Total
396329 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-75054 | 1 Jetbrains | 1 Intellij Idea | 2026-09-11 | N/A | 6.3 MEDIUM |
| In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects | |||||
| CVE-2026-75055 | 1 Jetbrains | 1 Intellij Idea | 2026-09-11 | N/A | 5.5 MEDIUM |
| In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE | |||||
| CVE-2026-75056 | 1 Jetbrains | 1 Intellij Idea | 2026-09-11 | N/A | 7.8 HIGH |
| In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible | |||||
| CVE-2026-75057 | 1 Jetbrains | 1 Intellij Idea | 2026-09-11 | N/A | 6.2 MEDIUM |
| In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log | |||||
| CVE-2026-75644 | 1 Adobe | 1 Experience Manager | 2026-09-11 | N/A | 5.4 MEDIUM |
| Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | |||||
| CVE-2026-75058 | 1 Jetbrains | 1 Intellij Idea | 2026-09-11 | N/A | 5.5 MEDIUM |
| In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers | |||||
| CVE-2026-75637 | 1 Adobe | 1 Experience Manager | 2026-09-11 | N/A | 5.4 MEDIUM |
| Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | |||||
| CVE-2026-72626 | 1 Adobe | 1 Experience Manager | 2026-09-11 | N/A | 5.4 MEDIUM |
| Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | |||||
| CVE-2026-84939 | 1 Apache | 1 Freemarker | 2026-09-11 | N/A | 9.1 CRITICAL |
| Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default enabled). This issue affects Apache FreeMarker from 2.2.0 through 2.3.34. Users are recommended to upgrade to version 2.3.35. Disabling localized lookup in previous versions also mitigates this. Note that even in versions affected by this vulnerability, the files that can be loaded remain restricted by the TemplateLoader that FreeMarker is configured to use. In particular, FileTemplateLoader prevents attempts to traverse outside the baseDir specified in its constructor. Other TemplateLoader implementations may allow access outside their designated base directory, but they are still constrained by the underlying storage mechanism—for example, a loader wrapping a Java class loader can only access resources that the class loader can load, while one wrapping a web application context can only access resources available through that context. | |||||
| CVE-2026-41870 | 1 Apache | 1 Nutch | 2026-09-11 | N/A | 8.8 HIGH |
| Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.11 through 1.22. Users are recommended to upgrade to version 1.23, which removes the Nutch Server. If an upgrade is not possible, user must restrict access to instances running the Nutch Service to trusted users only. Please, also visit the Apache Nutch security advisories https://nutch.apache.org/documentation/security/ . | |||||
| CVE-2026-71356 | 1 Adobe | 1 Experience Manager | 2026-09-11 | N/A | 5.4 MEDIUM |
| Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | |||||
| CVE-2026-21090 | 1 Samsung | 1 Android | 2026-09-11 | N/A | 7.8 HIGH |
| Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory. | |||||
| CVE-2026-21091 | 1 Samsung | 1 Android | 2026-09-11 | N/A | 7.8 HIGH |
| Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory. | |||||
| CVE-2026-21092 | 1 Samsung | 1 Android | 2026-09-11 | N/A | 5.3 MEDIUM |
| Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege. | |||||
| CVE-2026-21093 | 1 Samsung | 1 Android | 2026-09-11 | N/A | 6.7 MEDIUM |
| Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory. | |||||
| CVE-2026-21094 | 1 Samsung | 1 Android | 2026-09-11 | N/A | 8.8 HIGH |
| Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory. | |||||
| CVE-2026-67277 | 1 Mikrotik | 1 Routeros | 2026-09-11 | N/A | 8.2 HIGH |
| RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) | |||||
| CVE-2026-86060 | 1 Mikrotik | 1 Routeros | 2026-09-11 | N/A | 9.8 CRITICAL |
| RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) | |||||
| CVE-2026-27227 | 1 Adobe | 1 Experience Manager | 2026-09-11 | N/A | 5.4 MEDIUM |
| Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | |||||
| CVE-2026-75666 | 1 Adobe | 1 Experience Manager | 2026-09-11 | N/A | 5.4 MEDIUM |
| Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | |||||
