Search

Search Results (371432 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-8988 1 Autel 1 Maxicharger Single Charger 2026-07-27 N/A
Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical access can modify the boot configuration or file system to obtain operating system access.
CVE-2026-8989 1 Autel 1 Maxicharger Single Charger 2026-07-27 N/A
Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data.
CVE-2026-16517 2 Libarchive, Redhat 6 Libarchive, Enterprise Linux, Hardened Images and 3 more 2026-07-27 2.9 Low
A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.
CVE-2026-38763 1 Unistal Systems 1 Protegent 360 2026-07-27 5.5 Medium
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828
CVE-2026-38765 1 Unistal Systems 1 Protegent 360 2026-07-27 7.8 High
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys
CVE-2026-38766 1 Unistal Systems 1 Protegent 360 2026-07-27 7.8 High
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function
CVE-2025-60835 1 Izarc 1 Unrar 2026-07-27 7.8 High
An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
CVE-2025-44089 1 Nch Software 1 Expresszip 2026-07-27 8.8 High
An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
CVE-2026-16473 2 Redhat, Sbc 2 Enterprise Linux, Sbc 2026-07-27 4.3 Medium
A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.
CVE-2026-57600 1 Hikvision 4 Ds-2cd Series, Ds-2de Series, Ds-2dp Series and 1 more 2026-07-27 7.5 High
Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.
CVE-2026-61390 1 Hikvision 2 Ds-2cd Series, Ds-2de Series 2026-07-27 7.7 High
There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.
CVE-2026-16551 1 Thinkst Applied Research 1 Opencanary 2026-07-27 N/A
Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affects OpenCanary 0.9.8 only.
CVE-2026-16552 2 Redhat, Systemd 4 Enterprise Linux, Hardened Images, Openshift Container Platform and 1 more 2026-07-27 6.3 Medium
The reported issue is invalid, as it requires root privileges to reproduce, and it is out of scope of the threat model of the affected component.
CVE-2026-13069 1 Mongodb 1 Mongodb Server 2026-07-27 6.5 Medium
An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used to control an internal computation loop. The resulting resource exhaustion degrades availability for other operations.
CVE-2026-13056 1 Mongodb 1 Mongodb Server 2026-07-27 6.5 Medium
Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error.
CVE-2026-59531 2 Anh Tran, Wordpress 2 Falcon – Wordpress Optimizations & Tweaks, Wordpress 2026-07-27 7.5 High
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
CVE-2026-59536 2 Cocart Headless, Wordpress 2 Cocart – Headless Ecommerce, Wordpress 2026-07-27 7.5 High
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
CVE-2026-59537 2 Sender, Wordpress 2 Sender – Newsletter, Sms And Email Marketing Automation For Woocommerce, Wordpress 2026-07-27 7.6 High
Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions.
CVE-2026-59548 2 Byteflows, Wordpress 2 Byteflows Travel & Hotel Booking, Wordpress 2026-07-27 7.5 High
Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1.0.0 versions.
CVE-2026-59552 2 Shahadat Hossain, Wordpress 2 3d Flipbook Pdf Viewer & Embedder, Wordpress 2026-07-27 7.2 High
Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2 versions.