Export limit exceeded: 92759 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (92759 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-69101 | 2026-08-14 | 7.7 High | ||
| Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by supplying a crafted taskScript payload to the doEditWorkflow endpoint, which processes XML through an unhardened DocumentBuilderFactory with external entities and DTD loading enabled. Attackers can send a malicious XML document containing an external DTD reference to the edit_workflow action, causing the server to issue outbound HTTP requests to attacker-controlled infrastructure and exfiltrate local files readable by the TIS process user, including configuration files and Derby database credentials. | ||||
| CVE-2026-19825 | 1 Sourcecodester | 1 Simple Client Management System | 2026-08-14 | 7.3 High |
| A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. | ||||
| CVE-2026-18511 | 1 Ibm | 1 I | 2026-08-14 | 7.3 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, caused by improper bounds checking during TLS session establishment. A local attacker could overflow a fixed-length buffer and execute arbitrary code on the system or cause the JVM process to crash. | ||||
| CVE-2026-17502 | 1 Ibm | 1 I | 2026-08-14 | 8.6 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write. | ||||
| CVE-2026-62872 | 1 Microsoft | 15 .net, .net Framework, Windows 10 1607 and 12 more | 2026-08-14 | 8.8 High |
| Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-62886 | 1 Microsoft | 6 .net, Microsoft Visual Studio 2022, Microsoft Visual Studio 2026 and 3 more | 2026-08-14 | 7.8 High |
| Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | ||||
| CVE-2026-62897 | 1 Microsoft | 7 .net, .net Framework, Visual Studio 2022 and 4 more | 2026-08-14 | 7 High |
| Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-62901 | 3 Apple, Linux, Microsoft | 6 Macos, Linux Kernel, .net and 3 more | 2026-08-14 | 7.5 High |
| Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-62909 | 3 Apple, Linux, Microsoft | 6 Macos, Linux Kernel, .net and 3 more | 2026-08-14 | 7.8 High |
| Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-64908 | 1 Microsoft | 6 365 Apps, Access, Access 2016 and 3 more | 2026-08-14 | 7.8 High |
| Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-64915 | 1 Microsoft | 10 365 Apps, Microsoft 365, Office 2019 and 7 more | 2026-08-14 | 7.8 High |
| Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-72810 | 1 Siyuan | 1 Siyuan | 2026-08-14 | 8.6 High |
| SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSocket connection to the publish surface and passively receive real-time content events including password-protected and forbidden documents without authentication. | ||||
| CVE-2026-64906 | 1 Microsoft | 7 365 Apps, Access, Access 2016 and 4 more | 2026-08-14 | 7.8 High |
| Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-58641 | 3 Apple, Linux, Microsoft | 4 Macos, Linux Kernel, .net and 1 more | 2026-08-14 | 7.8 High |
| Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | ||||
| CVE-2026-70345 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-08-14 | 7.8 High |
| Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-70313 | 1 Microsoft | 8 365 Apps, Microsoft 365, Office 2019 and 5 more | 2026-08-14 | 7.8 High |
| Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-65810 | 1 Microsoft | 15 .net, .net Framework, Windows 10 1607 and 12 more | 2026-08-14 | 7.8 High |
| Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. | ||||
| CVE-2026-3987 | 1 Watchguard | 38 Firebox Cloud, Firebox M270, Firebox M290 and 35 more | 2026-08-14 | 7.2 High |
| A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process. | ||||
| CVE-2026-19823 | 1 Tenda | 2 W20e, W20e Firmware | 2026-08-14 | 8.8 High |
| A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. Impacted is the function formQOSRuleDel of the file /goform/delQos of the component QoS Rule Deletion. Performing a manipulation of the argument qosIndex results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. | ||||
| CVE-2026-19824 | 1 Tenda | 2 W20e, W20e Firmware | 2026-08-14 | 8.8 High |
| A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element is the function ipMacBindListStore of the file /goform/addIpMacBind. Executing a manipulation of the argument IPMacBindRule can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. | ||||