Export limit exceeded: 389339 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 389339 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 389339 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (389339 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-79692 | 2026-09-09 | 7.3 High | ||
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an External Control of File Name or Path vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to filesystem access for attacker. | ||||
| CVE-2026-78490 | 2026-09-09 | 7.5 High | ||
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Restriction of Excessive Authentication Attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to client-side request forgery. | ||||
| CVE-2026-79695 | 2026-09-09 | 7.3 High | ||
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. | ||||
| CVE-2026-81646 | 2026-09-09 | 5.9 Medium | ||
| Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2026-81647 | 2026-09-09 | 5.3 Medium | ||
| Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2026-49315 | 2026-09-09 | 7.1 High | ||
| DoS vulnerability in the input device module. Impact: Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2026-41987 | 2026-09-09 | 6.2 Medium | ||
| Permission control vulnerability in the app management module. Impact: Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2026-49309 | 2026-09-09 | 4.8 Medium | ||
| Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||||
| CVE-2026-49313 | 2026-09-09 | 5.5 Medium | ||
| Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||||
| CVE-2026-87732 | 2026-09-09 | 6.2 Medium | ||
| An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then compares the tag. On a forged tag, the functions returns false, but the destination buffer already holds the full plaintext. | ||||
| CVE-2026-87736 | 2026-09-09 | 4.3 Medium | ||
| An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points. | ||||
| CVE-2026-87737 | 2026-09-09 | 5.9 Medium | ||
| An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time required for a lookup can depend on a secret. | ||||
| CVE-2026-21085 | 2026-09-09 | N/A | ||
| Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory. | ||||
| CVE-2026-21086 | 2026-09-09 | N/A | ||
| Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration. | ||||
| CVE-2026-21087 | 2026-09-09 | N/A | ||
| Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege. | ||||
| CVE-2026-80239 | 2026-09-09 | 2.4 Low | ||
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to information exposure. | ||||
| CVE-2026-78485 | 2026-09-09 | 7.3 High | ||
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access | ||||
| CVE-2026-78489 | 2026-09-09 | 5.9 Medium | ||
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass. | ||||
| CVE-2026-87821 | 1 Laradashboard | 1 Lara Dashboard | 2026-09-09 | 7.1 High |
| Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read internal HTTP services and cloud metadata including IAM credentials by supplying malicious URLs without host validation or redirect restrictions. | ||||
| CVE-2026-87820 | 1 Cyberpanel | 1 Cyberpanel | 2026-09-09 | 5.3 Medium |
| CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated AI Scanner debugging endpoints that disclose administrator usernames, API-key prefixes, scan identifiers, target domains, and account metadata. Unauthenticated attackers can enumerate panel administrators and recent scanner activity to inventory multi-tenant installations and facilitate follow-on attacks. | ||||