Vulnerabilities (CVE)
Yack CVE helps teams search and track vulnerabilities.
TOTAL
388,134 CVE
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13. |
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An...Show more |
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentia...Show more |
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An...Show more |
1Entity Share Websub Project 1Entity Share Websub Sep 9, 2026 Sep 2, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2. |
Stack-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges over a network. |
Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network. |
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network. |
Missing authentication for critical function in Windows Power Dependency Coordinator allows an authorized attacker to perform tampering locally. |
Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally. |
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. |
PJSIP is a free and open source multimedia communication library written in C. Prior to commit acc03b5, a stack buffer overflow exists in PJSUA when processing Service-Route headers in a registration response (update_ser...Show more |
InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component insta...Show more |
Emlog is an open source website building system. In versions 2.6.29 and prior, article content is processed by Parsedown without enabling safe mode, which means raw HTML including <script> tags embedded in Markdown is pa...Show more |
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and label-body contexts, resulting stored XSS in form renders....Show more |
Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows servers. |
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access cou...Show more |
1Microsoft 5365 Apps Office 2016Office 2019+2 moreSep 9, 2026 Sep 8, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network. |
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. |
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. |