Export limit exceeded: 371569 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (371569 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-81388 | 1 Microsoft | 18 365, 365 Apps, Excel and 15 more | 2026-09-10 | 7.8 High |
| Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-20512 | 1 Mediatek, Inc. | 1 Mediatek Chipset | 2026-09-10 | 6.7 Medium |
| In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087540; Issue ID: MSV-8246. | ||||
| CVE-2026-12650 | 1 Ivanti | 1 Neurons For Itsm | 2026-09-10 | 9.9 Critical |
| A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. | ||||
| CVE-2026-14873 | 2026-09-10 | 8 High | ||
| The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their details like arbitrary user passwords, including administrator passwords, to a known plugin-configured custom value, enabling full account takeover of the site. This makes it possible for authenticated attackers, with subscriber-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account. | ||||
| CVE-2026-18386 | 2026-09-10 | 4.9 Medium | ||
| The WP BackItUp Community Edition plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.0 via the 'backup_file' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The basename() normalization present in the handler only executes when the traversed target path does not exist, providing no protection against reads of existing files. | ||||
| CVE-2026-15823 | 2026-09-10 | 4.3 Medium | ||
| The Builderall Cheetah For Wp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disable() function in versions up to, and including, 3.0.2. The wp_ajax_ba_cheetah_disable AJAX handler is registered without any capability or nonce verification, and the target post_id is sourced directly from user-controlled $_POST['ba_cheetah_data']['post_id']. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disable the page builder layout on arbitrary posts by setting the _ba_cheetah_enabled post meta to false, including on posts owned by other users. | ||||
| CVE-2026-78971 | 2026-09-10 | N/A | ||
| In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions. | ||||
| CVE-2026-79588 | 2026-09-10 | 4.3 Medium | ||
| U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP. | ||||
| CVE-2026-83527 | 1 Ivanti | 1 Sentry | 2026-09-10 | 8.1 High |
| An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access. | ||||
| CVE-2026-12646 | 1 Ivanti | 1 Neurons For Itsm | 2026-09-10 | 9.9 Critical |
| A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. | ||||
| CVE-2026-81391 | 1 Microsoft | 14 365 Apps, Excel, Excel 2016 and 11 more | 2026-09-10 | 5.5 Medium |
| Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-81393 | 1 Microsoft | 14 365 Apps, Excel, Excel 2016 and 11 more | 2026-09-10 | 5.5 Medium |
| Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-12745 | 1 Ivanti | 1 Neurons For Itsm | 2026-09-10 | 9.8 Critical |
| A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server. | ||||
| CVE-2026-12651 | 1 Ivanti | 1 Neurons For Itsm | 2026-09-10 | 8.8 High |
| A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. | ||||
| CVE-2026-12648 | 1 Ivanti | 1 Neurons For Itsm | 2026-09-10 | 8.8 High |
| A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. | ||||
| CVE-2026-12645 | 1 Ivanti | 1 Neurons For Itsm | 2026-09-10 | 9.9 Critical |
| A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. | ||||
| CVE-2026-12647 | 1 Ivanti | 1 Neurons For Itsm | 2026-09-10 | 9.9 Critical |
| A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. | ||||
| CVE-2026-69379 | 1 Microsoft | 5 Windows 11 23h2, Windows 11 24h2, Windows 11 25h2 and 2 more | 2026-09-10 | 7 High |
| Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-78512 | 1 Microsoft | 12 365 Apps, Microsoft 365, Microsoft Office Ltsc For Mac 2021 and 9 more | 2026-09-10 | 8.8 High |
| Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-68787 | 1 Microsoft | 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more | 2026-09-10 | 7.8 High |
| Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally. | ||||