Export limit exceeded: 27627 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (27627 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-105791 | 1 Microsoft | 1 Ufo | 2026-10-09 | 7.5 High |
| Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the run_shell tool in the CommandLineExecutor component of ufo/client/mcp/local_servers/cli_mcp_server.py validates only the first token of the bash_command parameter and permits explorer.exe. On Windows, explorer.exe delegates its following path argument to ShellExecute, so an attacker-influenced agent call can launch an arbitrary executable or script as the desktop user even though the subprocess uses shell=False. Exploitation depends on a user running an affected agent workflow and on inducing the tool call, but successful execution can access or modify that user's files, tokens, and sessions. This issue is fixed in version 3.0.9. | ||||
| CVE-2026-83943 | 1 Microsoft | 1 Azure Api Center | 2026-10-08 | 8.7 High |
| Exposure of sensitive information to an unauthorized actor in Azure API Center allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2017-8529 | 1 Microsoft | 9 Edge, Internet Explorer, Windows 10 and 6 more | 2026-10-08 | 6.5 Medium |
| Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to detect specific files on the user's computer when affected Microsoft scripting engines do not properly handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability". | ||||
| CVE-2026-96207 | 1 Microsoft | 1 Partner Center | 2026-10-08 | 10 Critical |
| Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-94510 | 1 Microsoft | 1 Bookings | 2026-10-08 | 9.9 Critical |
| Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-88131 | 1 Microsoft | 1 Dataverse | 2026-10-08 | 9.8 Critical |
| Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-83947 | 1 Microsoft | 1 Azure Event Grid System | 2026-10-08 | 7.7 High |
| Missing authorization in Azure Event Grid allows an authorized attacker to perform spoofing over a network. | ||||
| CVE-2026-77900 | 1 Microsoft | 1 Azure App Service | 2026-10-08 | 9.8 Critical |
| Missing authentication for critical function in Azure App Service allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69435 | 1 Microsoft | 1 Azure Sre Agent | 2026-10-08 | 9.6 Critical |
| Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-96940 | 1 Microsoft | 7 Exchange Server 2016, Exchange Server 2019, Exchange Server Se and 4 more | 2026-10-08 | 8.8 High |
| An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests. An attacker who successfully exploited this vulnerability could perform script/content injection attacks and attempt to trick the user into disclosing sensitive information. To exploit the vulnerability, an attacker could send a specially crafted email message containing a malicious link to a user. Alternatively, an attacker could use a chat client to social engineer a user into clicking the malicious link. The security update addresses the vulnerability by correcting how Microsoft Exchange validates web requests. Note: In order to exploit this vulnerability, a user must click a maliciously crafted link from an attacker. | ||||
| CVE-2023-32028 | 1 Microsoft | 7 Ole Db Driver 18 For Sql Server, Ole Db Driver 19 For Sql Server, Ole Db Driver For Sql Server and 4 more | 2026-10-08 | 7.8 High |
| Microsoft SQL OLE DB Remote Code Execution Vulnerability | ||||
| CVE-2022-26488 | 3 Microsoft, Netapp, Python | 4 Windows, Active Iq Unified Manager, Ontap Select Deploy Administration Utility and 1 more | 2026-10-08 | 7.0 High |
| In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local attacker to add user-writable directories to the system search path. To exploit, an administrator must have installed Python for all users and enabled PATH entries. A non-administrative user can trigger a repair that incorrectly adds user-writable paths into PATH, enabling search-path hijacking of other users and system services. This affects Python (CPython) through 3.7.12, 3.8.x through 3.8.12, 3.9.x through 3.9.10, and 3.10.x through 3.10.2. | ||||
| CVE-2020-15523 | 3 Microsoft, Netapp, Python | 3 Windows, Snapcenter, Python | 2026-10-08 | 7.8 High |
| In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs because python3X.dll may use an invalid search path for python3.dll loading (after Py_SetPath has been used). NOTE: this issue CANNOT occur when using python.exe from a standard (non-embedded) Python installation on Windows. | ||||
| CVE-2019-14566 | 3 Intel, Linux, Microsoft | 3 Software Guard Extensions Sdk, Linux Kernel, Windows | 2026-10-08 | 7.8 High |
| Insufficient input validation in Intel(R) SGX SDK multiple Linux and Windows versions may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service via local access. | ||||
| CVE-2019-14565 | 3 Intel, Linux, Microsoft | 3 Software Guard Extensions Sdk, Linux Kernel, Windows | 2026-10-08 | 7.8 High |
| Insufficient initialization in Intel(R) SGX SDK Windows versions 2.4.100.51291 and earlier, and Linux versions 2.6.100.51363 and earlier, may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service via local access. | ||||
| CVE-2026-106284 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-10-08 | 4.7 Medium |
| Out of bounds read in Printing in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106258 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-10-08 | 4.7 Medium |
| Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-106272 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-10-08 | 5.4 Medium |
| UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via crafted network traffic. (Chromium security severity: Low) | ||||
| CVE-2026-91803 | 3 Foxit, Foxitsoftware, Microsoft | 5 Pdf Editor, Pdf Reader, Foxit Pdf Editor and 2 more | 2026-10-08 | 8.8 High |
| A local privilege escalation vulnerability exists in the updater of Foxit PDF Editor/Reader due to unsafe loading of dynamic-link libraries from a user-writable directory during high-privilege operations. A local attacker could exploit this issue to execute code with elevated privileges. | ||||
| CVE-2026-91809 | 3 Foxit, Foxitsoftware, Microsoft | 5 Pdf Editor, Pdf Reader, Foxit Pdf Editor and 2 more | 2026-10-08 | 7.8 High |
| A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access a released object, resulting in an application crash. | ||||