Export limit exceeded: 395917 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 395917 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 395917 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (395917 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-78962 | 1 Google | 1 Chrome | 2026-08-27 | 4.3 Medium |
| Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-48426 | 1 Adobe | 1 Substance 3d Designer | 2026-08-27 | 7.8 High |
| Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||||
| CVE-2026-78968 | 1 Google | 1 Chrome | 2026-08-27 | 6.5 Medium |
| Missing authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially spoof address bar via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-48427 | 1 Adobe | 1 Substance 3d Designer | 2026-08-27 | 7.8 High |
| Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||||
| CVE-2026-48428 | 1 Adobe | 1 Substance 3d Designer | 2026-08-27 | 7.8 High |
| Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||||
| CVE-2026-48429 | 1 Adobe | 1 Substance 3d Designer | 2026-08-27 | 5.5 Medium |
| Substance3D - Designer is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||||
| CVE-2026-47890 | 1 Spring | 1 Spring Framework | 2026-08-27 | 9.8 Critical |
| Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 | ||||
| CVE-2026-13414 | 2026-08-27 | 4.8 Medium | ||
| The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain (and exposed to anonymous visitors on others), allowing unauthenticated attackers to disable the site's maintenance/coming-soon mode under a non-default countdown configuration. | ||||
| CVE-2026-16569 | 2026-08-27 | 4.3 Medium | ||
| The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock quantity of arbitrary products. | ||||
| CVE-2026-11747 | 1 Seres Software | 1 Syweb | 2026-08-27 | 6.1 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Seres Software syWEB allows Reflected XSS. This issue affects syWEB: through 27082026. NOTE: The vendor was contacted and it was learned that the product is not supported. | ||||
| CVE-2026-11754 | 1 Seres Software | 1 Syweb | 2026-08-27 | 5.3 Medium |
| Observable discrepancy vulnerability in Seres Software syWEB allows Account Footprinting. This issue affects syWEB: through 27082026. NOTE: The vendor was contacted and it was learned that the product is not supported. | ||||
| CVE-2026-48430 | 1 Adobe | 1 Substance 3d Designer | 2026-08-27 | 7.8 High |
| Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||||
| CVE-2026-48431 | 1 Adobe | 1 Substance 3d Designer | 2026-08-27 | 7.8 High |
| Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||||
| CVE-2026-78975 | 1 Google | 1 Chrome | 2026-08-27 | 6.5 Medium |
| Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-48432 | 1 Adobe | 1 Substance 3d Designer | 2026-08-27 | 7.8 High |
| Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||||
| CVE-2026-48433 | 1 Adobe | 1 Substance 3d Designer | 2026-08-27 | 7.8 High |
| Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||||
| CVE-2026-71564 | 1 Adobe | 1 Substance 3d Designer | 2026-08-27 | 7.8 High |
| Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||||
| CVE-2026-78981 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-08-27 | 6.5 Medium |
| Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to potentially obtain sensitive information via a local program. (Chromium security severity: Low) | ||||
| CVE-2026-78985 | 1 Google | 1 Chrome | 2026-08-27 | 9.6 Critical |
| Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-81672 | 2026-08-27 | N/A | ||
| SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video parameter. The application does not sanitize input before constructing SQL queries, which results in execution errors when malicious input is provided. The vulnerability exposes internal file paths and complete stack traces through the Slim framework’s error handler, which increases the severity due to the combination of information disclosure and SQL injection. | ||||