Vulnerabilities (CVE)

Filtered by CWE-20
Total 13237 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-20627 1 Apple 5 Ipados, Iphone Os, Macos and 2 more 2026-08-21 N/A 5.5 MEDIUM
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3, watchOS 26.3. An app may be able to access sensitive user data.
CVE-2025-12131 1 Silabs 1 Simplicity Software Development Kit 2026-08-20 N/A 6.5 MEDIUM
A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.
CVE-2026-76033 1 Google 1 Chrome 2026-08-20 N/A 4.2 MEDIUM
Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CVE-2026-20318 2026-08-20 N/A 9.6 CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20318 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20.
CVE-2026-12128 2026-08-20 N/A 5.3 MEDIUM
The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to, and including, 2.9.9.6.8. This is due to the `dopbsp_woocommerce_add_to_cart` AJAX action being registered via `wp_ajax_nopriv_*` with no authentication, no nonce verification, and no server-side recalculation of pricing — the `update` handler reads `price_total` directly from the attacker-controlled `cart_data` POST parameter and persists it to the database via `$wpdb->insert()` without validating it against the calendar's configured pricing. The `woocommerce_before_calculate_totals` callback subsequently reads the stored attacker-supplied value back from the database and passes it directly to `$product->set_price()` without recomputing from calendar settings. This makes it possible for unauthenticated attackers to override the WooCommerce checkout price of any bookable product tied to a booking calendar to an arbitrary value, effectively enabling the purchase of any such product at a self-chosen price.
CVE-2026-65811 1 Microsoft 1 Power Bi Report Server 2026-08-19 N/A 8.8 HIGH
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
CVE-2026-21229 1 Microsoft 1 Power Bi Report Server 2026-08-19 N/A 8.0 HIGH
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
CVE-2023-21818 1 Microsoft 12 Windows 10, Windows 10 1607, Windows 10 1809 and 9 more 2026-08-19 N/A 7.5 HIGH
Windows Secure Channel Denial of Service Vulnerability
CVE-2023-21816 1 Microsoft 13 Windows 10, Windows 10 1607, Windows 10 1809 and 10 more 2026-08-19 N/A 7.5 HIGH
Windows Active Directory Domain Services API Denial of Service Vulnerability
CVE-2023-21685 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2026-08-19 N/A 8.8 HIGH
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2020-1195 1 Microsoft 1 Edge 2026-08-19 4.3 MEDIUM 3.1 LOW
An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly validates input. An attacker who successfully exploited this vulnerability could write files to arbitrary locations and gain elevated privileges. The vulnerability by itself does not allow arbitrary code to run. However, this vulnerability could be used in conjunction with one or more vulnerabilities (for example a remote code execution vulnerability and another elevation of privilege vulnerability) to take advantage of the elevated privileges when running. The security update addresses the vulnerability by modifying how Microsoft Edge (Chromium-based) Feedback extension validates files.
CVE-2020-1173 1 Microsoft 1 Power Bi Report Server 2026-08-19 3.5 LOW 6.8 MEDIUM
A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments. An authenticated attacker could exploit the vulnerability by uploading a specially crafted payload and sending it to the user. The attacker who successfully exploited this vulnerability could then perform actions and run scripts in the security context of the user. This security update addresses the vulnerability by ensuring Power BI Report Server properly validates content-type of the attachments when uploading and opening.
CVE-2020-1084 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2026-08-19 2.1 LOW 5.5 MEDIUM
A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values. An attacker who successfully exploited this vulnerability could deny dependent security feature functionality. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The security update addresses the vulnerability by correcting how the Connected User Experiences and Telemetry Service validates certain function values.
CVE-2020-1081 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-19 7.2 HIGH 7.8 HIGH
An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while loading printer drivers. An authenticated attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The update addresses this vulnerability by correcting how the Windows Printer Service validates file paths.
CVE-2026-21072 1 Samsung 1 Android 2026-08-19 N/A 7.8 HIGH
Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
CVE-2026-21071 1 Samsung 1 Android 2026-08-19 N/A 7.8 HIGH
Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
CVE-2026-21083 1 Samsung 1 Smart Switch 2026-08-19 N/A 6.5 MEDIUM
Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
CVE-2026-21712 1 Nodejs 1 Node.js 2026-08-19 N/A 6.5 MEDIUM
A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.
CVE-2026-21070 1 Samsung 1 Android 2026-08-19 N/A 4.6 MEDIUM
Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.
CVE-2026-21058 1 Samsung 1 Android 2026-08-19 N/A 7.1 HIGH
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.