Export limit exceeded: 24352 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 396652 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (396652 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-34689 | 1 Adobe | 2 Adobe Connect, Adobe Connect Android Mobile App | 2026-09-23 | 8.6 High |
| Adobe Connect is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed. | ||||
| CVE-2026-83964 | 1 Adobe | 2 Adobe Connect, Adobe Connect Android Mobile App | 2026-09-23 | 6.2 Medium |
| Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue does not require user interaction. | ||||
| CVE-2026-75689 | 1 Adobe | 2 Adobe Connect, Adobe Connect Android Mobile App | 2026-09-23 | 9.3 Critical |
| Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed. | ||||
| CVE-2026-81999 | 1 Adobe | 2 Aem 6.5 Forms Jee, Aem 6.5 Lts Forms Jee | 2026-09-23 | 8.7 High |
| Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed. | ||||
| CVE-2026-75744 | 1 Adobe | 2 Aem 6.5 Forms Jee, Aem 6.5 Lts Forms Jee | 2026-09-23 | 8.1 High |
| Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed. | ||||
| CVE-2026-75745 | 1 Adobe | 2 Aem 6.5 Forms Jee, Aem 6.5 Lts Forms Jee | 2026-09-23 | 10 Critical |
| Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. | ||||
| CVE-2026-75743 | 1 Adobe | 2 Aem 6.5 Forms Jee, Aem 6.5 Lts Forms Jee | 2026-09-23 | 7.1 High |
| Adobe Experience Manager Forms JEE is affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. | ||||
| CVE-2026-76712 | 1 Hewlett Packard Enterprise (hpe) | 1 Ale | 2026-09-23 | 7.3 High |
| A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service. An unauthenticated remote attacker could exploit the vulnerable system by sending specially crafted input or intercepting network communications. Successful exploitation could result in the disclosure of sensitive information, bypass of security controls, or a denial of service condition on the affected system. | ||||
| CVE-2026-76713 | 1 Hewlett Packard Enterprise (hpe) | 1 Ale | 2026-09-23 | 7.2 High |
| A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker to gain unauthorized access to the file system with root privileges, potentially resulting in full system compromise. | ||||
| CVE-2026-76714 | 1 Hewlett Packard Enterprise (hpe) | 1 Ale | 2026-09-23 | 7.2 High |
| Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise. | ||||
| CVE-2026-76715 | 1 Hewlett Packard Enterprise (hpe) | 1 Ale | 2026-09-23 | 7.1 High |
| A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-middle (MitM) attack. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the affected appliance. | ||||
| CVE-2026-76716 | 1 Hewlett Packard Enterprise (hpe) | 1 Ale | 2026-09-23 | 5.3 Medium |
| Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or denial of service. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted input or leveraging improper security configurations. Successful exploitation could result in a denial of service condition or unauthorized access to sensitive information. | ||||
| CVE-2026-76717 | 1 Hewlett Packard Enterprise (hpe) | 1 Ale | 2026-09-23 | 5.3 Medium |
| A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input to a specific API endpoint. Successful exploitation could result in the disclosure of sensitive user information, including password hashes, which could be used to facilitate further attacks. | ||||
| CVE-2026-47116 | 1 Ltsecurity | 1 Ltk3500sf | 2026-09-23 | 9.8 Critical |
| LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where root and guest account passwords are stored as reversible hashes in /etc/shadow, recoverable using dictionary-based cracking tools. Attackers can use the recovered credentials to authenticate via Telnet or SSH and obtain full root-level access to the operating system. | ||||
| CVE-2026-63104 | 1 Usekaneo | 1 Kaneo | 2026-09-23 | 8.1 High |
| Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace members with viewer or member roles to delete and modify tasks beyond their assigned permissions by exploiting the bulk task endpoint that omits workspace permission checks. Attackers can send requests to the PATCH /api/task/bulk endpoint, which verifies only workspace membership without calling the role-based permission check enforced on all other task endpoints, to permanently delete all tasks or modify task status, priority, assignee, due date, and labels in a workspace. | ||||
| CVE-2026-87121 | 1 Lwip | 1 Tcp/ip Stack Mqtt | 2026-09-23 | 9.8 Critical |
| lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device. | ||||
| CVE-2026-61570 | 1 Joniles | 1 Mpxj | 2026-09-23 | 7.5 High |
| MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 5.5.5 until 16.4.1, MerlinReader creates a DocumentBuilder with default settings while parsing XML from the ZTIMEINTERVALS column of a Merlin project SQLite database, leaving doctype declarations and external entities enabled. A crafted database can cause the parser to read an arbitrary local file, although MPXJ's subsequent handling of the parsed XML makes disclosure of the file contents unlikely. This issue is fixed in version 16.4.1. | ||||
| CVE-2026-95813 | 1 E621ng | 1 E621ng | 2026-09-23 | 6.1 Medium |
| e621ng versions before 26.09.16 pass untrusted request parameters directly to Rails url_for in PaginatorComponent and controller navigation links, allowing attackers to redirect pagination and navigation controls to attacker-controlled origins. Attackers can supply host, protocol, and port query parameters that are interpreted as URL generation options, causing pagination links to point to malicious domains while the initial page loads from the legitimate site. | ||||
| CVE-2026-88020 | 1 Autonomy Logic | 1 Openplc Runtime | 2026-09-23 | 6.1 Medium |
| Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding. | ||||
| CVE-2026-17618 | 1 Ibm | 2 Financial Transaction Manager (ftm) for Redhat Openshift, Financial Transaction Manager Ftmfor Redhat Openshift | 2026-09-23 | 7.3 High |
| IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization. | ||||