Export limit exceeded: 395847 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (395847 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66631 | 2026-09-17 | 7.6 High | ||
| Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions. | ||||
| CVE-2026-66624 | 2026-09-17 | 7.6 High | ||
| Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions. | ||||
| CVE-2026-66575 | 2026-09-17 | 5.3 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions. | ||||
| CVE-2024-58384 | 1 Tornadoweb | 1 Tornado | 2026-09-17 | 5.4 Medium |
| Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests. | ||||
| CVE-2026-91924 | 1 Sosedoff | 1 Pgweb | 2026-09-17 | 8.5 High |
| pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, allowing attackers to supply arbitrary database connection strings. Attackers can bypass the resource-to-database mapping by providing a custom session identifier and connection URL to access unauthorized databases and internal services. | ||||
| CVE-2026-91925 | 1 Polyaxon | 1 Polyaxon | 2026-09-17 | 8.8 High |
| Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code. Attackers can submit runs with Jinja2 payloads in queue, namespace, conditions, presets, or dependencies fields to execute operating system commands in the scheduler process context, exposing database credentials and service tokens. | ||||
| CVE-2026-91997 | 2 Cs-technologies, Evolution-foundation | 2 Evolution, Evolution-api | 2026-09-17 | 5.3 Medium |
| evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restrictions to access sensitive metrics disclosing server version, database client name, configured server URL, and WhatsApp instance details. | ||||
| CVE-2026-92033 | 1 Mozilla | 1 Firefox | 2026-09-17 | 8.8 High |
| Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156. | ||||
| CVE-2026-25282 | 1 Qualcomm | 1 Snapdragon | 2026-09-17 | 7.9 High |
| Transient DOS when processing unverified data from a neighboring system causes out of bound memory access. | ||||
| CVE-2026-66578 | 2 Propertyhive, Wordpress | 2 Propertyhive, Wordpress | 2026-09-17 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions. | ||||
| CVE-2026-66608 | 2 Unlimited-elements, Wordpress | 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Wordpress | 2026-09-17 | 6.4 Medium |
| Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions. | ||||
| CVE-2026-72987 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 11 more | 2026-09-17 | 8.1 High |
| Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-72979 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 11 more | 2026-09-17 | 9.8 Critical |
| Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-72967 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-17 | 7.8 High |
| Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-73003 | 1 Microsoft | 16 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 13 more | 2026-09-17 | 7 High |
| Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-73005 | 1 Microsoft | 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more | 2026-09-17 | 7 High |
| Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-73009 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-17 | 9.8 Critical |
| Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-73010 | 1 Microsoft | 6 Windows 10 1809, Windows Server 2019, Windows Server 2019 (server Core Installation) and 3 more | 2026-09-17 | 9.8 Critical |
| Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-73012 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-17 | 8.8 High |
| Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-85893 | 1 Microsoft | 1 Edge Chromium | 2026-09-17 | 8.8 High |
| Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. | ||||