Export limit exceeded: 396729 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (396729 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-82009 | 1 Adobe | 1 Campaign Classic | 2026-09-22 | 9.1 Critical |
| Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary SQL commands. Exploitation of this issue does not require user interaction. Scope is changed. | ||||
| CVE-2026-82013 | 1 Adobe | 1 Campaign Classic | 2026-09-22 | 9.9 Critical |
| Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed. | ||||
| CVE-2026-75721 | 1 Adobe | 1 Campaign Classic | 2026-09-22 | 10 Critical |
| Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. | ||||
| CVE-2026-89276 | 1 Adobe | 1 Campaign Classic | 2026-09-22 | 9.9 Critical |
| Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. | ||||
| CVE-2026-69713 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-22 | 4.4 Medium |
| Dependency on vulnerable third-party component in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | ||||
| CVE-2026-94424 | 1 Moore Threads | 1 Mtt S80 Driver Package | 2026-09-22 | 8.8 High |
| A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-1645 | 2 Prasunsen, Wordpress | 2 Hostel, Wordpress | 2026-09-22 | 4.4 Medium |
| The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_currency' parameter and the 'locale_url' setting in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. | ||||
| CVE-2026-94403 | 1 Colorful | 1 Igamecenter | 2026-09-22 | 8.8 High |
| A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library ene.sys of the component IOCTL Handler. This manipulation causes untrusted pointer dereference. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-95272 | 1 Dgtlmoon | 1 Changedetection.io | 2026-09-22 | 3.7 Low |
| A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affects the function static_content of the file changedetectionio/flask_app.py of the component Screenshot Handler. Performing a manipulation of the argument filename results in path traversal. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-95273 | 1 Dgtlmoon | 1 Changedetection.io | 2026-09-22 | 4.3 Medium |
| A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of the file changedetectionio/flask_app.py of the component visual_selector_data. Executing a manipulation of the argument filename can lead to path traversal. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Distinct from CVE-2026-25527, which fixed a different parameter (group) in the same function. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-95271 | 1 Dgtlmoon | 1 Changedetection.io | 2026-09-22 | 7.3 High |
| A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_authentication of the file changedetectionio/flask_app.py of the component Authentication Hook. Such manipulation leads to improper authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-94490 | 1 Octoprint | 1 Octoprint | 2026-09-22 | 4.7 Medium |
| A security flaw has been discovered in OctoPrint 1.0.0. Affected by this issue is the function executeSystemCommand of the file src/octoprint/server/api/system.py of the component Command API. Performing a manipulation of the argument command results in os command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-25294 | 1 Qualcomm | 151 Cologne, Cologne Firmware, Congo and 148 more | 2026-09-22 | 7.4 High |
| Transient DOS while parsing frame during channel usage. | ||||
| CVE-2026-25290 | 1 Qualcomm | 15 Cologne, Cologne Firmware, Fastconnect 7800 and 12 more | 2026-09-22 | 7.8 High |
| Memory Corruption when validating large data buffers from external sources using addition to check buffer length. | ||||
| CVE-2026-25284 | 1 Qualcomm | 15 Cologne, Cologne Firmware, Fastconnect 7800 and 12 more | 2026-09-22 | 7.3 High |
| Information Disclosure when a pointer is reused after being deallocated. | ||||
| CVE-2026-25283 | 1 Qualcomm | 15 Cologne, Cologne Firmware, Fastconnect 7800 and 12 more | 2026-09-22 | 8.8 High |
| Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size. | ||||
| CVE-2026-25282 | 1 Qualcomm | 15 Cologne, Cologne Firmware, Fastconnect 7800 and 12 more | 2026-09-22 | 7.9 High |
| Transient DOS when processing unverified data from a neighboring system causes out of bound memory access. | ||||
| CVE-2026-25281 | 1 Qualcomm | 15 Cologne, Cologne Firmware, Fastconnect 7800 and 12 more | 2026-09-22 | 7.4 High |
| Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation. | ||||
| CVE-2026-83419 | 1 Oracle | 1 Communications Cloud Native Core Security Edge Protection Proxy | 2026-09-22 | 5.4 Medium |
| Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as unauthorized read access to a subset of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N). | ||||
| CVE-2026-88593 | 2026-09-22 | 6.1 Medium | ||
| kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes the user-controlled page and kkagent request parameters to FreeMarker templates without sanitization, and the templates insert these values into raw JavaScript contexts. | ||||