Export limit exceeded: 377195 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (377195 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16863 | 1 Ibm | 1 I | 2026-08-13 | 7.7 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read. | ||||
| CVE-2026-16904 | 1 Ibm | 1 I | 2026-08-13 | 8.1 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper privilege management during monitor owner reassignment. | ||||
| CVE-2026-16907 | 1 Ibm | 1 I | 2026-08-13 | 7.6 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking. | ||||
| CVE-2026-16931 | 1 Ibm | 1 I | 2026-08-13 | 7.5 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper handling of zero-length TCP options. | ||||
| CVE-2026-16956 | 1 Ibm | 1 Db2 Mirror For I | 2026-08-13 | 9.8 Critical |
| IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | ||||
| CVE-2026-17109 | 1 Ibm | 1 I | 2026-08-13 | 4.3 Medium |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to add unexpected parameters to a command due to parameter injection. | ||||
| CVE-2026-73574 | 1 Zimbra | 1 Collaboration | 2026-08-13 | 3.1 Low |
| In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially allowing unauthorized disclosure of protected files, such as WEB-INF/web.xml, within the web application directory. This occurs in the Forward servlet. | ||||
| CVE-2026-73576 | 1 Zimbra | 1 Collaboration | 2026-08-13 | 6.3 Medium |
| In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with the generated secret may be able to recover the JWT signing secret through offline brute-force, potentially enabling JWT forgery. | ||||
| CVE-2026-6471 | 1 Postgresql | 1 Postgresql | 2026-08-13 | 7.2 High |
| Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | ||||
| CVE-2026-28173 | 2 Arraytics, Wordpress | 2 Wp Event Solution, Wordpress | 2026-08-13 | 7.1 High |
| Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions. | ||||
| CVE-2026-28175 | 2 Wordpress, Wp-buy | 2 Wordpress, Visitor Traffic Real Time Statistics | 2026-08-13 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions. | ||||
| CVE-2026-28176 | 2 Booking Activities Team, Wordpress | 2 Booking Activities, Wordpress | 2026-08-13 | 8.8 High |
| Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions. | ||||
| CVE-2026-28181 | 2 Acymailing Newsletter Team, Wordpress | 2 Acymailing Smtp Newsletter, Wordpress | 2026-08-13 | 6.5 Medium |
| Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions. | ||||
| CVE-2026-28184 | 2 10web, Wordpress | 2 Form Maker By 10web, Wordpress | 2026-08-13 | 8.5 High |
| Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 versions. | ||||
| CVE-2026-58507 | 2026-08-13 | N/A | ||
| Private Repository Existence Disclosure via go-get Meta Endpoint | ||||
| CVE-2026-57886 | 2026-08-13 | N/A | ||
| Cross-repository issue/comment attachment re-linking can expose private attachment content | ||||
| CVE-2026-55987 | 2026-08-13 | N/A | ||
| OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) | ||||
| CVE-2026-55984 | 2026-08-13 | N/A | ||
| Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service | ||||
| CVE-2026-55982 | 2026-08-13 | N/A | ||
| OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes | ||||
| CVE-2026-59109 | 2026-08-13 | 8.8 High | ||
| SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement text using string concatenation, with neither parameterised queries nor escaping. The application's own escaping helper, Dazadi.sql_txt(), is not invoked on these code paths, so a party that sends an invoice can break out of the string literal and alter the query logic. This issue affects Zalktis: before 2026.1.586 and before 2026.2.592. | ||||