Export limit exceeded: 390875 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 390875 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (390875 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-87474 | 1 Google | 1 Chrome | 2026-09-09 | 9.6 Critical |
| Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-69417 | 1 Microsoft | 1 Sharepoint Server | 2026-09-09 | 7.3 High |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||||
| CVE-2026-87476 | 1 Google | 1 Chrome | 2026-09-09 | 6.5 Medium |
| Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-77897 | 1 Microsoft | 2 Power Automate Agent For Virtual Desktops, Power Automate For Desktop | 2026-09-09 | 7 High |
| Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-73003 | 1 Microsoft | 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more | 2026-09-09 | 7 High |
| Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69642 | 1 Microsoft | 3 Skype For Business Server 2015, Skype For Business Server 2019, Skype For Business Server Subscription Edition | 2026-09-09 | 6.5 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | ||||
| CVE-2026-69478 | 1 Microsoft | 18 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 15 more | 2026-09-09 | 7.8 High |
| Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-66305 | 1 Microsoft | 3 Skype For Business Server 2015, Skype For Business Server 2019, Skype For Business Server Subscription Edition | 2026-09-09 | 7.1 High |
| Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network. | ||||
| CVE-2026-65772 | 1 Microsoft | 1 Dynamics 365 | 2026-09-09 | 8.8 High |
| Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-58599 | 1 Microsoft | 3 Hevc Video Extensions, Hevc Video Extensions For Licensed Appplications, Hevc Video Extensions From Device Manufacturer | 2026-09-09 | 7.8 High |
| Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-53760 | 1 Admidio | 1 Admidio | 2026-09-09 | 5.2 Medium |
| Admidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endpoint handles plugin installation, uninstallation, and update operations via GET requests without CSRF token validation. Because these are top-level navigations, browsers include SameSite=Lax session cookies. An attacker crafts a malicious page that, when an authenticated administrator visits it, triggers arbitrary plugin operations. The uninstall operation executes DROP TABLE SQL scripts and destroys plugin data. This issue has been patched via commit 056b1bd. | ||||
| CVE-2026-52766 | 1 Yeswiki | 1 Yeswiki | 2026-09-09 | 9.1 Critical |
| YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that array, with no authorization check anywhere in the action body or in the page-deletion path it invokes. Combined with YesWiki's allow-by-default action ACL model, any user who has page write access, which is the default for everyone (default_write_acl='*') on a fresh install can permanently delete arbitrary wiki pages, including the front page, admin pages, and pages owned by other users. This issue has been patched in version 4.6.6. | ||||
| CVE-2026-37171 | 2026-09-09 | 5.9 Medium | ||
| A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant. | ||||
| CVE-2026-12230 | 2 Thimpress, Wordpress | 2 Learnpress – Wordpress Lms Plugin For Create And Sell Online Courses, Wordpress | 2026-09-09 | 6.4 Medium |
| The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_custom_css' parameter in all versions up to, and including, 4.3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-87636 | 1 Google | 1 Chrome | 2026-09-09 | 8.8 High |
| Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87455 | 1 Google | 1 Chrome | 2026-09-09 | 9.6 Critical |
| Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87448 | 1 Google | 1 Chrome | 2026-09-09 | 9.6 Critical |
| Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-87478 | 1 Google | 1 Chrome | 2026-09-09 | 6.5 Medium |
| Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87479 | 1 Google | 1 Chrome | 2026-09-09 | 8.3 High |
| Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87454 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-09-09 | 6.5 Medium |
| Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||