Export limit exceeded: 28591 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400113 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400113 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-61807 | 2 Grokability, Snipeitapp | 2 Snipe-it, Snipe-it | 2026-09-30 | 6.1 Medium |
| Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the table component $name becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-side code reads the browser-decoded countId, uses it as a selector, concatenates countId.substring(1) into an HTML string, and passes the string to jQuery .after(). A crafted name can therefore execute JavaScript when an authenticated user views the manufacturer detail page or supplier detail page, potentially exposing data or actions available to that session. This issue is fixed in version 8.6.2. | ||||
| CVE-2026-69325 | 1 Microsoft | 20 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 17 more | 2026-09-30 | 8.1 High |
| Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-103116 | 1 Os4ed | 1 Opensis-classic | 2026-09-30 | 6.3 Medium |
| A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-77185 | 1 Apache | 1 Mina Sshd | 2026-09-30 | 9.1 Critical |
| Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server. Apache MINA SSHD is a Java library for client- and server-side SSH. In the server part of the library, a mechanism to perform "asynchronous authentication" exists. A server implemented with Apache MINA SSHD must contain explicit code to make use of this feature. The implementation of this feature was flawed and could potentially lead to skipping checking the signature in public-key or hostbased authentication, or returning a wrong result. Users are recommended to upgrade to Apache MINA SSHD 2.20.0 or 3.0.0-M6, which fix the logic error and which additionally forbid the use of this "asynchronous authentication" mechanism with the public-key or hostbased authentication schemes: if used, the SSH session will be closed and the server will log an entry indicating that asynchronous authentication may be used only with password or keyboard-interactive authentication. | ||||
| CVE-2026-69329 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-09-30 | 7.5 High |
| Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-69336 | 1 Microsoft | 20 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 17 more | 2026-09-30 | 7.1 High |
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69338 | 1 Microsoft | 14 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 11 more | 2026-09-30 | 7.1 High |
| Use after free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69355 | 1 Microsoft | 6 Exchange Server, Exchange Server 2016, Exchange Server 2019 and 3 more | 2026-09-30 | 8.8 High |
| External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-69356 | 1 Microsoft | 5 Exchange Server, Exchange Server 2016, Exchange Server 2019 and 2 more | 2026-09-30 | 9.3 Critical |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | ||||
| CVE-2026-102399 | 2026-09-30 | 5.4 Medium | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions. | ||||
| CVE-2026-102396 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions. | ||||
| CVE-2026-102395 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions. | ||||
| CVE-2026-102386 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions. | ||||
| CVE-2026-102385 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. | ||||
| CVE-2026-102384 | 2026-09-30 | 5.9 Medium | ||
| Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions. | ||||
| CVE-2026-100513 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.5 versions. | ||||
| CVE-2026-100508 | 2026-09-30 | 5.3 Medium | ||
| Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions. | ||||
| CVE-2026-100507 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions. | ||||
| CVE-2026-97289 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions. | ||||
| CVE-2026-97288 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions. | ||||