Export limit exceeded: 391130 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 98298 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (98298 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-81385 1 Microsoft 7 365 Apps, Microsoft 365 Apps For Enterprise, Office 2019 and 4 more 2026-09-10 8.8 High
Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
CVE-2026-81956 1 Microsoft 21 365 Apps, Excel, Excel 2016 and 18 more 2026-09-10 7.8 High
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81992 3 Adobe, Apple, Microsoft 7 Acrobat, Acrobat 2024, Acrobat Dc and 4 more 2026-09-10 7.8 High
Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-81987 3 Adobe, Apple, Microsoft 7 Acrobat, Acrobat 2024, Acrobat Dc and 4 more 2026-09-10 7.8 High
Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-79324 1 Mageplaza 2 Gdpr, Module-gdpr 2026-09-10 7.5 High
Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by iterating the address id, via a GET request to /customer/address/delete/id/{id}. The controller extends the legacy Action class instead of AbstractAccount, so no authentication, ownership or form key check is enforced.
CVE-2026-79322 1 Mageplaza 2 Magento 2 Blog Extension, Mageplaza Blog 2026-09-10 8.6 High
SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id parameter to /mpblog/post/view.
CVE-2026-87084 1 Tanium 1 Enforce 2026-09-10 7.7 High
Tanium addressed a server-side request forgery vulnerability in Enforce.
CVE-2026-13359 2 Bestweblayout, Wordpress 2 Contact Form To Db By Bestwebsoft – Messages Database Plugin For Wordpress, Wordpress 2026-09-10 7.2 High
The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter in all versions up to, and including, 1.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload executes in the context of an administrator's browser session when they visit the plugin's message manager page at /wp-admin/admin.php?page=cntctfrmtdb_manager, making it possible to compromise administrator-level sessions via a simple unauthenticated contact form submission.
CVE-2026-14359 2 Wordpress, Yith 2 Wordpress, Yith Woocommerce Waitlist Premium 2026-09-10 8.8 High
The YITH WooCommerce Waitlist Premium plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.35.0. This is due to the add_user_in_waiting_list() function registered on the wp_ajax_yith_wcwtl_add_user action being missing both a capability check and a nonce verification, and using parse_str() + extract() to import attacker-controlled variables from $_POST['params'] that are then passed to wp_create_user() and $user->set_role(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator by creating a new user account and assigning it the administrator role.
CVE-2026-79617 1 Tubitak Bilgem Software Technologies Research Institute 1 Pardus Lightdm Greeter 2026-09-10 7.1 High
Incorrect Permission Assignment for Critical Resource vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus LightDM Greeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pardus LightDM Greeter: before 0.4.15.
CVE-2026-87853 2 Redhat, Sssd 4 Enterprise Linux, Openshift, Openshift Container Platform and 1 more 2026-09-10 7.5 High
A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP identifier is a strict prefix of a target user's identifier can authenticate as the target user.
CVE-2026-18147 1 Redhat 2 Enterprise Linux, Freeipa 2026-09-10 8.1 High
A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated session, potentially leading to full administrative control if an IdM administrator is targeted.
CVE-2026-76562 2 Otwthemes, Wordpress 2 Sidebar Manager Light, Wordpress 2026-09-10 7.2 High
The Sidebar Manager Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sbm_description' parameter in all versions up to, and including, 1.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-81386 1 Microsoft 15 365 Apps, Excel, Excel 2016 and 12 more 2026-09-10 7.8 High
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81955 1 Microsoft 42 365 Apps, Microsoft 365 Apps For Enterprise, Microsoft Office 2016 and 39 more 2026-09-10 8.8 High
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
CVE-2026-81951 1 Microsoft 15 365 Apps, Excel, Excel 2016 and 12 more 2026-09-10 7.8 High
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-81949 1 Microsoft 15 365 Apps, Excel, Excel 2016 and 12 more 2026-09-10 7.8 High
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-83940 1 Microsoft 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more 2026-09-10 7 High
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
CVE-2026-69530 1 Microsoft 6 Windows 10 1809, Windows Server 2019, Windows Server 2019 (server Core Installation) and 3 more 2026-09-10 8.1 High
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
CVE-2026-72965 1 Microsoft 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more 2026-09-10 7.8 High
Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.