Export limit exceeded: 395636 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 395636 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 395636 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (395636 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-13635 | 1 Synology | 1 Diskstation Manager | 2026-09-19 | 5.3 Medium |
| An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to obtain non-sensitive information. | ||||
| CVE-2026-13673 | 1 Synology | 1 Diskstation Manager | 2026-09-19 | 8.8 High |
| An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks. | ||||
| CVE-2026-6205 | 1 Synology | 1 Diskstation Manager | 2026-09-19 | 8.1 High |
| An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct denial-of-service attacks. | ||||
| CVE-2026-56590 | 1 Hcltech | 1 Bigfix Service Management | 2026-09-19 | 6.4 Medium |
| HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an unauthenticated attacker to upload and execute malicious payloads, resulting in a complete server compromise. | ||||
| CVE-2026-13666 | 1 Synology | 1 Diskstation Manager | 2026-09-19 | 3.5 Low |
| An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write limited files when a victim clicks a sharing URL. | ||||
| CVE-2026-13623 | 1 Synology | 1 Diskstation Manager | 2026-09-19 | 4.8 Medium |
| An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to read or write limited files. | ||||
| CVE-2026-13683 | 1 Synology | 1 Diskstation Manager | 2026-09-19 | 2.7 Low |
| An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to obtain non-sensitive information. | ||||
| CVE-2026-56592 | 1 Hcltech | 1 Bigfix Service Management | 2026-09-19 | 6.5 Medium |
| HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate account lockouts, which could allow an unauthenticated attacker to execute sustained brute-force attacks against the login interface, resulting in unauthorized system access. | ||||
| CVE-2026-56597 | 1 Hcltech | 1 Bigfix Service Management | 2026-09-19 | 3.1 Low |
| HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underlying network topology and identify potential internal targets. | ||||
| CVE-2026-56595 | 1 Hcltech | 1 Bigfix Service Management | 2026-09-19 | 3.1 Low |
| HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, enabling unauthorized access to protected resources and restricted APIs on behalf of a victim. | ||||
| CVE-2026-40530 | 1 Synology | 1 Diskstation Manager | 2026-09-19 | 8 High |
| An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks after the system is rebooted. | ||||
| CVE-2026-4036 | 1 Synology | 1 Diskstation Manager | 2026-09-19 | 6.5 Medium |
| An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain arbitrary sharing files. | ||||
| CVE-2026-40531 | 1 Synology | 1 Diskstation Manager | 2026-09-19 | 4.3 Medium |
| An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks. | ||||
| CVE-2026-40532 | 1 Synology | 1 Diskstation Manager | 2026-09-19 | 6.5 Medium |
| A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information. | ||||
| CVE-2026-40534 | 1 Synology | 1 Diskstation Manager | 2026-09-19 | 5.4 Medium |
| An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write limited files when the player is launched. | ||||
| CVE-2026-40536 | 1 Synology | 1 Diskstation Manager | 2026-09-19 | 4.3 Medium |
| An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information. | ||||
| CVE-2026-40537 | 1 Synology | 1 Diskstation Manager | 2026-09-19 | 4.3 Medium |
| A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information. | ||||
| CVE-2026-83561 | 2 Complianz, Wordpress | 2 Complianz – Gdpr/ccpa Cookie Consent, Wordpress | 2026-09-19 | 7.2 High |
| The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Elementor Cookie Blocker Regex in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires an administrator to approve the attacker's comment, and the site must have both the Elementor plugin installed and Complianz configured with the Twitter or Facebook cookie/script blocker enabled. | ||||
| CVE-2026-40533 | 1 Synology | 1 Diskstation Manager | 2026-09-19 | 5.3 Medium |
| An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information. | ||||
| CVE-2026-40535 | 1 Synology | 1 Diskstation Manager | 2026-09-19 | 6.5 Medium |
| An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write limited files and conduct limited denial-of-service attacks. | ||||