Total
396574 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-51684 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data received via window.postMessage before injecting it into the page DOM. An attacker can craft a malicious message that, when processed by renderCustomHtml, results in execution of arbitrary JavaScript in the context of the hosting site. | |||||
| CVE-2026-79576 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password. | |||||
| CVE-2026-52521 | 2026-09-09 | N/A | 8.1 HIGH | ||
| A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature. | |||||
| CVE-2026-79376 | 2026-09-09 | N/A | 8.8 HIGH | ||
| An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet. | |||||
| CVE-2025-63913 | 2026-09-09 | N/A | 7.5 HIGH | ||
| An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension. | |||||
| CVE-2021-44319 | 2026-09-09 | N/A | 7.5 HIGH | ||
| Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight. | |||||
| CVE-2026-67977 | 2026-09-09 | N/A | 7.5 HIGH | ||
| An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |||||
| CVE-2022-30983 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the Enter email parameter. | |||||
| CVE-2026-30250 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to execute arbitrary code | |||||
| CVE-2021-43717 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection function, you can access the projector using hard-coded authentication information and control the projector maliciously. | |||||
| CVE-2026-51366 | 2026-09-09 | N/A | 9.9 CRITICAL | ||
| SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter | |||||
| CVE-2026-77506 | 2026-09-09 | N/A | 4.8 MEDIUM | ||
| Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS. | |||||
| CVE-2026-67846 | 2026-09-09 | N/A | 7.8 HIGH | ||
| Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a potential incorrect privilege assignment issue in the v3 and v4 NBDTLB implementations. The raw mstatus.SUM value participates in the read and write permission logic without an explicit local satp.MODE validity check at the use site | |||||
| CVE-2026-51775 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.php component | |||||
| CVE-2026-67967 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-44867 and CVE-2026-36819 | |||||
| CVE-2026-67868 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary code. | |||||
| CVE-2026-38638 | 2026-09-09 | N/A | 7.5 HIGH | ||
| An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input. | |||||
| CVE-2026-51346 | 2026-09-09 | N/A | 9.1 CRITICAL | ||
| SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions. | |||||
| CVE-2026-77643 | 2026-09-09 | N/A | 4.4 MEDIUM | ||
| A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499. | |||||
| CVE-2026-75438 | 2026-09-09 | N/A | 7.5 HIGH | ||
| Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function | |||||
