Export limit exceeded: 369406 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (369406 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-15802 | 2026-07-22 | 8.1 High | ||
| The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). | ||||
| CVE-2026-60060 | 2026-07-22 | N/A | ||
| Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally. | ||||
| CVE-2026-58317 | 2026-07-22 | N/A | ||
| Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally. | ||||
| CVE-2019-25764 | 1 Asus | 1 Aura Sync | 2026-07-22 | N/A |
| **UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information. | ||||
| CVE-2026-15379 | 2026-07-22 | N/A | ||
| The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM account, bypassing filesystem ACLs. No admin privileges required. The provider reverts to the LocalSystem context when servicing WMI queries without re-impersonating the caller. Any local standard user can therefore read SYSTEM-readable files — including configuration files, service logs, and secrets stored with SYSTEM/Administrator-only ACLs — by querying the provider directly. | ||||
| CVE-2026-15380 | 2026-07-22 | N/A | ||
| A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3) | ||||
| CVE-2026-16368 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | ||||
| CVE-2026-16369 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | ||||
| CVE-2026-16383 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | ||||
| CVE-2026-16388 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16391 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | ||||
| CVE-2026-16359 | 1 Mozilla | 1 Firefox | 2026-07-22 | 9.1 Critical |
| Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | ||||
| CVE-2026-16400 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2026-16403 | 1 Mozilla | 1 Firefox | 2026-07-22 | N/A |
| Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153. | ||||
| CVE-2024-23564 | 2026-07-22 | 9.1 Critical | ||
| HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails. | ||||
| CVE-2024-23566 | 2026-07-22 | 6.5 Medium | ||
| HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force , automated attacks & account enumeration | ||||
| CVE-2024-23573 | 2026-07-22 | 3.7 Low | ||
| HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack. | ||||
| CVE-2024-23574 | 2026-07-22 | 5.3 Medium | ||
| HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system | ||||
| CVE-2024-23569 | 2026-07-22 | 4.3 Medium | ||
| HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header | ||||
| CVE-2024-23578 | 2026-07-22 | 4.2 Medium | ||
| HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard). | ||||