CVE Search

IDDescriptionSeverityUpdated
CVE-2024-11803Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Tellus Lite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V8 files in the V-Simulator 5 component. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24771.
high
CVE-2026-81578An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
high
Vulnerability of Interest
CVE-2022-26905Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium
CVE-2023-21720Microsoft Edge (Chromium-based) Tampering Vulnerability
medium
CVE-2023-36559Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium
CVE-2024-30055Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium
CVE-2024-43577Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium
CVE-2024-30058Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium
CVE-2024-38093Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium
CVE-2024-26188Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium
CVE-2014-1706crosh in Google Chrome OS before 33.0.1750.152 allows attackers to inject commands via unspecified vectors.
critical
CVE-2021-30612Chromium: CVE-2021-30612 Use after free in WebRTC
high
CVE-2021-30624Chromium: CVE-2021-30624 Use after free in Autofill
high
CVE-2024-11799Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Tellus Lite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V8 files in the V-Simulator 5 component. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24664.
high
CVE-2016-9159A vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP V6 and below CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 V6 and earlier CPU family (All versions), SIMATIC S7-400 V7 CPU family (All versions), SIMATIC S7-410 V8 CPU family (All versions), SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants) (All versions). An attacker with network access to port 102/tcp (ISO-TSAP) or via Profibus could obtain credentials from the PLC if protection-level 2 is configured on the affected devices.
medium
CVE-2026-42799Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects Kestrel: before 2026/02/10.
critical
CVE-2026-40949CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to trigger a denial of service.
medium
CVE-2026-55399CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure Access tunnel can create a non-persistent DoS against the publisher.
medium
CVE-2026-61613Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint, enabling code execution within the affected Cloud Agent sandbox or session and access to files, repository contents, environment variables, credentials, and GitHub App access tokens available to that session. This issue was fixed on 03/31/2026 by requiring authentication for the relevant agent endpoint.
high
CVE-2026-43510manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another organization. Fixed in 1.176.0 on or around 2026-04-30.
medium
CVE-2026-6343Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check public/private permissions which allows members without these permissions to access public playbooks via /get.. Mattermost Advisory ID: MMSA-2026-00591
medium
CVE-2026-6345Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user password which allows a malicious attacker to impersonate a user via the use of some of those passwords.. Mattermost Advisory ID: MMSA-2026-00614
medium
CVE-2026-21388Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00610
medium
CVE-2026-22545Mattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processing account auth type switch which allows an authenticated attacker to change account password without confirmation via falsely claiming a different auth provider.. Mattermost Advisory ID: MMSA-2026-00583
low
CVE-2026-54420LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.
high
CVE-2026-40953CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can create a denial of service attack against the client over which they have control.
medium
CVE-2026-77642tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.
high
CVE-2023-36354TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR740N V1/V2, TL-WR940N V2/V3, and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlTimeSchedRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
high
CVE-2026-42600MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-45Z, A path traversal vulnerability in MinIO's ReadMultiple internode storage-REST endpoint allows a caller holding the cluster root JWT to read files from outside the configured drive roots, bounded only by the MinIO process UID. The attacker sends POST minio/storage/{drivePath}/v63/rmpl with a msgpack-encoded body carrying ../ sequences in the Bucket field. The server opens the resulting path via os.OpenFile with O_RDONLY|O_NOATIME and returns its contents in the msgpack response stream. This vulnerability is fixed in RELEASE.2026-04-14T21-32-45Z.
medium
CVE-2021-30617Chromium: CVE-2021-30617 Policy bypass in Blink
medium
CVE-2022-23263Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2022-26899Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2022-26909Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2022-35796Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2023-33143Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2024-21385Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2024-21388Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
medium
CVE-2024-21399Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
high
CVE-2023-36022Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
medium
CVE-2023-36034Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
high
CVE-2023-28286Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
medium
CVE-2024-43472Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2024-43489Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
high
CVE-2024-43587Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
high
CVE-2024-43596Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
high
CVE-2024-43595Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
high
CVE-2026-45495Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
critical
CVE-2021-31937Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2021-36928Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2016-5179Chrome OS before 53.0.2785.144 allows remote attackers to execute arbitrary commands at boot.
critical