Export limit exceeded: 396261 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 16406 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (16406 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-69485 | 1 Microsoft | 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more | 2026-09-10 | 8.8 High |
| Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-69770 | 1 Microsoft | 24 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 21 more | 2026-09-10 | 5.5 Medium |
| Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-68852 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-10 | 5.5 Medium |
| Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-78519 | 1 Microsoft | 11 365 Apps, Microsoft 365 Apps For Enterprise, Microsoft Office 2016 and 8 more | 2026-09-10 | 8.8 High |
| Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-21108 | 1 Samsung Mobile | 1 Bixby | 2026-09-10 | N/A |
| Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information. | ||||
| CVE-2026-54048 | 1 Apache | 1 Impala | 2026-09-10 | 5.3 Medium |
| Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages. Users are recommended to upgrade to version 4.5.2, which fixes this issue. | ||||
| CVE-2026-57866 | 1 Apache | 1 Impala | 2026-09-10 | 8.8 High |
| Server side request forgery in Apache Impala versions 4.4.x and 4.5.x. Authenticated Impala users with permissions to execute the ai_generate_text() function can exfiltrate secrets provided by the credential providers configured in the `hadoop.security.credential.provider.path` property of `core-site.xml`. The secret's key must be known to the user. | ||||
| CVE-2026-65181 | 1 Apache | 1 Impala | 2026-09-10 | 8.1 High |
| Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code. Users are recommended to upgrade to version 4.5.2, which fixes this issue. | ||||
| CVE-2026-19233 | 1 Schneider-electric | 1 Ecostruxure It Data Center Expert | 2026-09-10 | N/A |
| CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized command execution and disclosure of server data when an attacker with a privileged account sends crafted, unvalidated parameters to a server endpoint. | ||||
| CVE-2026-85165 | 1 N8n | 1 N8n | 2026-09-10 | 9.9 Critical |
| n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-edit permission can mutate host objects through expression evaluation, with changes persisting process-wide until restart. | ||||
| CVE-2026-85167 | 1 N8n | 1 N8n | 2026-09-10 | 6.5 Medium |
| n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All and Google Cloud Firestore Document Query operations, which build their JSON query by interpolating expression values directly into the query string before parsing. A value containing quote and brace characters can close the intended field and introduce new query operators, turning an intended single-document lookup into a full-collection read. | ||||
| CVE-2026-87497 | 1 Google | 1 Chrome | 2026-09-10 | 4.3 Medium |
| Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-89049 | 1 Aws | 1 Amazon Ssm Agent | 2026-09-10 | 9.9 Critical |
| A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role credentials of a managed instance and acting with that role's permissions from outside the instance, via a crafted destination host value that uses an alternate representation of a denied link-local address. To remediate this issue, users should upgrade to version 3.3.4851.0 or later. | ||||
| CVE-2026-69806 | 1 Microsoft | 3 .net, Visual Studio 2022, Visual Studio 2026 | 2026-09-10 | 7 High |
| Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-19584 | 1 Rapid7 | 1 Velociraptor | 2026-09-10 | 7.7 High |
| Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored. | ||||
| CVE-2026-0298 | 2 Palo Alto Networks, Paloaltonetworks | 2 Globalprotect App, Globalprotect | 2026-09-10 | 8.1 High |
| An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected. | ||||
| CVE-2026-74871 | 1 Jahlives | 1 Openssl Encrypt | 2026-09-10 | 6.2 Medium |
| openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key generation. When configured with a single KDF and no prior hashing stage, attackers can bypass memory-hard key derivation and perform offline password cracking at SHA-256 speed instead of the configured KDF cost. | ||||
| CVE-2026-74881 | 1 Jahlives | 1 Openssl Encrypt | 2026-09-10 | 6.5 Medium |
| openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who visits them. | ||||
| CVE-2026-86122 | 1 Rowboatlabs | 1 Rowboat | 2026-09-10 | 5 Medium |
| Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. Attackers can point these URLs at internal services and cloud metadata endpoints to perform server-side request forgery and enumerate internal network topology. | ||||
| CVE-2026-85691 | 1 The-vibe-company | 1 Megaparse | 2026-09-10 | 7.5 High |
| MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers can supply internal service URLs or metadata endpoints without authentication to read their responses directly from the JSON response. | ||||