Total
397465 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-59322 | 2026-08-31 | N/A | 7.5 HIGH | ||
| CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext. | |||||
| CVE-2026-51785 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request | |||||
| CVE-2026-2334 | 2026-08-31 | N/A | N/A | ||
| An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to Remote Code Execution (RCE) within the context of the web application. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch. | |||||
| CVE-2026-67822 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow. | |||||
| CVE-2024-13942 | 2026-08-31 | N/A | 7.6 HIGH | ||
| Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of booting from external media (SPI NOR or NAND, EMMC or SD). The code reads the header of the next-stage loader twice. The header contains hashes of the executable modules and is signed with a private key, the public part of which is verified against the SHA256 digest blown in the OTP. The first read is only partial and contains only the hashes of the executable modules. The second is complete, including the header signature. Although the header is verified based on the fully read data, the authenticity of the executable modules is checked against the partial data from the first read. An attacker with physical access to a device containing RK3588s SoC can easily modify the next-stage loader data on-the-fly using a low-cost SD-card or SPI NOR/NAND or EMMC emulator. Even a simple ultra low-cost circuit comprising two memory chips (containing the same data but different headers - the original and the modified one) and a multiplexer can be used to carry out an attack. This can lead to arbitrary code execution with the highest privileges available (EL3). This issue affects RK3588s: RK3588s SoC BootROM (secure) 350B20210512V100 and possibly others. As remediation apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable https://www.rock-chips.com/a/en/products/RK35_Series/2022/0926/1660.html | |||||
| CVE-2026-67855 | 2026-08-31 | N/A | 7.5 HIGH | ||
| open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service. | |||||
| CVE-2026-72522 | 2026-08-31 | N/A | 6.2 MEDIUM | ||
| libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions. | |||||
| CVE-2026-67867 | 2026-08-31 | N/A | 7.5 HIGH | ||
| Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Alarm/Conditions wrapper when processing PublishResponse EventNotificationList data | |||||
| CVE-2026-68951 | 2026-08-31 | N/A | 5.3 MEDIUM | ||
| GROWI contains an incorrect authorization vulnerability. If this vulnerability is exploited, an unauthenticated attacker could retrieve the other user's bookmark data. | |||||
| CVE-2026-50986 | 2026-08-31 | N/A | 8.8 HIGH | ||
| PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validation controller has no CSRF token. An attacker can confirm an order in an awaiting status by hijacking a link. | |||||
| CVE-2026-67689 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints | |||||
| CVE-2025-69946 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_id, and ward_id. | |||||
| CVE-2026-67866 | 2026-08-31 | N/A | 7.5 HIGH | ||
| Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse and SOPC_StaMac_NewDeleteMonitoredItems in the client wrapper DeleteMonitoredItems path | |||||
| CVE-2025-59320 | 2026-08-31 | N/A | 4.6 MEDIUM | ||
| CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM. | |||||
| CVE-2026-67864 | 2026-08-31 | N/A | 7.5 HIGH | ||
| An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component | |||||
| CVE-2026-38709 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input. | |||||
| CVE-2026-67688 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code. | |||||
| CVE-2026-6484 | 2026-08-31 | N/A | 8.2 HIGH | ||
| In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution. | |||||
| CVE-2026-18127 | 2026-08-31 | N/A | 7.7 HIGH | ||
| External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage. | |||||
| CVE-2026-8810 | 2026-08-31 | N/A | 6.9 MEDIUM | ||
| On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables. | |||||
