SEPTEMBER 25, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

170,521 records on file
Page 1299 of 5,685
CVE ID Score Description
Exploit 1mo ago
6.1

Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection

Exploit 1mo ago
6.8

Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

Exploit 1mo ago
6.1

Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.

Exploit 1mo ago
6.6

TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata Revision 1.83 and advisory TCGVRT0009 for TCG standard TPM2.0

1mo ago
5.4

A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Notes' field of a calendar event. This could lead to the execution of malicious scripts when the event is viewed. Updating to version 14.2.1 or later is recommended to remediate this vulnerability.

Exploit 1mo ago
5.4

A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Survey Title' and 'Survey Instructions' fields. This vulnerability could be exploited by attackers to execute malicious scripts when the survey is accessed through its public link. It is advised to update to version 14.2.1 or later to fix this issue.

1mo ago
5.4

A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Dashboard title' and 'Dashboard content' text boxes. This can lead to the execution of malicious scripts when the dashboard is viewed. Users are recommended to update to version 14.2.1 or later to mitigate this vulnerability.

1mo ago
4.4

Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally.

1mo ago
5.5

External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.

1mo ago
6.7

Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.

1mo ago
5.4

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

Exploit 1mo ago
5.5

InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Exploit 1mo ago
5.5

InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Exploit 1mo ago
5.5

InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

1mo ago
5.1

Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally.

1mo ago
5.5

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

1mo ago
5.5

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

1mo ago
5.5

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

1mo ago
5.5

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

1mo ago
5.5

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

1mo ago
5.5

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

1mo ago
5.5

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

1mo ago
6.5

Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a network.

1mo ago
5.5

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

1mo ago
5.5

Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally.

1mo ago
5.5

Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally.

1mo ago
5.5

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

1mo ago
5.5

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

1mo ago
6.5

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Exploit 1mo ago
5.5

InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption in service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.