Export limit exceeded: 381375 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381375 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66800 | 1 Microsoft | 1 Azure Data Factory | 2026-08-20 | 8.6 High |
| Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-66309 | 1 Microsoft | 1 Azure Sql Database | 2026-08-20 | 9.1 Critical |
| Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-65816 | 1 Microsoft | 1 Azure Web Apps | 2026-08-20 | 10 Critical |
| Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-63509 | 1 Microsoft | 1 Microsoft Fabric | 2026-08-20 | 9.9 Critical |
| Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-65770 | 1 Microsoft | 1 Azure Managed Instance For Apache Cassandra | 2026-08-20 | 10 Critical |
| Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-16989 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 7.1 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper resolution of symbolic links. | ||||
| CVE-2026-70105 | 1 Microsoft | 8 365 Apps, Office 2019, Office 2021 and 5 more | 2026-08-20 | 6.5 Medium |
| Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-16980 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 6.3 Medium |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper validation of symbolic links. | ||||
| CVE-2026-65795 | 1 Microsoft | 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more | 2026-08-20 | 6.7 Medium |
| Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-16973 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 5.5 Medium |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to disclose sensitive kernel memory due to an out-of-bounds read. | ||||
| CVE-2026-16972 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 6.5 Medium |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to improper authentication. | ||||
| CVE-2026-16964 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 6.5 Medium |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages and forge replies due to the exposure of sensitive information. | ||||
| CVE-2026-16958 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 6.5 Medium |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds write. | ||||
| CVE-2026-16952 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 5.5 Medium |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to uncontrolled resource consumption. | ||||
| CVE-2026-55013 | 1 Microsoft | 1 Windows-remote-help | 2026-08-20 | 7.1 High |
| Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally. | ||||
| CVE-2026-55015 | 1 Microsoft | 1 Windows-remote-help | 2026-08-20 | 5.5 Medium |
| Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally. | ||||
| CVE-2026-14163 | 2026-08-20 | N/A | ||
| In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable snapshot in clear-text. | ||||
| CVE-2026-16951 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 6.7 Medium |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated attacker to execute arbitrary code due to a heap-based buffer overflow. | ||||
| CVE-2026-54505 | 2026-08-20 | N/A | ||
| TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK interpolates the unescaped activeSuggestion.title value into journey.frontpage.suggestionText through client/src/i18n/TranslationContext.tsx and renders the result with dangerouslySetInnerHTML in client/src/pages/JourneyPage.tsx. A trip owner can store HTML in a qualifying trip title, and GET /api/journeys/suggestions returns that title through getSuggestions(userId) to a collaborator who opens the authenticated Journey page. The markup is inserted as live DOM in the collaborator's session, enabling content spoofing and UI redress, although the default Content Security Policy blocks inline handlers and script execution. This issue is fixed in version 3.1.0. | ||||
| CVE-2026-69836 | 1 Microsoft | 1 Microsoft Entra Id | 2026-08-20 | 10 Critical |
| Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. | ||||