Export limit exceeded: 395909 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 395909 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (395909 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65330 | 1 Apple | 4 Ios And Ipados, Ipados, Iphone Os and 1 more | 2026-09-21 | 6.5 Medium |
| The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory. | ||||
| CVE-2026-65346 | 1 Apple | 4 Ios And Ipados, Ipados, Iphone Os and 1 more | 2026-09-21 | 8.8 High |
| An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to arbitrary code execution. | ||||
| CVE-2026-64760 | 1 Apple | 3 Ios And Ipados, Ipados, Iphone Os | 2026-09-21 | 5.5 Medium |
| An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to leak sensitive kernel state. | ||||
| CVE-2026-78953 | 1 Google | 1 Chrome | 2026-09-21 | 3.1 Low |
| Missing authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium) | ||||
| CVE-2026-75429 | 1 Powerjob | 1 Powerjob | 2026-09-21 | 9.8 Critical |
| PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layer | ||||
| CVE-2026-71801 | 2026-09-21 | 9.8 Critical | ||
| An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A remote, unauthenticated attacker can locally forge valid administrative session tokens to completely bypass the authentication mechanism gaining full unauthorized access to protected backend APIs. | ||||
| CVE-2026-79387 | 1 Pbootcms | 1 Pbootcms | 2026-09-21 | 4.3 Medium |
| SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface, enabling account takeover. | ||||
| CVE-2026-64718 | 1 Apple | 8 Ios And Ipados, Ipados, Iphone Os and 5 more | 2026-09-21 | 5.5 Medium |
| A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, Safari 27, iOS 26.6 and iPadOS 26.6, iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, visionOS 27, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. | ||||
| CVE-2026-43748 | 1 Apple | 1 Macos | 2026-09-21 | 9.8 Critical |
| An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination. | ||||
| CVE-2026-43698 | 1 Apple | 1 Macos | 2026-09-21 | 7.8 High |
| An injection issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.7. An app may be able to gain root privileges. | ||||
| CVE-2026-43760 | 1 Apple | 1 Macos | 2026-09-21 | 8.6 High |
| An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may be able to access user-sensitive data. | ||||
| CVE-2026-65329 | 1 Apple | 3 Ios And Ipados, Ipados, Iphone Os | 2026-09-21 | 5.9 Medium |
| An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, iOS 27 and iPadOS 27. An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic. | ||||
| CVE-2026-94144 | 1 Drogon | 1 Drogon | 2026-09-21 | 7.3 High |
| A flaw has been found in drogonframework drogon up to 1.9.13. This affects the function makeCriteria in the library orm_lib/src/Criteria.cc of the component ORM. Executing a manipulation of the argument filter can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-65343 | 1 Apple | 4 Ios And Ipados, Ipados, Iphone Os and 1 more | 2026-09-21 | 7.5 High |
| A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. A remote attacker may be able to cause unexpected system termination. | ||||
| CVE-2026-52023 | 1 Kamailio | 1 Kamailio | 2026-09-21 | 7.5 High |
| An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree() | ||||
| CVE-2026-65347 | 1 Apple | 4 Ios And Ipados, Ipados, Iphone Os and 1 more | 2026-09-21 | 6.5 Medium |
| The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to a denial-of-service. | ||||
| CVE-2026-79419 | 1 Emxtecnologia | 1 Gestao X Business Suite | 2026-09-21 | 8.7 High |
| A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao/Imagens.aspx endpoint, allowing an authenticated attacker to inject arbitrary JavaScript code that is reflected and executed in the context of a victim's browser. | ||||
| CVE-2026-78849 | 1 Netgate | 1 Pfsense | 2026-09-21 | 5.4 Medium |
| Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 allows a remote attacker to execute arbitrary code via the captive_portal_status.widget.php file | ||||
| CVE-2026-75167 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-21 | 4.3 Medium |
| A broken access control vulnerability in the ugw-usr-edit method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to change the password of arbitrary accounts. | ||||
| CVE-2026-71620 | 2026-09-21 | 8.1 High | ||
| File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote attacker to execute arbitrary code via a crafted .php file | ||||