Export limit exceeded: 12712 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 11541 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 390037 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (390037 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-19946 | 2026-09-09 | 4.3 Medium | ||
| The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability check on the wpas_do_mr_deny_user() function, which unlike its counterpart wpas_do_mr_activate_user() does not enforce current_user_can('edit_users') or current_user_can('edit_user', $user_id), relying solely on a nonce that is not scoped to the target user. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the mr_user_denied flag on any user account — including administrators — permanently blocking their moderated activation and dispatching a denial notification email to the victim. | ||||
| CVE-2026-76191 | 1 Adobe | 2 Adobe Animate 2023, Adobe Animate 2024 | 2026-09-09 | 8.2 High |
| Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. | ||||
| CVE-2026-75990 | 2026-09-09 | 8.6 High | ||
| Illustrator is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. | ||||
| CVE-2026-11814 | 1 Netgear | 52 Be9300, Be9300 Firmware, Mr60 and 49 more | 2026-09-09 | 6.8 Medium |
| A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs. | ||||
| CVE-2026-11738 | 1 Netgear | 55 Be9300, Be9300 Firmware, Mr60 and 52 more | 2026-09-09 | 4.4 Medium |
| Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality. | ||||
| CVE-2026-9214 | 1 Netgear | 2 R7000, R7000 Firmware | 2026-09-09 | 4.5 Medium |
| Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality. | ||||
| CVE-2026-11739 | 1 Netgear | 54 Mr60, Mr60 Firmware, Mr70 and 51 more | 2026-09-09 | 6.4 Medium |
| A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device. | ||||
| CVE-2026-11737 | 1 Netgear | 26 Rax20, Rax20 Firmware, Rax41 and 23 more | 2026-09-09 | 4.5 Medium |
| Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality. | ||||
| CVE-2026-11733 | 1 Netgear | 22 Rax41, Rax41 Firmware, Rax41v2 and 19 more | 2026-09-09 | 4.9 Medium |
| A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device. | ||||
| CVE-2026-11734 | 1 Netgear | 30 Mr70, Mr70 Firmware, Mr90 and 27 more | 2026-09-09 | 2.7 Low |
| A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable. | ||||
| CVE-2026-11736 | 1 Netgear | 38 Rax20, Rax20 Firmware, Rax35v2 and 35 more | 2026-09-09 | 4.9 Medium |
| A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality. | ||||
| CVE-2026-11735 | 1 Netgear | 40 R7000, R7000 Firmware, Rax20 and 37 more | 2026-09-09 | 4.9 Medium |
| A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality. | ||||
| CVE-2026-15141 | 1 Tp-link | 3 Td-w8961n, Tl-wr820n, Tl-wr820n Firmware | 2026-09-09 | 5.7 Medium |
| The web interface of the affected device relies on the HTTP referrer header as part of request validation. Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic. Successful exploitation may allow an adjacent attacker with access to the web management interface to obtain device configuration details and other sensitive information. | ||||
| CVE-2026-20504 | 2 Mediatek, Mediatek, Inc. | 39 Mt2735, Mt2735 Firmware, Mt6833 and 36 more | 2026-09-09 | 5.3 Medium |
| In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865. | ||||
| CVE-2026-20503 | 2 Mediatek, Mediatek, Inc. | 115 Mt2716, Mt2716 Firmware, Mt2735 and 112 more | 2026-09-09 | 5.3 Medium |
| In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01371002; Issue ID: MSV-9020. | ||||
| CVE-2026-20502 | 2 Mediatek, Mediatek, Inc. | 107 Mt2718, Mt2718 Firmware, Mt6580 and 104 more | 2026-09-09 | 8.4 High |
| In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196. | ||||
| CVE-2026-20501 | 2 Mediatek, Mediatek, Inc. | 107 Mt2718, Mt2718 Firmware, Mt6580 and 104 more | 2026-09-09 | 8.4 High |
| In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197. | ||||
| CVE-2026-20500 | 1 Mediatek | 45 Mediatek Chipset, Mt2716, Mt2716 Firmware and 42 more | 2026-09-09 | 5.5 Medium |
| In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: MSV-9232. | ||||
| CVE-2026-15406 | 2026-09-09 | 7.5 High | ||
| The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with custom-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. | ||||
| CVE-2026-67390 | 1 Microsoft | 12 Microsoft Sql Server 2017 (cu 31), Microsoft Sql Server 2017 (gdr), Microsoft Sql Server 2019 (cu 32) and 9 more | 2026-09-09 | 6.5 Medium |
| Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | ||||