Export limit exceeded: 391940 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (391940 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-43788 | 1 Apple | 1 Macos | 2026-09-15 | 6.6 Medium |
| An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents. | ||||
| CVE-2026-43687 | 1 Apple | 5 Ios And Ipados, Macos, Tvos and 2 more | 2026-09-15 | 6.5 Medium |
| The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a malicious NFS server may disclose kernel memory. | ||||
| CVE-2025-9236 | 1 Portabilis | 2 I-diario, I-educar | 2026-09-15 | 6.3 Medium |
| A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php of the component Tipos de usuàrio Page. Such manipulation of the argument nm_tipo/descrição leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. Upgrading to version 2.12 mitigates this issue. Upgrading the affected component is advised. The vendor confirms: "The reported attack vector was tested against the corrected code, and the previously described SQL Injection behavior could no longer be reproduced." | ||||
| CVE-2023-46273 | 1 Extremenetworks | 1 Iq Engine | 2026-09-15 | 8.8 High |
| Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send. | ||||
| CVE-2023-50459 | 2026-09-15 | 5.4 Medium | ||
| An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts. | ||||
| CVE-2023-50460 | 2026-09-15 | 5.4 Medium | ||
| An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any frontend user in the system. | ||||
| CVE-2023-50462 | 2026-09-15 | 5.3 Medium | ||
| An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier is permitted by the plugin. This enables an unauthenticated user to display various content elements, leading to an insecure direct object reference (IDOR) issue with the potential to expose internal content elements. | ||||
| CVE-2024-23176 | 2026-09-15 | 5.4 Medium | ||
| An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS. | ||||
| CVE-2026-25832 | 1 Trustedfirmware | 1 Mbed Tls | 2026-09-15 | 3.7 Low |
| In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group. | ||||
| CVE-2023-37366 | 1 Samsung | 1 Exynos 850 Firmware | 2026-09-15 | 2.8 Low |
| An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300, an Exynos Auto T5123. In the Shannon SM Task, improper handling of a loop with an unreachable exit condition cannot guarantee the termination of a required service via a malformed SM message. | ||||
| CVE-2023-45858 | 1 Paessler | 1 Prtg Network Monitor | 2026-09-15 | 8.6 High |
| A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files. | ||||
| CVE-2026-33966 | 1 Samsung | 1 Exynos 1330 Firmware | 2026-09-15 | 2.8 Low |
| An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. An information Leak occurs in the camera driver due to Insertion of Sensitive Information Into Debugging Code. | ||||
| CVE-2023-40772 | 1 Dataease | 1 Dataease | 2026-09-15 | 4.3 Medium |
| A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component. | ||||
| CVE-2023-45023 | 2026-09-15 | 4.2 Medium | ||
| The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component. | ||||
| CVE-2023-46035 | 2026-09-15 | 5.9 Medium | ||
| The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents. | ||||
| CVE-2023-28148 | 1 Paessler | 1 Prtg Network Monitor | 2026-09-15 | 7.2 High |
| A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520. | ||||
| CVE-2023-22632 | 1 Paessler | 1 Prtg Network Monitor | 2026-09-15 | 2.7 Low |
| PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor. | ||||
| CVE-2026-23791 | 1 Samsung | 1 Exynos 1280 Firmware | 2026-09-15 | 4.2 Medium |
| An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability in the Exynos DPU driver (due to missing input length validation in color mode LUT parsing) leads to kernel memory corruption and potential privilege escalation. | ||||
| CVE-2026-33960 | 1 Samsung | 1 Exynos 1330 Firmware | 2026-09-15 | 2.8 Low |
| An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000. . A malformed ioctl command to the Wi-Fi interface device can lead to improper buffer size allocation, resulting in an out-of-bounds write and causing a denial of service (DoS). | ||||
| CVE-2025-68624 | 2026-09-15 | 4.3 Medium | ||
| N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user to send outbound email using MAIL FROM addresses belonging to other tenants. When connecting to the SMTP TCP port and performing SMTP AUTH with valid credentials, the server accepts arbitrary sender domains without enforcing any domain-to-account binding. As a result, an attacker from any tenant can impersonate other tenant domains, producing messages that pass SPF and DMARC validation. NOTE: N-able's position is that the behavior is intended functionality of its shared SMTP relay architecture and that the service does not represent that it enforces per-tenant sender-domain binding. | ||||