Search

Search Results (326718 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-13008 2 M-files, M-files Corporation 3 M-files Server, Server, M-files Server 2026-01-07 N/A
An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using M-Files Web to capture session tokens of other active users.
CVE-2025-14267 1 M-files 3 M-files, M-files Server, Server 2026-01-07 4.9 Medium
Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows data leak exposure affecting versions before 25.12.15491.7
CVE-2025-14318 1 M-files 2 M-files Server, Server 2026-01-07 4.3 Medium
Improper access checks in M-Files Server before 25.12.15491.7 allows users to download files through M-Files Web using Web Companion despite Print and Download Prevention module being enabled.
CVE-2026-22162 2026-01-07 N/A
Not used
CVE-2026-22161 2026-01-07 N/A
Not used
CVE-2026-22160 2026-01-07 N/A
Not used
CVE-2026-22159 2026-01-07 N/A
Not used
CVE-2026-22158 2026-01-07 N/A
Not used
CVE-2026-22157 2026-01-07 N/A
Not used
CVE-2026-22156 2026-01-07 N/A
Not used
CVE-2025-30025 2026-01-07 N/A
The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.
CVE-2025-14625 1 Altera 2 Quartus Prime Lite, Quartus Prime Standard 2026-01-07 6.7 Medium
Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard on Windows (Nios II Command Shell modules), Altera Quartus Prime Lite on Windows (Nios II Command Shell modules) allows Search Order Hijacking.This issue affects Quartus Prime Standard: from 19.1 through 24.1; Quartus Prime Lite: from 19.1 through 24.1.
CVE-2025-14614 1 Altera 2 Quartus Prime Lite, Quartus Prime Standard 2026-01-07 6.7 Medium
Insecure Temporary File vulnerability in Altera Quartus Prime StandardĀ  Installer (SFX) on Windows, Altera Quartus Prime LiteĀ  Installer (SFX) on Windows allows Explore for Predictable Temporary File Names.This issue affects Quartus Prime Standard: from 23.1 through 24.1; Quartus Prime Lite: from 23.1 through 24.1.
CVE-2025-10876 1 Talentsoftware 1 Bap Automation 2026-01-07 5.3 Medium
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software e-BAP Automation allows Cross-Site Scripting (XSS).This issue affects e-BAP Automation: from 1.8.96 before v.41815.
CVE-2025-15416 1 Xnx3 1 Wangmarket 2026-01-07 2.4 Low
A vulnerability was found in xnx3 wangmarket up to 6.4. This affects an unknown function of the file /siteVar/save.do of the component Add Global Variable Handler. The manipulation of the argument Remark/Variable Value results in cross site scripting. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-21488 1 Internationalcolorconsortium 1 Iccdev 2026-01-07 6.1 Medium
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Out-of-bounds Read, Heap-based Buffer Overflow and Improper Null Termination through its CIccTagText::Read function. This issue is fixed in version 2.3.1.2.
CVE-2026-21489 1 Internationalcolorconsortium 1 Iccdev 2026-01-07 6.1 Medium
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below have Out-of-bounds Read and Integer Underflow (Wrap or Wraparound) vulnerabilities in its CIccCalculatorFunc::SequenceNeedTempReset function. This issue is fixed in version 2.3.1.2.
CVE-2026-21493 1 Internationalcolorconsortium 1 Iccdev 2026-01-07 6.6 Medium
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Type Confusion in its CIccSingleSampledeCurveXml class during XML Curve Serialization. This issue is fixed in version 2.3.1.2.
CVE-2025-14026 1 Forcepoint 1 One Endpoint 2026-01-07 7.8 High
Forcepoint One DLP Client, version 23.04.5642 (and possibly newer versions), includes a restricted version of Python 2.5.4 that prevents use of the ctypes library. ctypes is a foreign function interface (FFI) for Python, enabling calls to DLLs/shared libraries, memory allocation, and direct code execution. It was demonstrated that these restrictions could be bypassed.
CVE-2025-20793 1 Mediatek 49 Mt2735, Mt2737, Mt6813 and 46 more 2026-01-07 7.5 High
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01430930; Issue ID: MSV-4836.