Total
396528 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-80128 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | N/A | 6.4 MEDIUM |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass. | |||||
| CVE-2026-78487 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | N/A | 5.5 MEDIUM |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. | |||||
| CVE-2026-79734 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | N/A | 5.9 MEDIUM |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass. | |||||
| CVE-2026-81269 | 1 Data Field Project | 1 Data Field | 2026-09-09 | N/A | 5.3 MEDIUM |
| Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13. | |||||
| CVE-2026-80129 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | N/A | 6.5 MEDIUM |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. | |||||
| CVE-2026-80130 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | N/A | 7.1 HIGH |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to remote execution. | |||||
| CVE-2026-80131 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | N/A | 7.4 HIGH |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. | |||||
| CVE-2026-73474 | 1 Entity Share Websub Project | 1 Entity Share Websub | 2026-09-09 | N/A | 5.3 MEDIUM |
| Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2. | |||||
| CVE-2026-69321 | 2026-09-09 | N/A | 5.5 MEDIUM | ||
| Missing authentication for critical function in Windows Power Dependency Coordinator allows an authorized attacker to perform tampering locally. | |||||
| CVE-2026-69277 | 2026-09-09 | N/A | 7.8 HIGH | ||
| Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69272 | 2026-09-09 | N/A | 7.1 HIGH | ||
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-54611 | 2026-09-09 | N/A | 5.5 MEDIUM | ||
| InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possible to upload a malicious component into the server, however, it won't be installed, but upload files will be executed. Normally all php files in upload folder are not executed, however, by uploading custom .htaccess it becomes possible. Version 2.18.2 contains a fix. | |||||
| CVE-2026-53758 | 2026-09-09 | N/A | N/A | ||
| Emlog is an open source website building system. In versions 2.6.29 and prior, article content is processed by Parsedown without enabling safe mode, which means raw HTML including <script> tags embedded in Markdown is passed through unescaped. The output is rendered with no additional sanitization, resulting in stored XSS visible to all site visitors. At time of publication, there are no publicly known patches. | |||||
| CVE-2026-52772 | 2026-09-09 | N/A | 5.5 MEDIUM | ||
| YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and label-body contexts, resulting stored XSS in form renders. This issue has been patched in version 4.6.6. | |||||
| CVE-2026-44629 | 2026-09-09 | N/A | 7.9 HIGH | ||
| Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows servers. | |||||
| CVE-2026-80164 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | N/A | 7.4 HIGH |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. | |||||
| CVE-2026-87518 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-09-09 | N/A | 5.3 MEDIUM |
| Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-64918 | 1 Microsoft | 5 365 Apps, Office 2016, Office 2019 and 2 more | 2026-09-09 | N/A | 6.5 MEDIUM |
| Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-87490 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 6.5 MEDIUM |
| Information leak in Transactions Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-87502 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 4.2 MEDIUM |
| Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | |||||
