Export limit exceeded: 369599 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 369599 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (369599 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-13103 | 1 Lenovo | 1 App Store | 2026-07-22 | 7.3 High |
| A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code. | ||||
| CVE-2026-13104 | 1 Lenovo | 1 App Store | 2026-07-22 | 7.3 High |
| A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privileges. | ||||
| CVE-2026-10587 | 1 Lenovo | 57 Ideapad 5 15aba7 Bios, Ideapad Pro 5 16agp11 Bios, Ideapad Pro 5 16asp10 Bios and 54 more | 2026-07-22 | 6 Medium |
| A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode. | ||||
| CVE-2026-10588 | 1 Lenovo | 57 Ideapad 5 15aba7 Bios, Ideapad Pro 5 16agp11 Bios, Ideapad Pro 5 16asp10 Bios and 54 more | 2026-07-22 | 4.4 Medium |
| A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory. | ||||
| CVE-2026-10589 | 2026-07-22 | 6 Medium | ||
| A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode. | ||||
| CVE-2026-64797 | 2026-07-22 | N/A | ||
| IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts. | ||||
| CVE-2026-63265 | 2026-07-22 | N/A | ||
| Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted server-generated form configuration. Authenticated lower-privileged users or CSRF attacks could invoke lookups or mutations outside their authorization. | ||||
| CVE-2026-63685 | 2026-07-22 | N/A | ||
| Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend user or CSRF attack could perform database replacements, potentially causing major data corruption or site compromise. | ||||
| CVE-2026-63280 | 2026-07-22 | N/A | ||
| Conditions administration did not consistently enforce tokens and component/mapped-item permissions. | ||||
| CVE-2026-64796 | 2026-07-22 | N/A | ||
| Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection. | ||||
| CVE-2026-63683 | 2026-07-22 | N/A | ||
| IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules. | ||||
| CVE-2026-64798 | 2026-07-22 | N/A | ||
| Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy. | ||||
| CVE-2026-64795 | 2026-07-22 | N/A | ||
| Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that ran in visitors’ browsers. | ||||
| CVE-2026-64792 | 2026-07-22 | N/A | ||
| Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or administrator-only content could consequently be stored in the public search index and disclosed to visitors. | ||||
| CVE-2026-63281 | 2026-07-22 | N/A | ||
| Stored condition values could also execute HTML/JavaScript in administrator summaries. | ||||
| CVE-2026-64791 | 2026-07-22 | N/A | ||
| Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could install, update or remove extensions. | ||||
| CVE-2026-10649 | 2 Clusterlabs, Redhat | 10 Pacemaker, Enterprise Linux, Enterprise Linux Eus and 7 more | 2026-07-22 | 8.6 High |
| A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing. | ||||
| CVE-2026-63684 | 2026-07-22 | N/A | ||
| Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend users or CSRF attacks could expose, create or modify extension configuration and items. | ||||
| CVE-2026-62826 | 1 Microsoft | 3 Sharepoint Server, Sharepoint Server 2016, Sharepoint Server 2019 | 2026-07-22 | 4.6 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||||
| CVE-2025-60835 | 2026-07-22 | N/A | ||
| An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal. | ||||