Search

Search Results (381211 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-41371 1 Microsoft 22 Windows 10, Windows 10 1507, Windows 10 1607 and 19 more 2026-08-19 4.4 Medium
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2021-41368 1 Microsoft 7 365 Apps, Office, Office 2013 and 4 more 2026-08-19 6.1 Medium
Microsoft Access Remote Code Execution Vulnerability
CVE-2021-41367 1 Microsoft 22 Windows 10, Windows 10 1507, Windows 10 1607 and 19 more 2026-08-19 7.8 High
NTFS Elevation of Privilege Vulnerability
CVE-2021-41366 1 Microsoft 18 Windows 10, Windows 10 1507, Windows 10 1607 and 15 more 2026-08-19 7.8 High
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
CVE-2021-36957 1 Microsoft 12 Windows 10, Windows 10 1607, Windows 10 1809 and 9 more 2026-08-19 7.8 High
Windows Desktop Bridge Elevation of Privilege Vulnerability
CVE-2023-21808 1 Microsoft 27 .net, .net Framework, Powershell and 24 more 2026-08-19 7.8 High
.NET and Visual Studio Remote Code Execution Vulnerability
CVE-2023-21801 1 Microsoft 22 Windows 10, Windows 10 1507, Windows 10 1607 and 19 more 2026-08-19 7.8 High
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
CVE-2023-21718 1 Microsoft 1 Sql Server 2026-08-19 7.8 High
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVE-2023-21707 1 Microsoft 1 Exchange Server 2026-08-19 8.8 High
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-21684 1 Microsoft 21 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 18 more 2026-08-19 8.8 High
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
CVE-2026-20846 1 Microsoft 31 Office, Windows 10 1607, Windows 10 1809 and 28 more 2026-08-19 7.5 High
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
CVE-2017-20263 1 Focalpointx 2 Focalpoint, Focalpoint Pro / Free 2026-08-19 8.2 High
Joomla! Component FocalPoint Pro/Free 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_focalpoint, view=location, and a crafted id parameter containing SQL commands to extract sensitive database information.
CVE-2017-20264 1 Pulseextensions 1 Sponsor Wall 2026-08-19 7.1 High
Joomla! Component Sponsor Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wallid parameter. Attackers can send GET requests to index.php with the option=com_sponsorwall&task=click&wallid parameter containing SQL injection payloads to extract sensitive database information including credentials and configuration data.
CVE-2017-20265 1 Pulseextensions 1 Flip Wall 2026-08-19 7.1 High
Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wallid parameter. Attackers can send GET requests to index.php with the option=com_flipwall&task=click&wallid parameter containing SQL injection payloads to extract sensitive database information.
CVE-2017-20266 1 Joomshaper 2 Sp Movie Database, Standard Pro Movie Database 2026-08-19 8.2 High
Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchword parameter. Attackers can send GET requests to the searchresults view with crafted SQL payloads in the searchword parameter to extract sensitive database information.
CVE-2026-70657 1 9001 1 Copyparty 2026-08-19 4.3 Medium
Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory key, granting read access to the containing folder. This vulnerability was only reachable if both types of keys (filekeys and dirkeys) were manually enabled in the volume flags simultaneously. This issue is fixed in version 1.20.17.
CVE-2026-70667 1 Netflix 1 Lemur 2026-08-19 6.3 Medium
Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificates/verify.py checked the original CRL or OCSP URL but the later request could reach a different destination. The CRL requests.get call followed HTTP redirects without validating each Location target, so a public attacker-controlled URL could redirect to loopback, RFC1918, link-local, or instance-metadata addresses. Validation and connection also performed separate DNS resolutions, creating a time-of-check time-of-use window for DNS rebinding on both CRL and OCSP paths. An operator uploading a certificate through POST /api/1/certificates/upload could therefore induce blind internal requests despite the earlier mitigation. The fix disables redirects and pins validated addresses while preserving the correct Host value. This issue is fixed in version 1.9.3.
CVE-2026-70408 2026-08-19 N/A
An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.
CVE-2026-68922 2026-08-19 5.5 Medium
MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobsf/StaticAnalyzer/views/android/icon_analysis.py uses the Android manifest android:icon value to construct paths under the scan resource directory without rejecting traversal or verifying containment, allowing an authenticated user to upload a crafted ZIP or APK that reads a server file with an ALLOWED_EXTENSIONS suffix, copies it to DWD_DIR as the predictable name -icon., and retrieves it through the /download/ endpoint. The same behavior provides a file-existence oracle through the icon_path report field. This issue is fixed in version 4.5.1.
CVE-2026-53455 2026-08-19 N/A
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio generated a shell-based Git credential helper in custom_components/blueprint_studio/backend/git_manager.py by interpolating the configured Git username and token directly into executable helper script content without validating credential values. An attacker able to set Git credentials could include newline characters or shell syntax in a username or token. When Git executed the generated credential helper, the injected shell commands ran with the operating-system privileges of Home Assistant and could access or modify Home Assistant configuration data. This issue is fixed in version 2.5.2.