Vulnerabilities (CVE)

Total 398567 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-73240 1 Apache 1 Allura 2026-08-17 N/A 9.8 CRITICAL
Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
CVE-2026-66141 1 Exim 1 Exim 2026-08-17 N/A 7.4 HIGH
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
CVE-2026-66140 1 Exim 1 Exim 2026-08-17 N/A 8.4 HIGH
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
CVE-2026-20801 1 Gallagher 2 Hanwha Vms Integration, Nx Witness Vms Integration 2026-08-17 N/A 5.6 MEDIUM
Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations allows unprivileged users with local network access to view live video streams. This issue affects all versions of Gallagher NxWitness VMS integration prior to 9.10.017 and Gallagher Hanwha VMS integration prior to 9.10.025.
CVE-2026-65948 1 Apache 1 Ranger 2026-08-17 N/A 7.3 HIGH
UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option for production deployments.  Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CVE-2026-65945 1 Apache 1 Ranger 2026-08-17 N/A 6.5 MEDIUM
Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CVE-2026-42537 1 Apache 1 Ranger 2026-08-17 N/A 9.8 CRITICAL
Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CVE-2026-70339 1 Microsoft 1 Edge Chromium 2026-08-17 N/A 5.4 MEDIUM
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-65797 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2026-08-17 N/A 6.7 MEDIUM
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-70304 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2026-08-17 N/A 6.7 MEDIUM
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-65798 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2026-08-17 N/A 6.7 MEDIUM
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-63702 1 Dell 1 Wyse Management Suite 2026-08-17 N/A 6.3 MEDIUM
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
CVE-2026-40920 1 Apache 1 Ranger 2026-08-17 N/A 9.8 CRITICAL
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CVE-2026-32227 1 Apache 1 Ranger 2026-08-17 N/A 9.8 CRITICAL
SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the issue.
CVE-2026-28672 1 Apache 1 Ranger 2026-08-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8.
CVE-2026-65799 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2026-08-17 N/A 6.7 MEDIUM
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-18097 1 Ibm 1 Db2 2026-08-17 N/A 5.5 MEDIUM
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.
CVE-2026-66270 1 Dell 1 Wyse Management Suite 2026-08-17 N/A 7.2 HIGH
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
CVE-2026-10571 4 Apple, Ibm, Linux and 1 more 7 Macos, Aix, I and 4 more 2026-08-17 N/A 5.7 MEDIUM
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources when the restConnector-2.0 feature is enabled.
CVE-2026-63701 1 Dell 1 Wyse Management Suite 2026-08-17 N/A 6.3 MEDIUM
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.