Export limit exceeded: 401173 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (102062 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-59685 | 1 Apache | 1 Http Server | 2026-10-01 | 7.5 High |
| Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | ||||
| CVE-2026-56449 | 2 Apache, Redhat | 2 Http Server, Hummingbird | 2026-10-01 | 7.5 High |
| Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | ||||
| CVE-2021-27065 | 1 Microsoft | 1 Exchange Server | 2026-10-01 | 7.8 High |
| Microsoft Exchange Server Remote Code Execution Vulnerability | ||||
| CVE-2021-26858 | 1 Microsoft | 1 Exchange Server | 2026-10-01 | 7.8 High |
| Microsoft Exchange Server Remote Code Execution Vulnerability | ||||
| CVE-2021-26411 | 1 Microsoft | 17 Edge, Internet Explorer, Windows 10 1507 and 14 more | 2026-10-01 | 8.8 High |
| Internet Explorer Memory Corruption Vulnerability | ||||
| CVE-2021-20022 | 2 Microsoft, Sonicwall | 20 Windows, Email Security, Email Security Appliance 3300 and 17 more | 2026-10-01 | 7.2 High |
| SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. | ||||
| CVE-2020-12812 | 1 Fortinet | 1 Fortios | 2026-10-01 | 7.5 High |
| An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username. | ||||
| CVE-2018-7602 | 2 Debian, Drupal | 2 Debian Linux, Drupal | 2026-10-01 | 8.1 High |
| A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild. | ||||
| CVE-2026-67987 | 2026-10-01 | 7.5 High | ||
| crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains polynomial-time regular expression denial-of-service conditions in think-tag response parsing on Ruby 3.1.x. A malicious or anomalous model response containing many unterminated <think> tags can cause excessive CPU consumption in two consecutive regular expressions and delay chat-completion processing | ||||
| CVE-2026-104051 | 1 Hascheksolutions | 1 Pictshare | 2026-10-01 | 8.2 High |
| PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy. | ||||
| CVE-2026-15911 | 1 Confluent | 1 Confluent-kafka | 2026-10-01 | 7.4 High |
| Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation. | ||||
| CVE-2026-55232 | 1 Givanz | 1 Vvveb | 2026-10-01 | 7.6 High |
| Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's SSRF guard resolves a host with an IPv4-only function and never inspects IPv6, so any host that lacks an A record passes a private-range check. Editor oEmbed proxy fetches an attacker-supplied URL server side and reflects a response body, so an authenticated admin-panel user (default role site_admin or higher) can read internal-only services and cloud metadata, including IAM credentials, using an IPv6 literal or a domain that carries only an AAAA record. This issue has been patched in version 1.0.8.6. | ||||
| CVE-2026-14316 | 1 Fortra | 1 Core Privileged Access Manager (boks) | 2026-10-01 | 8.1 High |
| The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of the heap allocation. | ||||
| CVE-2026-79896 | 1 Fortra | 1 Boks Manager | 2026-10-01 | 7.5 High |
| Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption. | ||||
| CVE-2026-100514 | 2026-10-01 | 7.5 High | ||
| Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions. | ||||
| CVE-2026-55230 | 1 Givanz | 1 Vvveb | 2026-10-01 | 8.7 High |
| Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's HTML sanitizer fails to strip event-handler attributes when a tag carries a greater-than character inside a quoted attribute value. A low-privilege content author (default role author or contributor) can store a payload in post or product content that runs JavaScript in a browser of every visitor and of any administrator who views or previews that content, which opens a path to admin account takeover. This issue has been patched in version 1.0.8.6. | ||||
| CVE-2026-55231 | 1 Givanz | 1 Vvveb | 2026-10-01 | 7.2 High |
| Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, a flawed central path sanitizer lets an authenticated admin-panel user who holds backup access (default role site_admin or higher) read and delete arbitrary files on a server. An attacker can recover database credentials from config/db.php, read host files such as /etc/passwd, and delete config/db.php to push a site back into install mode for a full takeover. This issue has been patched in version 1.0.8.6. | ||||
| CVE-2018-15982 | 6 Adobe, Apple, Google and 3 more | 12 Flash Player, Flash Player Installer, Mac Os X and 9 more | 2026-10-01 | 7.8 High |
| Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution. | ||||
| CVE-2026-97277 | 2026-10-01 | 7.6 High | ||
| Subscriber Broken Access Control in Social Boost <= 3.6.2 versions. | ||||
| CVE-2026-94390 | 2 Dotstore, Wordpress-extensions | 2 Hide Shipping Method For Woocommerce, Hide Shipping Method For Woocommerce | 2026-10-01 | 7.2 High |
| Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions. | ||||