Export limit exceeded: 381370 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 381370 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381370 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16996 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 8.8 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an integer underflow. | ||||
| CVE-2026-16991 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 7.8 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper handling of symbolic links. | ||||
| CVE-2026-69855 | 1 Microsoft | 1 Microsoft Copilot In Azure | 2026-08-20 | 7.7 High |
| Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network. | ||||
| CVE-2026-69543 | 1 Microsoft | 1 Azure Virtual Machines | 2026-08-20 | 8.5 High |
| Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69558 | 1 Microsoft | 1 Partner Center | 2026-08-20 | 8.6 High |
| Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-69555 | 1 Microsoft | 1 Azure Arc | 2026-08-20 | 10 Critical |
| Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69400 | 1 Microsoft | 1 Azure Logic Apps | 2026-08-20 | 9.6 Critical |
| Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69419 | 1 Microsoft | 1 Azure Data Manager For Energy | 2026-08-20 | 8.5 High |
| Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-68782 | 1 Microsoft | 1 Azure Sql Database | 2026-08-20 | 9.9 Critical |
| Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-66800 | 1 Microsoft | 1 Azure Data Factory | 2026-08-20 | 8.6 High |
| Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-66309 | 1 Microsoft | 1 Azure Sql Database | 2026-08-20 | 9.1 Critical |
| Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-65816 | 1 Microsoft | 1 Azure Web Apps | 2026-08-20 | 10 Critical |
| Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-63509 | 1 Microsoft | 1 Microsoft Fabric | 2026-08-20 | 9.9 Critical |
| Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-65770 | 1 Microsoft | 1 Azure Managed Instance For Apache Cassandra | 2026-08-20 | 10 Critical |
| Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-16989 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 7.1 High |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper resolution of symbolic links. | ||||
| CVE-2026-70105 | 1 Microsoft | 8 365 Apps, Office 2019, Office 2021 and 5 more | 2026-08-20 | 6.5 Medium |
| Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-54508 | 2026-08-20 | N/A | ||
| TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before native redirect following in importGoogleList() and importNaverList() in server/src/services/placeService.ts and resolveGoogleMapsUrl() in server/src/services/mapsService.ts. The affected sinks call checkSsrf() from server/src/utils/ssrfGuard.ts and then use fetch() with redirect: 'follow' instead of the DNS-pinned safeFetch() path, so a public attacker-controlled URL can redirect the server to loopback, RFC 1918, or cloud metadata addresses without revalidation. An authenticated trip member can reach the list-import routes, and any authenticated user can reach /api/maps/resolve-url, allowing blind GET requests to internal services without response-body reflection. This issue is fixed in version 3.1.0. | ||||
| CVE-2026-16980 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 6.3 Medium |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper validation of symbolic links. | ||||
| CVE-2026-65795 | 1 Microsoft | 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more | 2026-08-20 | 6.7 Medium |
| Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-16973 | 1 Ibm | 2 Aix, Powervm Vios | 2026-08-20 | 5.5 Medium |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to disclose sensitive kernel memory due to an out-of-bounds read. | ||||