Export limit exceeded: 398587 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 398587 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 398587 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (101105 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-79740 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | 7.5 High |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure. | ||||
| CVE-2026-79950 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | 7.5 High |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure. | ||||
| CVE-2025-12737 | 1 Wso2 | 16 Api Control Plane, Api Manager, Identity Server and 13 more | 2026-09-09 | 8.4 High |
| The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system. | ||||
| CVE-2026-79692 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | 7.3 High |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an External Control of File Name or Path vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to filesystem access for attacker. | ||||
| CVE-2026-79637 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | 7.7 High |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. | ||||
| CVE-2026-78490 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | 7.5 High |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Restriction of Excessive Authentication Attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to client-side request forgery. | ||||
| CVE-2026-78485 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | 7.3 High |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access | ||||
| CVE-2026-79641 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | 7.5 High |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges. | ||||
| CVE-2026-80122 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | 7.3 High |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. | ||||
| CVE-2026-9854 | 1 Hitachienergy | 2 Microscada Sys600, Microscada X Sys600 | 2026-09-09 | 7.8 High |
| A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine. | ||||
| CVE-2026-78494 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | 7.4 High |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. | ||||
| CVE-2026-9853 | 1 Hitachienergy | 2 Microscada Sys600, Microscada X Sys600 | 2026-09-09 | 7.8 High |
| A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself. Only the SYS600 system users should be permitted to view and modify application objects. | ||||
| CVE-2026-9852 | 1 Hitachienergy | 2 Microscada Sys600, Microscada X Sys600 | 2026-09-09 | 7.8 High |
| A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment configured, execute malicious code on the user’s machine. To exploit this issue attackers would need a way to create arbitrary log messages. This could be achieved through normal functionality via SCIL scripts, a log injection vulnerability, or via the SYS600 broker. This vulnerability affects all Windows users regardless of their privilege level who can run the Notify service and export the log. | ||||
| CVE-2026-87585 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-09-09 | 8.8 High |
| Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High) | ||||
| CVE-2026-87633 | 1 Google | 1 Chrome | 2026-09-09 | 8.6 High |
| Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High) | ||||
| CVE-2026-69442 | 1 Microsoft | 5 365 Apps, Office 2016, Office 2019 and 2 more | 2026-09-09 | 8.8 High |
| Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-85124 | 1 Fastify | 2 Fastify-http-proxy, Fastify\/http-proxy | 2026-09-09 | 7.5 High |
| @fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destination validation that the WebSocket path performs, and the underlying reply-from library only rejects forward-slash traversal, so a request containing backslash dot-segments can escape the boundary set by the prefix and rewritePrefix options. An unauthenticated network attacker can use this to reach upstream paths that were meant to stay hidden behind the proxy, resulting in disclosure of internal endpoints. This is a path traversal issue (CWE-22). Users should upgrade to @fastify/http-proxy 11.6.2 or later. | ||||
| CVE-2026-69629 | 1 Microsoft | 6 365 Apps, Office 2019, Office 2021 and 3 more | 2026-09-09 | 8.8 High |
| Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69632 | 1 Microsoft | 8 365 Apps, Microsoft 365, Office 2019 and 5 more | 2026-09-09 | 8.8 High |
| Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-77908 | 1 Microsoft | 1 Dynamics 365 | 2026-09-09 | 8.8 High |
| Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network. | ||||