Export limit exceeded: 402912 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402912 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402912 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-102101 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 8.1 High |
| Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely, potentially resulting in remote code execution on the appliance. Exploitation depends on an attacker first being able to influence the affected data, so this issue is not exploitable on its own. | ||||
| CVE-2026-102100 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 8.7 High |
| Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user to submit content that, when later viewed by another user, executes arbitrary JavaScript in that user's authenticated session. This could be used to perform actions on the victim's behalf and may have permitted account takeover, including of higher-privileged users. Exploitation requires the victim to view the attacker-supplied content. | ||||
| CVE-2026-102099 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.2 High |
| Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a Kiteworks administrative export feature could allow an authenticated administrator to write a file to an arbitrary location on the underlying host, potentially leading to command execution on the appliance. Exploitation requires an existing, authenticated administrative account with access to the affected export function. | ||||
| CVE-2026-102098 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.2 High |
| Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an existing, authenticated administrative account with access to the affected reporting function. | ||||
| CVE-2026-102096 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.2 High |
| Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted package could cause the underlying system to execute arbitrary operating-system commands, potentially with elevated privileges, on the affected appliance. | ||||
| CVE-2026-102093 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 7.2 High |
| Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-management permissions to elevate another user to full system-administrator privileges beyond those the administrative user was authorized to grant. | ||||
| CVE-2026-102092 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 8.7 High |
| Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated session when they preview shared content. This could potentially lead to session compromise and account takeover. | ||||
| CVE-2026-106254 | 1 Google | 2 Android, Chrome | 2026-10-07 | 5.1 Medium |
| Information leak in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: Medium) | ||||
| CVE-2026-102090 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 4.3 Medium |
| Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain. This could increase the credibility of phishing attempts relying on malicious links embedded in the displayed content. | ||||
| CVE-2026-106415 | 1 Google | 1 Chrome | 2026-10-07 | 4.3 Medium |
| Information leak in Enterprise in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106416 | 1 Google | 1 Chrome | 2026-10-07 | 5.4 Medium |
| Code injection in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium) | ||||
| CVE-2026-106343 | 1 Google | 1 Chrome | 2026-10-07 | 5.4 Medium |
| Improper state validation in Autofill AI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-76742 | 2026-10-07 | 9.8 Critical | ||
| Authentication bypass vulnerabilities exist in the web management interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to gain unauthorized access to the affected system. | ||||
| CVE-2026-49933 | 1 Google | 1 Android | 2026-10-07 | 7.8 High |
| In handle_le_monitor_device_event of msft.cc, there is a possible control-flow hijack in the privileged bluetooth process due to an uninitialized pointer dereference. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-106414 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-10-07 | 9.6 Critical |
| Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106413 | 1 Google | 1 Chrome | 2026-10-07 | 4.2 Medium |
| Race condition in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106255 | 1 Google | 1 Chrome | 2026-10-07 | 7.5 High |
| Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-106256 | 1 Google | 2 Android, Chrome | 2026-10-07 | 8.8 High |
| Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106253 | 1 Google | 1 Chrome | 2026-10-07 | 4.3 Medium |
| Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium) | ||||
| CVE-2026-106252 | 1 Google | 1 Chrome | 2026-10-07 | 8.8 High |
| Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) | ||||