SEPTEMBER 5, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

35,559 records on file
Page 575 of 1,186
CVE ID Score Description
1mo ago
9.8

Memory corruption due to buffer copy without checking the size of input in modem while decoding raw SMS received.

1mo ago
9.3

Memory corruption due to double free in core while initializing the encryption key.

1mo ago
9.8

memory corruption in modem due to improper check while calculating size of serialized CoAP message

1mo ago
9.8

Memory corruption in modem due to improper input validation while handling the incoming CoAP message

1mo ago
9.8

Memory corruption in modem due to buffer overwrite while building an IPv6 multicast address based on the MAC address of the iface

1mo ago
9.8

Memory correction in modem due to buffer overwrite during coap connection

1mo ago
9.8

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

1mo ago
9

TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted files when executing a file transfer. This is due to the fact that TightVNC runs in the backend as a high-privileges account.

1mo ago
9.8

Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups().

Exploit 1mo ago
9.1

Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.

Exploit 1mo ago
9.8

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

Exploit 1mo ago
9.8

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

Exploit 1mo ago
9.8

File Upload vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the upload file type parameter.

1mo ago
9.8

A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.

Exploit 1mo ago
9.8

An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the key_wifi_safe_net_check_url, KEY_Cirus_scan_whitelist and KEY_AD_NEW_USER_AVOID_TIME parameters.

Exploit 1mo ago
9.8

An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges via the reverb and EQ preset parameters.

Exploit 1mo ago
9.8

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the parameter “Remote Operation” is enabled. The parameter is disabled by default. The vulnerability could allow an unauthenticated remote attacker to perform arbitrary code execution on the device.

KEV 1mo ago
9.8

Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.

1mo ago
9.8

An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file. After this attacker can gain access to BI user’s passwords and depending on the privileges of the BI user, the attacker can perform operations that can completely compromise the application.

Exploit 1mo ago
10

Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system.

Exploit 1mo ago
9

Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system.

Exploit 1mo ago
9.8

An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a crafted file.

Exploit 1mo ago
9.8

Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter.

1mo ago
9.8

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).

1mo ago
9.8

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).

Exploit 1mo ago
9.8

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).

1mo ago
9.8

Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.

1mo ago
9.8

Certain Lexmark devices through 2023-02-19 have an Integer Overflow.

1mo ago
9.8

Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.

1mo ago
9.8

Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.