Export limit exceeded: 378662 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (378662 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16137 | 1 Progress | 1 Sharefile Storage Zones Controller | 2026-08-17 | 7.2 High |
| In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code. | ||||
| CVE-2026-59911 | 1 Dell | 1 Objectscale | 2026-08-17 | 5.5 Medium |
| Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | ||||
| CVE-2026-11719 | 1 Google | 1 Mcp Toolbox For Databases | 2026-08-17 | 8.1 High |
| An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol handlers. While the 2025-11-25 protocol version handler correctly enforces per-tool restrictions defined by scopesRequired, older supported protocol versions (2025-06-18, 2025-03-26, and 2024-11-05) omit this check. An authenticated client with low-privilege tokens (e.g., read) can bypass the intended per-tool scope restrictions and execute high-privilege tools (e.g., admin) simply by specifying an older protocol version in the MCP-Protocol-Version header, or by omitting the header entirely (which causes the server to default to the vulnerable 2024-11-05 handler). | ||||
| CVE-2019-25758 | 1 Wdmtech | 1 Vbizz | 2026-08-17 | 8.8 High |
| Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to upload arbitrary PHP files by submitting malicious files through the profile_pic parameter. Attackers can upload PHP files via POST requests to the employee view endpoint and execute them from the uploads directory to achieve remote code execution. | ||||
| CVE-2019-25759 | 1 Wdmtech | 1 Vbizz | 2026-08-17 | 7.1 High |
| Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the payid parameter. Attackers can submit POST requests to the employee management interface with crafted payid array values containing SQL commands to extract sensitive database information including version and database names. | ||||
| CVE-2026-62820 | 1 Microsoft | 9 Windows 10 1607, Windows 10 1809, Windows Server 2016 and 6 more | 2026-08-17 | 8.1 High |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-75060 | 2026-08-17 | 8.4 High | ||
| In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools | ||||
| CVE-2026-75059 | 2026-08-17 | 4.4 Medium | ||
| In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible | ||||
| CVE-2026-75056 | 2026-08-17 | 7.8 High | ||
| In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible | ||||
| CVE-2026-75055 | 2026-08-17 | 5.5 Medium | ||
| In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE | ||||
| CVE-2026-75053 | 2026-08-17 | 5.4 Medium | ||
| In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint | ||||
| CVE-2026-75050 | 2026-08-17 | 7.1 High | ||
| In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters | ||||
| CVE-2026-75049 | 2026-08-17 | 6.5 Medium | ||
| In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint | ||||
| CVE-2026-75048 | 2026-08-17 | 8.2 High | ||
| In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible | ||||
| CVE-2026-75047 | 2026-08-17 | 6.5 Medium | ||
| In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint | ||||
| CVE-2026-75046 | 2026-08-17 | 4.3 Medium | ||
| In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint | ||||
| CVE-2026-75044 | 2026-08-17 | 8.1 High | ||
| In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint | ||||
| CVE-2026-62881 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-08-17 | 6.7 Medium |
| Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-62883 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-08-17 | 6.7 Medium |
| Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2025-27772 | 2026-08-17 | N/A | ||
| UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/new_run` endpoint is vulnerable to remote code execution via the `checks` and `metadata` parameters. Any user that has access to UpTrain and a valid authentication method may be able to execute arbitrary code in the context of the host running UpTrain, which in most cases will be the docker container as suggested by the documentation. As of time of publication, no known patch is available. | ||||