Total
396887 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-69276 | 2026-09-08 | N/A | 9.8 CRITICAL | ||
| Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69271 | 2026-09-08 | N/A | 8.0 HIGH | ||
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-68890 | 2026-09-08 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-68885 | 2026-09-08 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-58649 | 2026-09-08 | N/A | 6.5 MEDIUM | ||
| Origin validation error in .NET allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-55273 | 2026-09-08 | N/A | 7.8 HIGH | ||
| In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-49921 | 2026-09-08 | N/A | 9.8 CRITICAL | ||
| In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-27258 | 1 Adobe | 1 Dng Software Development Kit | 2026-09-08 | N/A | 5.4 MEDIUM |
| Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | |||||
| CVE-2026-27222 | 3 Adobe, Apple, Microsoft | 3 Bridge, Macos, Windows | 2026-09-08 | N/A | 5.4 MEDIUM |
| Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | |||||
| CVE-2026-21269 | 1 Adobe | 1 Coldfusion | 2026-09-08 | N/A | 4.6 MEDIUM |
| ColdFusion is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. | |||||
| CVE-2026-19843 | 2026-09-08 | N/A | 8.4 HIGH | ||
| A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host. | |||||
| CVE-2025-70152 | 1 Fabian | 1 Scholars Tracking System | 2026-09-08 | N/A | 9.8 CRITICAL |
| code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters (firstname, lastname, username, password, user_id) into SQL queries without validation or parameterization. | |||||
| CVE-2025-70151 | 1 Fabian | 1 Scholars Tracking System | 2026-09-08 | N/A | 8.8 HIGH |
| code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the original, user-supplied filename without validating the file type or extension. By uploading a PHP file and then requesting it from /uploads/, an attacker can execute arbitrary PHP code as the web server user. | |||||
| CVE-2025-70150 | 1 Codeastro | 1 Membership Management System | 2026-09-08 | N/A | 9.8 CRITICAL |
| CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter. | |||||
| CVE-2025-70149 | 1 Codeastro | 1 Membership Management System | 2026-09-08 | N/A | 9.8 CRITICAL |
| CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter. | |||||
| CVE-2025-70148 | 1 Codeastro | 1 Membership Management System | 2026-09-08 | N/A | 7.5 HIGH |
| Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure direct object reference (IDOR). | |||||
| CVE-2025-70147 | 1 Projectworlds | 1 Online Time Table Generator | 2026-09-08 | N/A | 7.5 HIGH |
| Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET requests to these endpoints without a valid session. | |||||
| CVE-2025-70146 | 1 Projectworlds | 1 Online Time Table Generator | 2026-09-08 | N/A | 9.1 CRITICAL |
| Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting records) via direct HTTP requests to affected endpoints without a valid session. | |||||
| CVE-2025-70141 | 1 Oretnom23 | 1 Customer Support System | 2026-09-08 | N/A | 9.4 CRITICAL |
| SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php based on the action parameter. An unauthenticated remote attacker can perform sensitive operations such as creating customers and deleting users (including the admin account), as well as modifying or deleting other application records (tickets, departments, comments), resulting in unauthorized data modification. | |||||
| CVE-2025-34115 | 2026-09-08 | N/A | N/A | ||
| An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint. A user with access to the web interface can exploit the 'Test this command' feature to execute arbitrary shell commands as the unprivileged web application user. The vulnerability resides in the configuration section of the application and requires valid login credentials with access to the command testing functionality. This issue is fixed in version 7.2.0. | |||||
