Export limit exceeded: 400603 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400603 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-86105 | 1 Watchguard | 1 Fireware Os | 2026-09-30 | N/A |
| An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access. | ||||
| CVE-2026-86104 | 1 Watchguard | 1 Fireware Os | 2026-09-30 | N/A |
| An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request. | ||||
| CVE-2026-13224 | 1 Watchguard | 1 Fireware Os | 2026-09-30 | N/A |
| A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request. | ||||
| CVE-2026-18105 | 1 Watchguard | 1 Fireware Os | 2026-09-30 | N/A |
| An uncontrolled resource consumption vulnerability in Fireware OS's diagnostic tasks feature allows a low-privileged, authenticated user to cause a denial of service of the system's diagnostic tools by repeatedly starting and aborting a specially crafted diagnostic task through the web UI. | ||||
| CVE-2026-86101 | 1 Watchguard | 1 Fireware Os | 2026-09-30 | N/A |
| An improper authorization vulnerability in WatchGuard Fireware OS's SAML login process allows a remote, authenticated SAML user with access only to the Access Portal to obtain unauthorized Mobile VPN with SSL access through a specially crafted request. | ||||
| CVE-2026-86132 | 1 Watchguard | 1 Fireware Os | 2026-09-30 | N/A |
| An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher suite. | ||||
| CVE-2026-86128 | 1 Watchguard | 1 Fireware Os | 2026-09-30 | N/A |
| A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted IPv6 packet. | ||||
| CVE-2026-90441 | 1 Watchguard | 1 Fireware Os | 2026-09-30 | N/A |
| A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request. | ||||
| CVE-2026-82877 | 2 Ilias, Ilias-elearning E.v. | 2 Ilias, Ilias | 2026-09-30 | 6.5 Medium |
| ILIAS before versions 9.22, 10.10, and 11.3 contains an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports. Attackers can construct absolute file paths through an unsandboxed import directory and retrieve sensitive files including configuration files containing database credentials and setup passwords. | ||||
| CVE-2026-80428 | 1 Ilias | 1 Ilias | 2026-09-30 | 9.8 Critical |
| ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and triggering deserialization via the Shibboleth back-channel logout endpoint. Attackers can write arbitrary serialized objects into session storage, then exploit an available POP gadget through the logout endpoint's unrestricted deserialization to write attacker-controlled PHP content to a web-accessible path and achieve remote code execution as the web server user. | ||||
| CVE-2026-95274 | 1 Google | 1 Chrome | 2026-09-30 | 8.3 High |
| Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-95276 | 1 Google | 1 Chrome | 2026-09-30 | 8.3 High |
| Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: Medium) | ||||
| CVE-2026-95277 | 1 Google | 1 Chrome | 2026-09-30 | 9.6 Critical |
| Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-102306 | 1 Google | 1 Chrome | 2026-09-30 | 9.6 Critical |
| Use after free in Bluetooth in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-95280 | 1 Google | 1 Chrome | 2026-09-30 | 7.5 High |
| Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-95286 | 1 Google | 1 Chrome | 2026-09-30 | 8.8 High |
| Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-102457 | 1 Digiwin | 1 Easyflow .net | 2026-09-30 | 6.5 Medium |
| EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files. | ||||
| CVE-2026-102454 | 1 Digiwin | 1 Easyflow .net | 2026-09-30 | 7.2 High |
| EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | ||||
| CVE-2026-102455 | 1 Digiwin | 1 Easyflow .net | 2026-09-30 | 9.8 Critical |
| EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content. | ||||
| CVE-2026-102456 | 1 Digiwin | 1 Easyflow .net | 2026-09-30 | 6.5 Medium |
| EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents. | ||||