Export limit exceeded: 395782 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 20806 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 395782 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 395782 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (395782 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-94144 | 1 Drogon | 1 Drogon | 2026-09-21 | 7.3 High |
| A flaw has been found in drogonframework drogon up to 1.9.13. This affects the function makeCriteria in the library orm_lib/src/Criteria.cc of the component ORM. Executing a manipulation of the argument filter can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-65343 | 1 Apple | 4 Ios And Ipados, Ipados, Iphone Os and 1 more | 2026-09-21 | 7.5 High |
| A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. A remote attacker may be able to cause unexpected system termination. | ||||
| CVE-2026-52023 | 1 Kamailio | 1 Kamailio | 2026-09-21 | 7.5 High |
| An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree() | ||||
| CVE-2026-65347 | 1 Apple | 4 Ios And Ipados, Ipados, Iphone Os and 1 more | 2026-09-21 | 6.5 Medium |
| The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to a denial-of-service. | ||||
| CVE-2026-79419 | 1 Emxtecnologia | 1 Gestao X Business Suite | 2026-09-21 | 8.7 High |
| A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao/Imagens.aspx endpoint, allowing an authenticated attacker to inject arbitrary JavaScript code that is reflected and executed in the context of a victim's browser. | ||||
| CVE-2026-78849 | 1 Netgate | 1 Pfsense | 2026-09-21 | 5.4 Medium |
| Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 allows a remote attacker to execute arbitrary code via the captive_portal_status.widget.php file | ||||
| CVE-2026-75167 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-21 | 4.3 Medium |
| A broken access control vulnerability in the ugw-usr-edit method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to change the password of arbitrary accounts. | ||||
| CVE-2026-71620 | 2026-09-21 | 8.1 High | ||
| File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote attacker to execute arbitrary code via a crafted .php file | ||||
| CVE-2026-94215 | 1 Redhat | 2 Build Keycloak, Red Hat Single Sign On | 2026-09-21 | 5.5 Medium |
| A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses a per-request in-memory cache to resolve clients by their unique identifier without verifying if the client belongs to the realm specified in the request path. This allows an administrator with limited privileges to read or modify sensitive client configurations in the master realm by accessing them through a realm they control. Successful exploitation could lead to the exposure of client credentials or the redirection of administrative login attempts to malicious sites. | ||||
| CVE-2026-94213 | 1 Redhat | 2 Build Keycloak, Red Hat Single Sign On | 2026-09-21 | 4.9 Medium |
| A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy evaluation endpoint, which is used by administrators to test how access policies apply to specific users. Due to missing authorization checks, a delegated administrator with limited viewing privileges can access the full profile and role information of any user in the realm, even if they are not permitted to view user details. This could lead to the exposure of sensitive information such as email addresses and assigned security roles. | ||||
| CVE-2026-52295 | 1 Ffmpeg | 1 Ffmpeg | 2026-09-21 | 2.9 Low |
| FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavformat/iamf_writer.c. | ||||
| CVE-2026-67398 | 1 Webpros | 1 Whmcs | 2026-09-21 | N/A |
| Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions. | ||||
| CVE-2026-79418 | 1 Emxtecnologia | 1 Gestao X Business Suite | 2026-09-21 | 8.7 High |
| EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the context of other authenticated users, potentially resulting in session hijacking, account takeover, and unauthorized actions. | ||||
| CVE-2026-79573 | 2026-09-21 | 6.5 Medium | ||
| L-ONE v1.0.0 was discovered to contain multiple SQL injection vulnerabilities in the /attachment/getBusinessUploadList component via the busid, id, and taskid parameters. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. | ||||
| CVE-2026-52307 | 1 Classcms | 1 Classcms | 2026-09-21 | 5.4 Medium |
| An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the title field. | ||||
| CVE-2026-75308 | 2026-09-21 | 6.1 Medium | ||
| yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload of the system lacks file type validation. Attackers can upload files of any type, including HTML, JSP, and other executable files. | ||||
| CVE-2026-87469 | 1 Google | 1 Chrome | 2026-09-21 | 4.3 Medium |
| Improper input validation in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via crafted network traffic. (Chromium security severity: Low) | ||||
| CVE-2026-79590 | 1 Mruby | 1 Mruby | 2026-09-21 | 6.5 Medium |
| A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling functions, resulting in undefined behavior and application crash. | ||||
| CVE-2024-10492 | 1 Redhat | 4 Build Keycloak, Jboss Enterprise Application Platform, Jbosseapxp and 1 more | 2026-09-21 | N/A |
| A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order to perform resource creation, for example, an LDAP provider configuration and set up a Vault read file, which will only inform whether that file exists or not. | ||||
| CVE-2024-9666 | 1 Redhat | 2 Build Keycloak, Jboss Enterprise Application Platform | 2026-09-21 | 4.7 Medium |
| A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accept non-IP values, such as obfuscated identifiers, without proper validation. This issue can lead to costly DNS resolution operations, which an attacker could exploit to tie up IO threads and potentially cause a denial of service. The attacker must have access to send requests to a Keycloak instance that is configured to accept proxy headers, specifically when reverse proxies do not overwrite incoming headers, and Keycloak is configured to trust these headers. | ||||