Export limit exceeded: 369469 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 369469 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (369469 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-58317 2026-07-22 N/A
Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.
CVE-2019-25764 1 Asus 1 Aura Sync 2026-07-22 N/A
**UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.
CVE-2026-15379 2026-07-22 N/A
The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM account, bypassing filesystem ACLs. No admin privileges required. The provider reverts to the LocalSystem context when servicing WMI queries without re-impersonating the caller. Any local standard user can therefore read SYSTEM-readable files — including configuration files, service logs, and secrets stored with SYSTEM/Administrator-only ACLs — by querying the provider directly.
CVE-2026-15380 2026-07-22 N/A
A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3)
CVE-2026-16368 1 Mozilla 1 Firefox 2026-07-22 N/A
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
CVE-2026-16369 1 Mozilla 1 Firefox 2026-07-22 N/A
Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
CVE-2026-16383 1 Mozilla 1 Firefox 2026-07-22 N/A
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
CVE-2026-16388 1 Mozilla 1 Firefox 2026-07-22 N/A
Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153.
CVE-2026-16391 1 Mozilla 1 Firefox 2026-07-22 N/A
Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
CVE-2026-16359 1 Mozilla 1 Firefox 2026-07-22 9.1 Critical
Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
CVE-2026-16400 1 Mozilla 1 Firefox 2026-07-22 N/A
Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153.
CVE-2026-16403 1 Mozilla 1 Firefox 2026-07-22 N/A
Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153.
CVE-2024-23564 2026-07-22 9.1 Critical
HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails.
CVE-2024-23566 2026-07-22 6.5 Medium
HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force , automated attacks & account enumeration
CVE-2024-23573 2026-07-22 3.7 Low
HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack.
CVE-2024-23574 2026-07-22 5.3 Medium
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system
CVE-2024-23569 2026-07-22 4.3 Medium
HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
CVE-2024-23578 2026-07-22 4.2 Medium
HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).
CVE-2024-23572 2026-07-22 4.2 Medium
HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.
CVE-2026-16351 1 Mozilla 1 Firefox 2026-07-22 N/A
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.