Export limit exceeded: 100519 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (100519 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-84099 | 2026-09-12 | 8.1 High | ||
| The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site. | ||||
| CVE-2026-84047 | 2026-09-12 | 8.6 High | ||
| The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-81090 | 2026-09-12 | 7.2 High | ||
| The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution. | ||||
| CVE-2026-80491 | 2026-09-12 | 8.6 High | ||
| The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks. | ||||
| CVE-2026-81954 | 1 Microsoft | 18 365, 365 Apps, Excel and 15 more | 2026-09-12 | 7.8 High |
| Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-72973 | 1 Microsoft | 15 365, 365 Apps, Microsoft 365 and 12 more | 2026-09-12 | 8.8 High |
| Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-76202 | 1 Adobe | 6 Adobe Commerce, Adobe Commerce B2b, Commerce and 3 more | 2026-09-12 | 8.2 High |
| Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction. | ||||
| CVE-2026-58874 | 1 Google | 1 Android | 2026-09-11 | 7.8 High |
| In multiple functions of SmsController.java, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-86169 | 1 Axolotl-ai-cloud | 1 Axolotl | 2026-09-11 | 8.8 High |
| Axolotl before 0.19.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python code by crafting a malicious Hugging Face model repository selected as base_model, which is loaded with hardcoded trust_remote_code=True during AutoModelForCausalLM.from_pretrained. | ||||
| CVE-2026-78514 | 1 Microsoft | 11 365, 365 Apps, Microsoft 365 and 8 more | 2026-09-11 | 8.8 High |
| Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-84000 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-11 | 7.8 High |
| Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally. | ||||
| CVE-2026-83985 | 1 Microsoft | 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more | 2026-09-11 | 7.8 High |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-81353 | 1 Microsoft | 1 Heif Image Extension | 2026-09-11 | 7.8 High |
| Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-78462 | 1 Microsoft | 1 Visual Studio Code | 2026-09-11 | 8.8 High |
| Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | ||||
| CVE-2026-78457 | 1 Microsoft | 9 Windows 11 24h2, Windows 11 24h2, Windows 11 25h2 and 6 more | 2026-09-11 | 7 High |
| Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-78444 | 1 Microsoft | 6 Windows 10 1809, Windows Server 2019, Windows Server 2019 (server Core Installation) and 3 more | 2026-09-11 | 8.1 High |
| Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-77905 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-11 | 7 High |
| Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-71328 | 1 Microsoft | 4 .net, Visual Studio 2022, Visual Studio 2026 and 1 more | 2026-09-11 | 8.8 High |
| Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-73017 | 1 Microsoft | 18 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 15 more | 2026-09-11 | 7.5 High |
| Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally. | ||||
| CVE-2026-73007 | 1 Microsoft | 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more | 2026-09-11 | 7.8 High |
| Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | ||||