Export limit exceeded: 23489 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 23489 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 23489 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 23489 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 23489 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 23489 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (23489 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-62565 1 Oracle 1 Hrms 2026-08-04 7.1 High
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year End). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (US) accessible data as well as unauthorized update, insert or delete access to some of Oracle HRMS (US) accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
CVE-2026-16415 1 Google 1 Chrome 2026-08-04 5.4 Medium
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
CVE-2026-16416 1 Google 1 Chrome 2026-08-04 9.3 Critical
Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
CVE-2026-16417 1 Google 1 Chrome 2026-08-04 3.1 Low
Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
CVE-2026-16423 1 Google 1 Chrome 2026-08-04 8.8 High
Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-50330 1 Zipgenius 1 Zipgenius 2026-08-04 8.8 High
An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.
CVE-2025-50325 1 Bandisoft 1 Bandizip 2026-08-04 5.4 Medium
BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of BandiZip
CVE-2026-45820 1 101arrowz 1 Fflate 2026-08-04 N/A
fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop indefinitely due to out-of-bounds reads returning undefined, which coerces to 0, keeping the loop condition permanently true.
CVE-2026-57600 1 Hikvision 4 Ds-2cd Series, Ds-2de Series, Ds-2dp Series and 1 more 2026-08-04 7.5 High
Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.
CVE-2026-18774 1 Nousresearch 1 Hermes-agent 2026-08-04 6.3 Medium
A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image Generation Provider. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-24080 2026-08-04 7.8 High
Memory Corruption when handling malformed request parameters in the fingerprint TA.
CVE-2026-46712 2026-08-04 N/A
Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain a vulnerability where a lack of proper permission checks allows access to certain data points from the Direct Messages (formerly Chat) feature, regardless of account permissions. This vulnerability occurs whether or not federation is enabled. Notes created with "specified" visibility (formerly "direct" visibility) are not affected. This issue has been fixed in version 2026.5.4.
CVE-2025-34163 2026-08-04 N/A
Dongsheng Logistics Software exposes an unauthenticated endpoint at /CommMng/Print/UploadMailFile that fails to enforce proper file type validation and access control. An attacker can upload arbitrary files, including executable scripts such as .ashx, via a crafted multipart/form-data POST request. This allows remote code execution on the server, potentially leading to full system compromise. The vulnerability is presumed to affect builds released prior to July 2025 and is remediated in newer versions of the product, though the exact affected range remains undefined. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-07-23 UTC.
CVE-2026-25292 2026-08-04 7.6 High
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
CVE-2026-25289 2026-08-04 9.6 Critical
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
CVE-2026-25288 2026-08-04 7.4 High
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
CVE-2026-67198 2026-08-04 7.5 High
Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or incomplete protobuf messages. Attackers can send well-formed requests such as ViewToArrowReq with no viewport set or MakeTableReq with no data field to trigger unwrap() calls on None values at nine distinct sites, causing the process to abort with SIGABRT.
CVE-2026-40714 1 Dell 1 Powerprotect Data Manager 2026-08-04 7.2 High
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
CVE-2026-49499 1 Dell 1 Powerprotect Data Manager 2026-08-04 8.8 High
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
CVE-2026-46737 1 Dell 1 Powerprotect Data Manager 2026-08-04 6.7 Medium
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.