Total
396563 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-70293 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() which could lead to arbitrary code execution, a denial of service, or other unspecified impacts. | |||||
| CVE-2026-37067 | 2026-09-09 | N/A | 5.3 MEDIUM | ||
| Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially crafted POST request. | |||||
| CVE-2026-79423 | 2026-09-09 | N/A | 8.8 HIGH | ||
| An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request. | |||||
| CVE-2026-39113 | 2026-09-09 | N/A | 4.0 MEDIUM | ||
| Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11) and later snapshots/builds allows an attacker to cause a denial of service via the ext/misc/sqlar.c, sqlarUncompressFunc(), sqlar_uncompress(), sqlite3_value_int64(), sqlite3_malloc(int), uncompress() components | |||||
| CVE-2026-79569 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. | |||||
| CVE-2026-39254 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, CxAudioHidDevice::DeviceGetDescriptionString components | |||||
| CVE-2025-63823 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values. | |||||
| CVE-2026-75413 | 2026-09-09 | N/A | 7.5 HIGH | ||
| DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any file via the parameter targetPath. | |||||
| CVE-2026-50771 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary code via the Email Notification, Create Evaluation Sets and HTML Editor functions. | |||||
| CVE-2026-50775 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly. | |||||
| CVE-2025-52182 | 2026-09-09 | N/A | 7.5 HIGH | ||
| The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability. | |||||
| CVE-2026-38636 | 2026-09-09 | N/A | 7.5 HIGH | ||
| An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input. | |||||
| CVE-2026-50774 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role. | |||||
| CVE-2026-75161 | 2026-09-09 | N/A | 8.8 HIGH | ||
| An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to inject arbitrary code into the dpcheck system utility executed as root. | |||||
| CVE-2026-25250 | 2026-09-09 | N/A | 6.0 MEDIUM | ||
| EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable." | |||||
| CVE-2026-87733 | 2026-09-09 | N/A | 6.2 MEDIUM | ||
| An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key, signatures can be forged without a private key. | |||||
| CVE-2025-51684 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data received via window.postMessage before injecting it into the page DOM. An attacker can craft a malicious message that, when processed by renderCustomHtml, results in execution of arbitrary JavaScript in the context of the hosting site. | |||||
| CVE-2026-79576 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password. | |||||
| CVE-2026-52521 | 2026-09-09 | N/A | 8.1 HIGH | ||
| A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature. | |||||
| CVE-2026-79376 | 2026-09-09 | N/A | 8.8 HIGH | ||
| An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet. | |||||
