Vulnerabilities (CVE)

Total 400203 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-14865 1 Progress 1 Telerik Ui For Asp.net Ajax 2026-08-06 N/A 5.3 MEDIUM
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion.
CVE-2026-14902 1 Ivanti 1 Xtraction 2026-08-06 N/A 4.0 MEDIUM
An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs.
CVE-2026-14932 1 Progress 1 Telerik Ui For Asp.net Ajax 2026-08-06 N/A 6.5 MEDIUM
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension files within the application directory.
CVE-2026-14903 1 Ivanti 1 Xtraction 2026-08-06 N/A 7.7 HIGH
Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.
CVE-2026-12523 1 Cloudflare 1 Quiche 2026-08-06 N/A 7.5 HIGH
Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames. Impact HTTP/3 defines multiple frame types to support HTTP message exchanges and connection management. Each frame has a length and a payload whose length depends on the frame type. quiche was found to be vulnerable when parsing some frame types to pre-allocating memory based on the declared length. An attacker would not need to send the number of declared bytes to trigger this issue. In addition, quiche was found to not apply QPACK decompression limits correctly. This could allow an attacker to send specially crafted HEADERS frames that would cause more memory commitment than otherwise advertised by MAX_FIELD_SECTION_SIZE (configured by set_max_field_section_size()). Mitigation: * Users are requested to upgrade to quiche 0.29.3 which is the earliest version containing the fix for this issue. Credits: Disclosed responsibly by Sébastien Féry
CVE-2026-58659 1 Lightningai 1 Pytorch Lightning 2026-08-06 N/A 7.8 HIGH
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called.
CVE-2026-66326 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 6.5 MEDIUM
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-66325 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 6.1 MEDIUM
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-66322 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 7.1 HIGH
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-66321 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 7.4 HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-66318 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 8.1 HIGH
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVE-2026-66317 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 5.4 MEDIUM
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
CVE-2026-66316 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 5.4 MEDIUM
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-66315 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 7.5 HIGH
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-66314 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 6.5 MEDIUM
Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVE-2026-66313 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 6.8 MEDIUM
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
CVE-2026-66312 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 6.5 MEDIUM
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
CVE-2026-66311 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 6.2 MEDIUM
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
CVE-2026-65804 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 6.1 MEDIUM
Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-54463 1 Faye 1 Websocket-driver 2026-08-06 N/A 7.5 HIGH
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver include a length header that allows an arbitrarily large integer to be encoded as bytes with the high bit set, and a server or client can send an indefinite sequence of 0x80 or higher bytes that the peer parses into an ever-growing Ruby integer. This can make a WebSocket connection consume an unbounded amount of memory and lead to the host process running out of memory. This issue is fixed in version 0.8.1.