Export limit exceeded: 389535 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (389535 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-82563 | 2026-09-09 | 7.6 High | ||
| An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of firmware-update behavior. | ||||
| CVE-2026-81640 | 2026-09-09 | 8.8 High | ||
| An attacker could derive the camera's Wi-Fi password and connect to its wireless network. This weakens or eliminates the security value of the access-point password and may expose the live video stream, device services, status interfaces, and firmware-update functionality. | ||||
| CVE-2026-81330 | 2026-09-09 | 6.5 Medium | ||
| The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames transmitted over UDP. An attacker within local wireless range may capture and reconstruct the live video stream without transport encryption. | ||||
| CVE-2026-79617 | 2026-09-09 | 7.1 High | ||
| Incorrect Permission Assignment for Critical Resource vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus LightDM Greeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pardus LightDM Greeter: before 0.4.15. | ||||
| CVE-2026-79572 | 2026-09-09 | 7.5 High | ||
| An XXE (XML External Entity) vulnerability in the level-rule module of Distribution Management v1.0.0 allows attackers to read sensitive files, scan internal networks, or launch server attacks via supplying a crafted XML payload. | ||||
| CVE-2026-79419 | 1 Emxtecnologia | 1 Gestao X Business Suite | 2026-09-09 | 6.1 Medium |
| A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao/Imagens.aspx endpoint, allowing an authenticated attacker to inject arbitrary JavaScript code that is reflected and executed in the context of a victim's browser. | ||||
| CVE-2026-79323 | 2026-09-09 | 7.5 High | ||
| Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal customer and admin identifiers via a POST request to /graphql. | ||||
| CVE-2026-79322 | 2026-09-09 | 8.6 High | ||
| SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id parameter to /mpblog/post/view. | ||||
| CVE-2026-78839 | 2026-09-09 | 8.1 High | ||
| An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attackers to execute arbitrary code via uploading a crafted .phar file. | ||||
| CVE-2026-78838 | 1 Appnitro | 1 Machform | 2026-09-09 | 6.5 Medium |
| A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted payload into the filter[filters][0][field] parameter. | ||||
| CVE-2026-78738 | 2026-09-09 | 6.1 Medium | ||
| Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature. | ||||
| CVE-2026-77974 | 2026-09-09 | 8 High | ||
| After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel. | ||||
| CVE-2026-75170 | 1 Hubcore | 1 Hubcore | 2026-09-09 | 6.1 Medium |
| Cross-site scripting (XSS) vulnerability in the /loginController/doLogin endpoint of the HubCore platform (version 14.1.1) allows a remote unauthenticated attacker to inject arbitrary JavaScript into the application's response via the language POST parameter. | ||||
| CVE-2026-75166 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-09 | 8.8 High |
| Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a password. By leveraging the tcpdump -z option, an authenticated attacker can achieve arbitrary command execution. | ||||
| CVE-2026-75162 | 1 Mbs-solutions | 1 X-serie Gateway | 2026-09-09 | 6.5 Medium |
| An information disclosure vulnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows any remote authenticated user, including users with the low-privileged Standard role, to retrieve the configured OPC-UA authentication credentials in cleartext via the JSON API response. | ||||
| CVE-2026-71625 | 1 Slimkit | 1 Thinksns+ | 2026-09-09 | 9.8 Critical |
| An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component | ||||
| CVE-2026-71622 | 2026-09-09 | 7.4 High | ||
| SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information via the User.php component | ||||
| CVE-2026-67403 | 2026-09-09 | N/A | ||
| Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant identifier. | ||||
| CVE-2026-70582 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2026-09-09 | 6.4 Medium |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69819 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2026-09-09 | 9.8 Critical |
| Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network. | ||||