Export limit exceeded: 402652 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 51613 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (51613 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-85877 | 1 Microsoft | 2 Windows 11 24h2, Windows 11 24h2 | 2026-09-09 | 8.8 High |
| Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-79952 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | 5.3 Medium |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Encoding or Escaping of Output vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to launch of phishing attacks. | ||||
| CVE-2026-79964 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | 5.3 Medium |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Escape, Meta, or Control Sequences vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to launch of phishing attacks. | ||||
| CVE-2026-80239 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | 2.4 Low |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to information exposure. | ||||
| CVE-2026-79727 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | 3.3 Low |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. | ||||
| CVE-2026-9852 | 1 Hitachienergy | 2 Microscada Sys600, Microscada X Sys600 | 2026-09-09 | 7.8 High |
| A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment configured, execute malicious code on the user’s machine. To exploit this issue attackers would need a way to create arbitrary log messages. This could be achieved through normal functionality via SCIL scripts, a log injection vulnerability, or via the SYS600 broker. This vulnerability affects all Windows users regardless of their privilege level who can run the Notify service and export the log. | ||||
| CVE-2026-69442 | 1 Microsoft | 5 365 Apps, Office 2016, Office 2019 and 2 more | 2026-09-09 | 8.8 High |
| Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69626 | 1 Microsoft | 9 365 Apps, Microsoft 365, Office 2016 and 6 more | 2026-09-09 | 6.5 Medium |
| Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-69629 | 1 Microsoft | 6 365 Apps, Office 2019, Office 2021 and 3 more | 2026-09-09 | 8.8 High |
| Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-85788 | 1 Aws | 1 Aws Labs Mysql Mcp Server | 2026-09-09 | 5.5 Medium |
| Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via SQL inline comments that the regex engine does not treat as whitespace. To remediate this issue, users should upgrade to version 1.0.23. | ||||
| CVE-2026-70351 | 1 Microsoft | 1 Webp Image Extension | 2026-09-09 | 8.8 High |
| Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-87650 | 1 Google | 1 Chrome | 2026-09-09 | 9.6 Critical |
| Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-87654 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-09-09 | 9.6 Critical |
| Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-87604 | 1 Google | 1 Chrome | 2026-09-09 | 8.3 High |
| Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-87579 | 1 Google | 1 Chrome | 2026-09-09 | 8.8 High |
| Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-80076 | 1 Microsoft | 8 365 Apps, Microsoft 365, Office 2019 and 5 more | 2026-09-09 | 6.5 Medium |
| Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-78513 | 1 Microsoft | 10 365 Apps, Microsoft 365, Office 2019 and 7 more | 2026-09-09 | 5.5 Medium |
| Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-72977 | 1 Microsoft | 10 365 Apps, Microsoft 365, Office 2019 and 7 more | 2026-09-09 | 6.5 Medium |
| Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-85062 | 1 Omgovich | 1 Colord | 2026-09-09 | 5.3 Medium |
| Colord is a tiny yet powerful tool for high-performance color manipulations and conversions. Prior to 2.9.4, synchronous CSS color string matchers in src/colorModels/rgbString.ts, src/colorModels/hslString.ts, src/colorModels/hwbString.ts, src/colorModels/lchString.ts, and src/colorModels/cmykString.ts use the ambiguous numeric regular expression ([+-]?\d*.?\d+), allowing the same digits to be divided between overlapping quantifiers in quadratically many ways when malformed input is rejected. An attacker who can supply an unbounded color string to colord(), getFormat(), isEqual(), mix(), or contrast(), including through a request body, JSON field, or uploaded stylesheet, can block the processing thread with a multi-kilobyte payload. The affected matchers are parseRgbaString, parseHslaString, parseHwbaString, parseLchaString, and parseCmykaString. This issue is fixed in version 2.9.4. | ||||
| CVE-2026-52772 | 1 Yeswiki | 1 Yeswiki | 2026-09-09 | 5.5 Medium |
| YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and label-body contexts, resulting stored XSS in form renders. This issue has been patched in version 4.6.6. | ||||