Export limit exceeded: 375984 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (375984 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-58231 1 Sap Se 2 Sap Commerce Cloud Data Hub Adapter, Sap Commerce Cloud Data Hub Adapter 2026-08-11 10 Critical
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.
CVE-2026-72919 1 Rocketchat 1 Rocket.chat 2026-08-11 4.3 Medium
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the channels.convertToTeam REST endpoint allows an authenticated registered user with the create-team permission to convert an unrelated public channel by supplying channelName instead of channelId because the edit-room permission is checked only for channelId. This issue is fixed in versions 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1.
CVE-2026-13133 1 Ly Corporation 1 Line For Windows 2026-08-11 N/A
A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate System32 copy.
CVE-2026-12570 1 Keras-team 1 Keras 2026-08-11 5.0 Medium
A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving/saving_lib.py does not validate the shape or size of datasets, leading to unbounded memory allocation. A specially crafted .keras file can exploit this flaw to trigger an out-of-memory (OOM) condition, causing the process to be terminated (exit code 137). This issue bypasses the fix for CVE-2026-0897, which only addressed a similar vulnerability in KerasFileEditor. The attack vector includes poisoned models from public repositories or malicious model registries, posing a risk to machine learning pipelines that process untrusted models.
CVE-2026-64940 1 Nishishi Factory 1 Tegalog -fumy Otegaru Memo Logger- 2026-08-11 8.6 High
Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from the management console.
CVE-2026-21075 1 Samsung Mobile 1 My Galaxy 2026-08-11 N/A
Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.
CVE-2026-21081 1 Samsung Mobile 1 Samsungpassautofill 2026-08-11 N/A
Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
CVE-2026-66403 1 Ecovacs Robotics 2 Deebot Pro K1vac, Deebot Pro M1 2026-08-11 7.5 High
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.
CVE-2026-66404 1 Ecovacs Robotics 2 Deebot Pro K1vac, Deebot Pro M1 2026-08-11 6.5 Medium
DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affected products may be retrieved.
CVE-2026-66405 1 Ecovacs Robotics 2 Deebot Pro K1vac, Deebot Pro M1 2026-08-11 8.8 High
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.
CVE-2026-66406 1 Ecovacs Robotics 2 Deebot Pro K1vac, Deebot Pro M1 2026-08-11 4.8 Medium
DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be executed with the administrative privilege.
CVE-2026-66407 1 Ecovacs Robotics 2 Deebot Pro K1vac, Deebot Pro M1 2026-08-11 8.1 High
DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.
CVE-2026-66408 1 Ecovacs Robotics 2 Deebot Pro K1vac, Deebot Pro M1 2026-08-11 4.6 Medium
The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affected product may allow to obtain the password of the root account.
CVE-2026-66409 1 Ecovacs Robotics 2 Deebot Pro K1vac, Deebot Pro M1 2026-08-11 5.3 Medium
DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to connect to the access point of an affected robot.
CVE-2026-66410 1 Ecovacs Robotics 2 Android App "ecovacs Pro", Ios App "ecovacs Pro" 2026-08-11 4.8 Medium
Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or altered.
CVE-2026-66411 1 Ecovacs Robotics 2 Deebot Pro K1vac, Deebot Pro M1 2026-08-11 5.3 Medium
DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unauthenticated attacker may connect and operate the affected robot.
CVE-2026-19404 1 Redhat 3 Directory Server, Enterprise Linux, Redhat Directory Server 2026-08-11 6.5 Medium
A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to invoke them otherwise. This allows removal of a replica ID from replication metadata, purging of changelog records, and interruption of administrator-initiated cleanup, which can leave replication inconsistent or unavailable.
CVE-2026-66915 1 Fabrikar.com 1 Fabrik Extension For Joomla 2026-08-11 N/A
Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.7 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.
CVE-2026-66642 2 Wordpress, Wp Umbrella 2 Wordpress, Wp Umbrella 2026-08-11 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP Umbrella: from 2.24.2 through 2.26.2.
CVE-2026-65948 1 Apache 1 Ranger 2026-08-11 7.3 High
UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option for production deployments.  Users are recommended to upgrade to version 2.9.0, which fixes this issue.