Export limit exceeded: 376902 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 376902 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (376902 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-67991 | 2026-08-13 | N/A | ||
| crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial of service. | ||||
| CVE-2026-28002 | 2026-08-13 | 8.5 High | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection. This issue affects Booktics: from n/a through 1.0.22. | ||||
| CVE-2026-66808 | 2 Hypershift, Microsoft | 4 Addon Operator, Sharepoint Server, Sharepoint Server 2016 and 1 more | 2026-08-13 | 8.8 High |
| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-66805 | 2 Microsoft, Redhat | 4 Sharepoint Server, Sharepoint Server 2016, Sharepoint Server 2019 and 1 more | 2026-08-13 | 8.8 High |
| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-61928 | 1 Microsoft | 18 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 15 more | 2026-08-13 | 5.5 Medium |
| Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. | ||||
| CVE-2026-65660 | 1 Microsoft | 3 Sharepoint Server, Sharepoint Server 2016, Sharepoint Server 2019 | 2026-08-13 | 6.5 Medium |
| Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||||
| CVE-2026-61923 | 1 Microsoft | 16 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 13 more | 2026-08-13 | 7.8 High |
| Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-63520 | 1 Microsoft | 3 Sharepoint Server, Sharepoint Server 2016, Sharepoint Server 2019 | 2026-08-13 | 8.1 High |
| Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-64921 | 1 Microsoft | 3 Sharepoint Server, Sharepoint Server 2016, Sharepoint Server 2019 | 2026-08-13 | 8.8 High |
| Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-67990 | 2026-08-13 | N/A | ||
| basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to submit requests that are forwarded to enabled upstream write or management endpoints, such as creating an Alertmanager silence or requesting a Prometheus reload. The final impact depends on the APIs enabled by the upstream services. | ||||
| CVE-2026-73403 | 2026-08-13 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions. | ||||
| CVE-2026-73401 | 2026-08-13 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions. | ||||
| CVE-2026-73357 | 2026-08-13 | 6.5 Medium | ||
| Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions. | ||||
| CVE-2026-73353 | 2026-08-13 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions. | ||||
| CVE-2026-73349 | 2026-08-13 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. | ||||
| CVE-2026-73346 | 2026-08-13 | 7.6 High | ||
| Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. | ||||
| CVE-2026-73344 | 2026-08-13 | 5.9 Medium | ||
| Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. | ||||
| CVE-2026-73340 | 2026-08-13 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. | ||||
| CVE-2026-73188 | 2026-08-13 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions. | ||||
| CVE-2026-66704 | 2026-08-13 | 7.2 High | ||
| Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. | ||||