Vulnerabilities (CVE)

Total 398740 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-66805 1 Microsoft 1 Sharepoint Server 2026-08-13 N/A 8.8 HIGH
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-63520 1 Microsoft 1 Sharepoint Server 2026-08-13 N/A 8.1 HIGH
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-64921 1 Microsoft 1 Sharepoint Server 2026-08-13 N/A 8.8 HIGH
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-64922 1 Microsoft 1 Sharepoint Server 2026-08-13 N/A 4.6 MEDIUM
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-65658 1 Microsoft 1 Sharepoint Server 2026-08-13 N/A 8.8 HIGH
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-65665 1 Microsoft 1 Sharepoint Server 2026-08-13 N/A 8.8 HIGH
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-65663 1 Microsoft 1 Sharepoint Server 2026-08-13 N/A 8.8 HIGH
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-64916 1 Microsoft 1 Sharepoint Server 2026-08-13 N/A 4.6 MEDIUM
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-61359 1 Microsoft 6 Windows 11 23h2, Windows 11 24h2, Windows 11 25h2 and 3 more 2026-08-13 N/A 7.8 HIGH
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
CVE-2026-8985 1 Autel 2 Maxicharger Single Charger, Maxicharger Single Charger Firmware 2026-08-13 N/A 9.8 CRITICAL
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.
CVE-2026-61933 1 Microsoft 4 Windows 11 24h2, Windows 11 25h2, Windows 11 26h1 and 1 more 2026-08-13 N/A 5.5 MEDIUM
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-8986 1 Autel 2 Maxicharger Single Charger, Maxicharger Single Charger Firmware 2026-08-13 N/A 9.8 CRITICAL
Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.
CVE-2026-8984 1 Autel 2 Maxicharger Single Charger, Maxicharger Single Charger Firmware 2026-08-13 N/A 9.8 CRITICAL
Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges.
CVE-2026-21764 1 Hcltech 1 Devops Loop 2026-08-13 N/A 3.1 LOW
HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restricted. This may result in unintended application behavior under certain conditions.
CVE-2026-8989 1 Autel 2 Maxicharger Single Charger, Maxicharger Single Charger Firmware 2026-08-13 N/A 6.8 MEDIUM
Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data.
CVE-2026-54229 2026-08-13 N/A 7.0 HIGH
A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD_OPEN_READONLY and calls dd_chown to change ownership of all files to the caller's uid, succeeding even while post-create event handlers hold a write lock. This allows an attacker to gain filesystem-level control of the dump directory while privileged event scripts are still running.
CVE-2026-54228 2026-08-13 N/A 7.8 HIGH
A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can call SetElement to write arbitrary text files into the root-owned dump directory, bypassing package validation and allowing crashes of unpackaged binaries to survive post-create processing.
CVE-2026-50559 1 Quarkus 1 Quarkus 2026-08-13 N/A 7.5 HIGH
Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5C) to access protected static resources. This is a distinct issue from CVE-2026-39852, which addressed only literal semicolon stripping. Versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2 contain a patch.
CVE-2026-45109 1 Vercel 1 Next.js 2026-08-13 N/A 7.5 HIGH
Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.
CVE-2026-44579 1 Vercel 1 Next.js 2026-08-13 N/A 7.5 HIGH
Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open for an extended period, consuming file descriptors and server capacity until legitimate users are denied service. This vulnerability is fixed in 15.5.16 and 16.2.5.