Export limit exceeded: 376218 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 376218 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (376218 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-6726 | 2026-08-11 | N/A | ||
| An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010. | ||||
| CVE-2026-14180 | 1 Redhat | 8 Apache Camel Hawtio, Camel Spring Boot, Enterprise Linux and 5 more | 2026-08-11 | 5.3 Medium |
| A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By sending a specially crafted request with an extremely large chunk size, an attacker can cause these values to overlap, tricking the parser into thinking a request has finished prematurely. This can allow a second, "smuggled" request to be processed out of sync, potentially bypassing security controls. | ||||
| CVE-2026-64919 | 1 Microsoft | 5 365 Apps, Access 2016, Office 2019 and 2 more | 2026-08-11 | 7.8 High |
| Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-70325 | 1 Microsoft | 7 365 Apps, Office 2019, Office 2021 and 4 more | 2026-08-11 | 5.5 Medium |
| Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-70320 | 1 Microsoft | 7 365 Apps, Office 2019, Office 2021 and 4 more | 2026-08-11 | 5.5 Medium |
| Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-70310 | 1 Microsoft | 8 365 Apps, Office 2019, Office 2021 and 5 more | 2026-08-11 | 5.5 Medium |
| Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-68797 | 1 Microsoft | 8 365 Apps, Excel 2016, Office 2019 and 5 more | 2026-08-11 | 5.5 Medium |
| Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-66806 | 2 Microsoft, Redhat | 6 365 Apps, Office 2019, Office 2021 and 3 more | 2026-08-11 | 5.5 Medium |
| Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-66301 | 1 Microsoft | 1 Dynamics 365 | 2026-08-11 | 6.5 Medium |
| Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network. | ||||
| CVE-2026-66154 | 2026-08-11 | 8.3 High | ||
| An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes. | ||||
| CVE-2026-66148 | 2026-08-11 | 6.3 Medium | ||
| An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges. | ||||
| CVE-2026-63530 | 1 Microsoft | 8 365 Apps, Office 2019, Office 2021 and 5 more | 2026-08-11 | 5.5 Medium |
| Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-39833 | 1 Golang | 2 Crypto, Ssh | 2026-08-11 | 9.1 Critical |
| The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested. | ||||
| CVE-2026-39832 | 1 Golang | 2 Crypto, Ssh | 2026-08-11 | 9.1 Critical |
| When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them. | ||||
| CVE-2026-73250 | 2026-08-11 | N/A | ||
| Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the Notepad++ Windows 11 x64 and ARM64 installer passes the attacker-influenced installation directory `$INSTDIR` from PowerEditor/installer/nppSetup.nsi into a PowerShell `-Command` string used by RegisterMSIX to invoke Add-AppxPackage, allowing PowerShell subexpression syntax such as `$()` in the installation path to execute commands in the installer's security context when the context menu component is selected. This issue is fixed in version 8.9.7. | ||||
| CVE-2026-67558 | 2026-08-11 | 7.4 High | ||
| The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject forged hormone measurements into the victim's cloud record and clinical trend view. | ||||
| CVE-2026-73283 | 1 Openbsd | 1 Openssh | 2026-08-11 | 2.5 Low |
| In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not. | ||||
| CVE-2026-73282 | 1 Openbsd | 1 Openssh | 2026-08-11 | 4.8 Medium |
| In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent. | ||||
| CVE-2026-73281 | 1 Openbsd | 1 Openssh | 2026-08-11 | 3.5 Low |
| In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension. | ||||
| CVE-2026-73243 | 2026-08-11 | 5.8 Medium | ||
| kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /addTask endpoint in kkFileView is omitted from TrustHostFilter and TrustDirFilter in server/src/main/java/cn/keking/config/WebConfig.java, allowing FileConvertQueueTask to fetch an attacker-selected URL after FileHandlerService#getFileAttribute uses the fullfilename parameter to force an OFFICE, COMPRESS, or CAD type. This issue is fixed in version 5.0.1. | ||||