Total
396563 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-63913 | 2026-09-09 | N/A | 7.5 HIGH | ||
| An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension. | |||||
| CVE-2021-44319 | 2026-09-09 | N/A | 7.5 HIGH | ||
| Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight. | |||||
| CVE-2026-67977 | 2026-09-09 | N/A | 7.5 HIGH | ||
| An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |||||
| CVE-2022-30983 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the Enter email parameter. | |||||
| CVE-2026-30250 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to execute arbitrary code | |||||
| CVE-2021-43717 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection function, you can access the projector using hard-coded authentication information and control the projector maliciously. | |||||
| CVE-2026-51366 | 2026-09-09 | N/A | 9.9 CRITICAL | ||
| SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter | |||||
| CVE-2026-77506 | 2026-09-09 | N/A | 4.8 MEDIUM | ||
| Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS. | |||||
| CVE-2026-67846 | 2026-09-09 | N/A | 7.8 HIGH | ||
| Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a potential incorrect privilege assignment issue in the v3 and v4 NBDTLB implementations. The raw mstatus.SUM value participates in the read and write permission logic without an explicit local satp.MODE validity check at the use site | |||||
| CVE-2026-51775 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.php component | |||||
| CVE-2026-67967 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-44867 and CVE-2026-36819 | |||||
| CVE-2026-67868 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary code. | |||||
| CVE-2026-38638 | 2026-09-09 | N/A | 7.5 HIGH | ||
| An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input. | |||||
| CVE-2026-51346 | 2026-09-09 | N/A | 9.1 CRITICAL | ||
| SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions. | |||||
| CVE-2026-77643 | 2026-09-09 | N/A | 4.4 MEDIUM | ||
| A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499. | |||||
| CVE-2026-75438 | 2026-09-09 | N/A | 7.5 HIGH | ||
| Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function | |||||
| CVE-2026-39255 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, dup_wcs components | |||||
| CVE-2026-71626 | 2026-09-09 | N/A | 7.5 HIGH | ||
| An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components | |||||
| CVE-2025-67066 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path | |||||
| CVE-2026-77650 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution. | |||||
