Export limit exceeded: 390860 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (390860 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-33967 | 1 Samsung | 1 Exynos 1330 Firmware | 2026-09-14 | 2.8 Low |
| An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, an out-of-bounds array access vulnerability in the error-handling path leads to memory corruption. | ||||
| CVE-2026-33966 | 1 Samsung | 1 Exynos 1330 Firmware | 2026-09-14 | 2.8 Low |
| An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. An information Leak occurs in the camera driver due to Insertion of Sensitive Information Into Debugging Code. | ||||
| CVE-2026-85129 | 2026-09-14 | 8.8 High | ||
| The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web scripts which will execute for anyone viewing the site, including administrators. The same request destroys the site's existing theme settings. | ||||
| CVE-2026-88793 | 2026-09-14 | 8.8 High | ||
| The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing unauthenticated attackers to store arbitrary web scripts which will execute in the session of any user viewing the affected content, including an administrator. | ||||
| CVE-2026-89050 | 2026-09-14 | 4.3 Medium | ||
| The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a paid ad placement without payment. | ||||
| CVE-2026-90615 | 1 Sourcecodester | 1 Class And Exam Timetabling System | 2026-09-14 | 4.3 Medium |
| A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /subject1.php. Such manipulation of the argument subject leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. | ||||
| CVE-2026-33964 | 1 Samsung | 1 Exynos 1580 Firmware | 2026-09-14 | 6.4 Medium |
| An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent to the camera driver, causing limited information disclosure or denial of service. | ||||
| CVE-2026-33963 | 1 Samsung | 1 Exynos 1330 Firmware | 2026-09-14 | 7.5 High |
| An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service. | ||||
| CVE-2026-33962 | 1 Samsung | 1 Exynos 850 Firmware | 2026-09-14 | 2.8 Low |
| An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A malformed Netlink command can trigger an out-of-bounds read, potentially leading to information leakage. | ||||
| CVE-2026-33960 | 1 Samsung | 1 Exynos 1330 Firmware | 2026-09-14 | 2.8 Low |
| An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000. . A malformed ioctl command to the Wi-Fi interface device can lead to improper buffer size allocation, resulting in an out-of-bounds write and causing a denial of service (DoS). | ||||
| CVE-2026-90614 | 1 Fedml-ai | 1 Fedml | 2026-09-14 | 6.3 Medium |
| A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend. This manipulation of the argument s3_key_str causes deserialization. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-36453 | 1 Rhymix | 1 Rhymix | 2026-09-14 | 7.4 High |
| Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables. | ||||
| CVE-2026-37008 | 1 Crewai | 1 Crewai | 2026-09-14 | 8.1 High |
| CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling ctypes.CDLL(None) loads the C library without relying in any import statements. In other words, a within-process sandbox cannot merely account for the import system and instead must account for the complete runtime of the Python interpreter. | ||||
| CVE-2026-38332 | 2026-09-14 | 2.9 Low | ||
| TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length. | ||||
| CVE-2025-64059 | 1 Getgrav | 1 Grav | 2026-09-14 | 1.8 Low |
| Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content. | ||||
| CVE-2025-70819 | 2026-09-14 | 6.3 Medium | ||
| Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file. | ||||
| CVE-2025-70820 | 2026-09-14 | 3.5 Low | ||
| Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder. | ||||
| CVE-2026-29810 | 1 Cyberpanel | 1 Cyberpanel | 2026-09-14 | 4.3 Medium |
| CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic. | ||||
| CVE-2026-33957 | 1 Samsung | 1 Exynos 1580 Firmware | 2026-09-14 | 4.2 Medium |
| An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the custos_iwc device enables out-of-bounds read and write, potentially leading to memory corruption or information leakage. | ||||
| CVE-2026-33956 | 1 Samsung | 1 Exynos 1330 Firmware | 2026-09-14 | 2.8 Low |
| An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Sending a malformed message to the test_msg sysfs entry causes an out-of-bounds write, leading to denial of service. | ||||