Export limit exceeded: 376174 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 376174 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (376174 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65769 | 1 Microsoft | 1 Teams | 2026-08-11 | 6.5 Medium |
| Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-65660 | 1 Microsoft | 3 Sharepoint Server, Sharepoint Server 2016, Sharepoint Server 2019 | 2026-08-11 | 6.5 Medium |
| Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||||
| CVE-2026-65655 | 2026-08-11 | N/A | ||
| When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to Temporal UI Server over HTTP, affected versions derive authentication-cookie Secure attributes from the proxy-to-server connection. Temporal UI Server can therefore issue access-token cookies, and refresh-token cookies when provided by the identity provider, without Secure even though the browser completed login over HTTPS. A victim who visits attacker-controlled content while a credential remains live may expose that credential only if the attacker can also steer traffic for the UI hostname, prevent the browser's HTTPS connection from succeeding, serve the hostname over HTTP, and read a later same-site plaintext request. A malicious website alone cannot read the cookie, and passive observation of a successful TLS connection is insufficient. Effective HSTS, a blocking HTTPS-only warning, or TLS re-encryption between the proxy and Temporal UI Server prevents the demonstrated disclosure path. A recovered credential may be replayed within the victim's assigned permissions. Refresh-token replay additionally depends on the identity provider's issuance, expiry, rotation, and reuse-detection behavior. | ||||
| CVE-2026-64899 | 1 Microsoft | 8 365 Apps, Office 2016, Office 2019 and 5 more | 2026-08-11 | 5.5 Medium |
| Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-63531 | 1 Microsoft | 8 365 Apps, Office 2019, Office 2021 and 5 more | 2026-08-11 | 5.5 Medium |
| Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||||
| CVE-2026-62915 | 1 Microsoft | 3 Exchange Server 2016, Exchange Server 2019, Exchange Server Se | 2026-08-11 | 6.5 Medium |
| Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. | ||||
| CVE-2026-62893 | 1 Microsoft | 8 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 5 more | 2026-08-11 | 9.8 Critical |
| Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-62887 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2026-08-11 | 5.5 Medium |
| Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-62837 | 1 Microsoft | 3 Sharepoint Server, Sharepoint Server 2016, Sharepoint Server 2019 | 2026-08-11 | 6.5 Medium |
| Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | ||||
| CVE-2026-62798 | 1 Microsoft | 5 Windows 11 23h2, Windows 11 24h2, Windows 11 25h2 and 2 more | 2026-08-11 | 5.5 Medium |
| Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-62775 | 1 Microsoft | 1 Windows 11 26h1 | 2026-08-11 | 5.5 Medium |
| Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-62730 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2026-08-11 | 5.5 Medium |
| Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-62714 | 1 Microsoft | 8 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 5 more | 2026-08-11 | 6.5 Medium |
| Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | ||||
| CVE-2026-62709 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2026-08-11 | 5.5 Medium |
| Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-62702 | 1 Microsoft | 8 Windows 10 21h2, Windows 10 22h2, Windows 11 23h2 and 5 more | 2026-08-11 | 6.8 Medium |
| Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-61928 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-08-11 | 5.5 Medium |
| Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. | ||||
| CVE-2026-59138 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2026-08-11 | 6.5 Medium |
| Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. | ||||
| CVE-2026-59131 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-08-11 | 5.6 Medium |
| No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-50516 | 1 Microsoft | 1 Azure Kubernetes Service | 2026-08-11 | 9.4 Critical |
| Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-19579 | 2026-08-11 | 5.4 Medium | ||
| Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated, low-privileged user can supply a non-empty cancel_by_admin value to bypass the request-ownership check and cancel another user's pending checkout request. Because asset and user identifiers are sequential integers, an attacker can enumerate them to cancel every pending checkout request, disrupting the asset-request workflow. This is fixed in Snipe-IT 8.6.0. | ||||