Export limit exceeded: 394031 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (394031 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-25294 | 2026-09-17 | 7.4 High | ||
| Transient DOS while parsing frame during channel usage. | ||||
| CVE-2026-25290 | 2026-09-17 | 7.8 High | ||
| Memory Corruption when validating large data buffers from external sources using addition to check buffer length. | ||||
| CVE-2026-25284 | 2026-09-17 | 7.3 High | ||
| Information Disclosure when a pointer is reused after being deallocated. | ||||
| CVE-2026-25283 | 2026-09-17 | 8.8 High | ||
| Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size. | ||||
| CVE-2026-25282 | 2026-09-17 | 7.9 High | ||
| Transient DOS when processing unverified data from a neighboring system causes out of bound memory access. | ||||
| CVE-2026-25281 | 2026-09-17 | 7.4 High | ||
| Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation. | ||||
| CVE-2026-25280 | 2026-09-17 | 7.8 High | ||
| Memory corruption when processing escape handling flow with insufficient user buffer sizes. | ||||
| CVE-2026-25278 | 2026-09-17 | 7.8 High | ||
| Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying. | ||||
| CVE-2026-25275 | 2026-09-17 | 7.5 High | ||
| Transient DOS when processing authentication frames with invalid FILS information element header lengths. | ||||
| CVE-2026-25261 | 2026-09-17 | 6.7 Medium | ||
| Memory corruption while processing rear sensor IOCTL calls. | ||||
| CVE-2026-24081 | 2026-09-17 | 7.4 High | ||
| Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled. | ||||
| CVE-2026-24075 | 2026-09-17 | 7.8 High | ||
| Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions. | ||||
| CVE-2026-24074 | 2026-09-17 | 7.8 High | ||
| Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations. | ||||
| CVE-2026-24073 | 2026-09-17 | 7.8 High | ||
| Memory corruption when processing decode statistics due to insufficient validation of offset against structure size. | ||||
| CVE-2025-59607 | 2026-09-17 | 7.8 High | ||
| Memory Corruption when copying large input data exceeds normal allocation limits. | ||||
| CVE-2026-50604 | 2026-09-17 | N/A | ||
| A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially allowing access to functionality that should be restricted. | ||||
| CVE-2026-50603 | 2026-09-17 | N/A | ||
| A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions. | ||||
| CVE-2026-83041 | 1 Oracle | 1 Webcenter Portal | 2026-09-17 | 7.7 High |
| Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N). | ||||
| CVE-2026-83043 | 1 Oracle | 1 Webcenter Portal | 2026-09-17 | 9.6 Critical |
| Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). | ||||
| CVE-2026-83044 | 1 Oracle | 1 Xml Gateway | 2026-09-17 | 7.1 High |
| Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle XML Gateway. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle XML Gateway. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L). | ||||