Vulnerabilities (CVE)

Filtered by CWE-20
Total 13237 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-77533 2026-08-28 N/A 9.9 CRITICAL
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
CVE-2026-77537 2026-08-28 N/A 10.0 CRITICAL
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
CVE-2026-59568 2026-08-28 N/A 9.1 CRITICAL
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
CVE-2026-43678 1 Apple 1 Swiftnio 2026-08-28 N/A 5.3 MEDIUM
An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in swift-nio version 2.101.0.
CVE-2026-78943 1 Google 1 Chrome 2026-08-28 N/A 3.1 LOW
Improper input validation in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-62347 2026-08-28 N/A 4.3 MEDIUM
HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an implementation flaw in an architectural security tactic that fails to properly validate whether the received input matches the expected type.
CVE-2026-56547 2026-08-28 N/A 3.5 LOW
The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address to be embedded in them.  The values cannot be changed later on, so the Apple profile generation page asks for those values and reflects them back in the generated Apple profile.  The Apple profile is not usable without additional information and only allows the attacker to attack their own device, but HCL Traveler could at least check that the values submitted and reflected back in the Apple profile are found in the Domino directory entry for the already authenticated user.
CVE-2026-16641 2026-08-28 N/A 9.8 CRITICAL
Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.
CVE-2026-16643 2026-08-28 N/A 5.7 MEDIUM
Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*.
CVE-2026-15088 2026-08-28 N/A 5.7 MEDIUM
Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*.
CVE-2026-16642 2026-08-28 N/A 5.7 MEDIUM
Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.
CVE-2026-18261 2026-08-28 N/A 5.7 MEDIUM
Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.
CVE-2026-81827 2026-08-28 N/A N/A
Affected versions of Flowintel incorrectly attempted to validate login email addresses by calling Email(email). That does not perform WTForms field validation; it merely constructs a validator object. Consequently, malformed attacker-controlled email input could continue through the login process and be written to security-relevant logs. The vulnerable code inserted the supplied email into both a warning log and the custom audit logger. Since CR/LF characters were not escaped, an unauthenticated attacker could potentially inject additional physical log lines or forge misleading log entries. The patch corrects the validation call to Email()(form, form.email), changes the standard logging call to parameterized logging, and introduces _sanitize_log_fragment() so carriage returns and line feeds are encoded instead of creating new records. Version impacted >=3.3.0
CVE-2026-81662 2026-08-28 N/A N/A
Affected versions of Flowintel improperly trust configuration keys supplied to the alerts settings update endpoint. While configuration values were normalized to Python literals, the corresponding keys were used directly when constructing and replacing lines in conf/config_module.py. The vulnerable code used requester-controlled keys in both the regular expression and the generated assignment: f'{key} = {py_val}' and appended an assignment if the key was not already present. The modified Python configuration module was subsequently reloaded using importlib.reload(). This creates a code-generation boundary in which specially crafted configuration keys can alter the Python source structure and result in execution of attacker-controlled Python statements. Version impacted >=3.3.0
CVE-2026-78980 1 Google 1 Chrome 2026-08-28 N/A 4.3 MEDIUM
Improper input validation in ReaderMode in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-79000 1 Google 1 Chrome 2026-08-28 N/A 4.3 MEDIUM
Improper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
CVE-2026-79015 1 Google 1 Chrome 2026-08-28 N/A 4.3 MEDIUM
Improper input validation in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-79105 2 Apple, Google 2 Iphone Os, Chrome 2026-08-28 N/A 4.3 MEDIUM
Improper input validation in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-79192 1 Google 1 Chrome 2026-08-28 N/A 4.3 MEDIUM
Improper input validation in Variations in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)
CVE-2026-79203 1 Google 1 Chrome 2026-08-28 N/A 3.1 LOW
Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)