Export limit exceeded: 395912 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 395912 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 395912 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 395912 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 395912 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 395912 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (395912 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-94401 | 1 Misp | 1 Misp | 2026-09-21 | N/A |
| MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was actually XML. Because of this, a user with permission to modify data could upload a file containing a local file path or a web address instead. If a local file path was supplied, MISP could read that file from the server. If a URL was supplied, MISP could make a request to that address, including systems that may only be reachable from inside the organization’s network. The vulnerability could therefore expose sensitive local files and allow unauthorized requests to internal services. Exploitation required a valid MISP account with modify permissions, but no additional user interaction was needed. Version affected: <2.5.47 | ||||
| CVE-2026-72961 | 1 Microsoft | 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more | 2026-09-21 | 8.2 High |
| Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69643 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-21 | 8 High |
| Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69630 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-21 | 7 High |
| Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-93375 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-09-21 | 8.1 High |
| Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) | ||||
| CVE-2026-69608 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-21 | 7.8 High |
| Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69610 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-21 | 7 High |
| Buffer over-read in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69612 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-21 | 7.8 High |
| Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69618 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-21 | 5.5 Medium |
| Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-94382 | 1 Beszel | 1 Beszel | 2026-09-21 | 4.2 Medium |
| Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or delete alerts on systems they cannot access. Attackers can supply arbitrary system IDs in the request body to register alert rules and receive notifications disclosing target system names and metrics. | ||||
| CVE-2026-94211 | 1 Leantime | 1 Leantime | 2026-09-21 | 2.4 Low |
| A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected by this issue is some unknown functionality of the file /app/Domain/Dashboard/Templates/show.blade.php of the component Project Dashboard. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. "EDIT perm" needed to plant; fires cross-user for anyone viewing the project dashboard since the poisoned label name is echoed raw. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-93374 | 1 Google | 2 Android, Chrome | 2026-09-21 | 9.6 Critical |
| Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | ||||
| CVE-2026-94111 | 2026-09-21 | 6.6 Medium | ||
| Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicious extension as a browser client to intercept and manipulate page content, DOM, and screenshots returned to the AI agent. | ||||
| CVE-2026-94108 | 2 Getid3, James-heinrich | 2 Getid3, Getid3 | 2026-09-21 | 6.5 Medium |
| getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media files to disclose local files, perform server-side request forgery, or cause denial of service through entity expansion. | ||||
| CVE-2026-94105 | 1 Nivocart | 1 Nivocart | 2026-09-21 | 5.3 Medium |
| NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller that allows unauthenticated attackers to disable password recovery by supplying an invalid code parameter. Attackers can send a GET request with a missing or incorrect code to rewrite the config_password setting to 0, disabling self-service password recovery until an administrator manually re-enables it. | ||||
| CVE-2026-94039 | 1 Vas3k | 1 Taxhacker | 2026-09-21 | 7.3 High |
| A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/invoices/actions.ts of the component Invoice PDF Renderer. Performing a manipulation of the argument businessLogo results in server-side request forgery. The attack is possible to be carried out remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-94034 | 1 Sourcecodester | 1 Drug Recommendation System | 2026-09-21 | 3.5 Low |
| A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /drug_recommender/Admin/change_password of the component Password Change. Performing a manipulation of the argument txtoldpassword/txtnewpassword results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and could be used. | ||||
| CVE-2026-94028 | 2 Mealie, Mealie-recipes | 2 Mealie, Mealie | 2026-09-21 | 4.3 Medium |
| A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_dump of the file mealie/routes/households/controller_group_recipe_actions.py of the component Recipe Action Trigger. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.26.0 is able to address this issue. This patch is called fb221afa258c8dd2c4ac95b1996c33ef9db3f477. The affected component should be upgraded. | ||||
| CVE-2026-93997 | 1 Sourcecodester | 1 Drug Recommendation System | 2026-09-21 | 7.3 High |
| A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected by this issue is some unknown functionality of the file /Admin/edit_symptom.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. | ||||
| CVE-2026-93993 | 1 Mistral | 1 Mistral-vibe | 2026-09-21 | 8.8 High |
| Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe. | ||||