Export limit exceeded: 400389 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400389 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400389 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400389 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-69329 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-30 | 7.5 High |
| Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-69336 | 1 Microsoft | 20 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 17 more | 2026-09-30 | 7.1 High |
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-15815 | 1 Grafana | 2 Grafana, Grafana Enterprise | 2026-09-30 | 8.8 High |
| Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped executable runs with the privileges of the Grafana server process, resulting in remote code execution. Plugin archives are extracted before their signature is verified, so a valid plugin signature does not prevent the write. An operator can therefore be affected by installing a plugin that appears legitimate, as well as by installing a plugin from an arbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or preinstall configuration. Grafana Enterprise is affected because it includes the same plugin extraction code as Grafana OSS. | ||||
| CVE-2026-76154 | 2 Grafana, Redhat | 3 Grafana, Grafana Enterprise, Hummingbird | 2026-09-30 | 7.3 High |
| A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin. | ||||
| CVE-2026-69338 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 11 more | 2026-09-30 | 7.1 High |
| Use after free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69355 | 1 Microsoft | 6 Exchange Server, Exchange Server 2016, Exchange Server 2019 and 3 more | 2026-09-30 | 8.8 High |
| External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-69356 | 1 Microsoft | 5 Exchange Server, Exchange Server 2016, Exchange Server 2019 and 2 more | 2026-09-30 | 9.3 Critical |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | ||||
| CVE-2026-102385 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. | ||||
| CVE-2026-102384 | 2026-09-30 | 5.9 Medium | ||
| Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions. | ||||
| CVE-2026-100513 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.5 versions. | ||||
| CVE-2026-100508 | 2026-09-30 | 5.3 Medium | ||
| Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions. | ||||
| CVE-2026-100507 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions. | ||||
| CVE-2026-97289 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions. | ||||
| CVE-2026-97288 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions. | ||||
| CVE-2026-97287 | 2026-09-30 | 8.5 High | ||
| Contributor SQL Injection in Event Tickets <= 5.29.5 versions. | ||||
| CVE-2026-97286 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Strong Testimonials <= 3.3.11 versions. | ||||
| CVE-2026-97285 | 2026-09-30 | 5.4 Medium | ||
| Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions. | ||||
| CVE-2026-97282 | 2026-09-30 | 5.3 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions. | ||||
| CVE-2026-97279 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Polylang <= 3.8.9 versions. | ||||
| CVE-2026-97274 | 2026-09-30 | 9.8 Critical | ||
| Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions. | ||||