Export limit exceeded: 373127 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (373127 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-50324 | 1 Onecommander | 1 Onecommander | 2026-08-04 | 8.8 High |
| An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component. | ||||
| CVE-2025-50329 | 1 Conexware | 1 Powerarchiver | 2026-08-04 | 9.8 Critical |
| An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe. | ||||
| CVE-2026-56844 | 1 Veeam | 1 Backup And Replication | 2026-08-04 | N/A |
| A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system. | ||||
| CVE-2026-57599 | 1 Hikvision | 1 Ds-2cd Series | 2026-08-04 | 6.6 Medium |
| There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH. | ||||
| CVE-2026-61390 | 1 Hikvision | 2 Ds-2cd Series, Ds-2de Series | 2026-08-04 | 7.7 High |
| There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets. | ||||
| CVE-2026-61391 | 1 Hikvision | 2 Ds-2cd Series, Ds-2de Series | 2026-08-04 | 7.2 High |
| There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets. | ||||
| CVE-2026-61392 | 1 Hikvision | 2 Ds-2cd Series, Ds-2de Series | 2026-08-04 | 5.3 Medium |
| There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory. | ||||
| CVE-2026-67974 | 1 Nasa | 1 Cfs | 2026-08-04 | N/A |
| A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet. | ||||
| CVE-2026-67975 | 1 Nasa | 1 Cfs | 2026-08-04 | N/A |
| Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands. | ||||
| CVE-2026-44276 | 1 Dell | 1 Powerprotect Data Manager | 2026-08-03 | 6 Medium |
| Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the REST API. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | ||||
| CVE-2026-40712 | 1 Dell | 1 Powerprotect Data Manager | 2026-08-03 | 9.1 Critical |
| Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | ||||
| CVE-2026-46738 | 1 Dell | 1 Powerprotect Data Manager | 2026-08-03 | 9.1 Critical |
| Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | ||||
| CVE-2026-65650 | 1 Elgg | 1 Elgg | 2026-08-03 | 4.3 Medium |
| Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload. | ||||
| CVE-2026-22049 | 1 Netapp | 1 Ontap 9 | 2026-08-03 | N/A |
| ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA. | ||||
| CVE-2026-67970 | 1 Nasa | 1 Cfs | 2026-08-03 | N/A |
| Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal. | ||||
| CVE-2026-67973 | 1 Nasa | 1 Cfs | 2026-08-03 | N/A |
| An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs. | ||||
| CVE-2026-67616 | 1 Owen2345 | 1 Camaleon Cms | 2026-08-03 | 4.3 Medium |
| Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue. | ||||
| CVE-2026-60366 | 1 Oracle | 1 Platform Security For Java | 2026-08-03 | 10 Critical |
| Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). | ||||
| CVE-2026-60367 | 1 Oracle | 1 Platform Security For Java | 2026-08-03 | 9.8 Critical |
| Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). | ||||
| CVE-2026-60368 | 1 Oracle | 1 Platform Security For Java | 2026-08-03 | 8.8 High |
| Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). | ||||