 2026-09-02 | 7.1 High |
| Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery. This issue affects Talassoft Industrial Management Software: from V.4 before V.16. | ||||
| CVE-2026-18630 | 1 Tmt Machine | 1 Talassoft Industrial Management Software | 2026-09-02 | 8.8 High |
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows SQL Injection. This issue affects Talassoft Industrial Management Software: from V.4 before V.16. | ||||
| CVE-2026-18931 | 1 Tmt Machine | 1 Talassoft Industrial Management Software | 2026-09-02 | 9.1 Critical |
| Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Embedded Sensitive Data. This issue affects Talassoft Industrial Management Software: from V.4 before V.16. | ||||
| CVE-2026-84201 | 1 Argneshu | 1 Appium-mcp-server | 2026-09-02 | 7.1 High |
| appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, allowing attackers to write files outside the intended PROJECT_ROOT directory. Attackers can supply absolute paths or relative paths with parent directory segments to overwrite arbitrary files with the server user's privileges, including shell profiles and configuration files in the home directory. | ||||
| CVE-2026-10195 | 2 Fs-code, Wordpress | 2 Fs Poster - Wordpress Social Media Auto Poster & Scheduler [facebook, Instagram, Twitter, Pinterest], Wordpress | 2026-09-02 | 8.8 High |
| The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. This is due to insufficient input sanitization of the FFmpeg path parameter before passing it to the exec() function, combined with missing authorization checks on the REST API endpoints. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary commands on the underlying server. | ||||