Export limit exceeded: 376416 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (376416 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-62887 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2026-08-11 | 5.5 Medium |
| Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-62837 | 1 Microsoft | 3 Sharepoint Server, Sharepoint Server 2016, Sharepoint Server 2019 | 2026-08-11 | 6.5 Medium |
| Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | ||||
| CVE-2026-62798 | 1 Microsoft | 5 Windows 11 23h2, Windows 11 24h2, Windows 11 25h2 and 2 more | 2026-08-11 | 5.5 Medium |
| Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-62775 | 1 Microsoft | 1 Windows 11 26h1 | 2026-08-11 | 5.5 Medium |
| Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-62730 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2026-08-11 | 5.5 Medium |
| Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-62714 | 1 Microsoft | 8 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 5 more | 2026-08-11 | 6.5 Medium |
| Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | ||||
| CVE-2026-62709 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more | 2026-08-11 | 5.5 Medium |
| Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-62702 | 1 Microsoft | 8 Windows 10 21h2, Windows 10 22h2, Windows 11 23h2 and 5 more | 2026-08-11 | 6.8 Medium |
| Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-61928 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-08-11 | 5.5 Medium |
| Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. | ||||
| CVE-2026-19077 | 2 Duplicate Post Project, Wordpress | 2 Duplicate Post, Wordpress | 2026-08-11 | 6.5 Medium |
| The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Duplicate Post WordPress plugin before 1.5.5 access to permanently delete arbitrary posts on the site, including those belonging to other users. | ||||
| CVE-2026-19075 | 2 Plugins360, Wordpress | 2 All-in-one Video Gallery, Wordpress | 2026-08-11 | 5 Medium |
| All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back to the requester. | ||||
| CVE-2026-19049 | 2 Prosolution, Wordpress | 2 Prosolution Wp Client, Wordpress | 2026-08-11 | 8.6 High |
| The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the database and to delete the records the ProSolution WP Client WordPress plugin before 2.0.9 stores. | ||||
| CVE-2026-18960 | 2026-08-11 | 5.4 Medium | ||
| The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API. | ||||
| CVE-2026-18934 | 2026-08-11 | 5.5 Medium | ||
| The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed to edit the import job named in the request, allowing users with author-level access and above to permanently delete the posts created by another user's import job, reset its deduplication and scheduling state, disable it, or clear its error log. One of the affected actions performs no object-type check either, so arbitrary posts and pages can also be unpublished regardless of who owns them. | ||||
| CVE-2026-18844 | 2026-08-11 | 8.1 High | ||
| The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never issued by the companion mobile application, yet are fully processed by the device when it is powered on. | ||||
| CVE-2026-18707 | 2026-08-11 | 4.3 Medium | ||
| An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the server process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service. | ||||
| CVE-2026-18705 | 2026-08-11 | 6.5 Medium | ||
| An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process. | ||||
| CVE-2026-18704 | 2026-08-11 | 6.5 Medium | ||
| An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to modify. This is due to an internal-use aggregation stage being reachable by external clients without an appropriate authorization check on its embedded operations. | ||||
| CVE-2026-18701 | 2026-08-11 | 6.5 Medium | ||
| An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpectedly by submitting a specially formed query filter. This could result in a denial of service. | ||||
| CVE-2026-18666 | 2026-08-11 | 4.3 Medium | ||
| The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing users with a role as low as Subscriber to perform SQL injection and extract arbitrary data from the database, including user password hashes. | ||||