Export limit exceeded: 385620 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 385620 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (385620 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-46418 | 2026-09-02 | 7.6 High | ||
| Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition. | ||||
| CVE-2026-38577 | 1 Tenda | 1 Hg21 | 2026-09-02 | 9.8 Critical |
| Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access. | ||||
| CVE-2026-75460 | 1 Xuezhisi | 1 Open Source Exam System | 2026-09-02 | 6.5 Medium |
| XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interface POST /api/teacher/user/page/list. The role parameter in UserPageRequestVM is fully controllable by the requester. | ||||
| CVE-2026-51756 | 1 Totolink | 1 T6 | 2026-09-02 | 5.9 Medium |
| Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a crafted MQTT message to the cs_broker component. | ||||
| CVE-2026-51766 | 1 Totolink | 1 T6 | 2026-09-02 | 7.5 High |
| Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mesh slaves via sending a crafted MQTT message to the cs_broker component. | ||||
| CVE-2026-84128 | 1 Mozilla | 1 Firefox | 2026-09-02 | 8.8 High |
| Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155. | ||||
| CVE-2026-84133 | 1 Mozilla | 1 Firefox | 2026-09-02 | N/A |
| Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | ||||
| CVE-2026-84134 | 1 Mozilla | 1 Firefox | 2026-09-02 | N/A |
| Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | ||||
| CVE-2026-84136 | 1 Mozilla | 1 Firefox | 2026-09-02 | N/A |
| Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | ||||
| CVE-2026-84235 | 1 Rockwell Automation | 1 1756-enbt Module | 2026-09-02 | N/A |
| A denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module. The device requires a restart to recover. | ||||
| CVE-2026-9055 | 2026-09-02 | 9.8 Critical | ||
| The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a WordPress user with the wpamelia-manager role when the 'externalId' parameter is set to 0. This makes it possible for unauthenticated attackers to escalate their privileges to administrator by first elevating to the manager role, then creating a provider entity linked to an administrator user ID and overwriting that administrator's password. | ||||
| CVE-2024-35585 | 2026-09-02 | 8.6 High | ||
| Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication. | ||||
| CVE-2026-79682 | 1 Dell | 12 Powerstore 1000t, Powerstore 1200t, Powerstore 3000t and 9 more | 2026-09-02 | 8.8 High |
| Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges. | ||||
| CVE-2026-84142 | 1 Mozilla | 1 Firefox | 2026-09-02 | N/A |
| Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155. | ||||
| CVE-2026-84353 | 1 Google | 1 Chrome | 2026-09-02 | N/A |
| Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | ||||
| CVE-2026-84359 | 1 Google | 1 Chrome | 2026-09-02 | N/A |
| Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-84357 | 1 Google | 1 Chrome | 2026-09-02 | N/A |
| Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: High) | ||||
| CVE-2026-84324 | 1 Google | 1 Chrome | 2026-09-02 | N/A |
| Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) | ||||
| CVE-2026-84326 | 1 Google | 1 Chrome | 2026-09-02 | N/A |
| Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-84325 | 1 Google | 1 Chrome | 2026-09-02 | N/A |
| Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High) | ||||