Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
49,803 matching · page 433/997Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-21362(opens NVD record) | High | 7.8 | Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 10, 2026 |
| CVE-2026-21333(opens NVD record) | High | 8.6 | Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 10, 2026 |
| CVE-2026-31837(opens NVD record) | High | 7.5 | Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of use of the RequestAuthentication resource. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8. | Mar 10, 2026 |
| CVE-2026-31812(opens NVD record) | Medium | 5.3 | Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In quinn-proto parsing logic, attacker-controlled varints are decoded with unwrap(), so truncated encodings cause Err(UnexpectedEnd) and panic. This is reachable over the network with a single packet and no prior trust or authentication. This vulnerability is fixed in 0.11.14. | Mar 10, 2026 |
| CVE-2026-27278(opens NVD record) | High | 7.8 | Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 10, 2026 |
| CVE-2026-27221(opens NVD record) | Medium | 5.5 | Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to spoof the identity of a signer. Exploitation of this issue requires user interaction. | Mar 10, 2026 |
| CVE-2026-27220(opens NVD record) | High | 7.8 | Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 10, 2026 |
| CVE-2026-30951(opens NVD record) | High | 7.5 | Sequelize is a Node.js ORM tool. Prior to 6.37.8, there is SQL injection via unescaped cast type in JSON/JSONB where clause processing. The _traverseJSON() function splits JSON path keys on :: to extract a cast type, which is interpolated raw into CAST(... AS <type>) SQL. An attacker who controls JSON object keys can inject arbitrary SQL and exfiltrate data from any table. This vulnerability is fixed in 6.37.8. | Mar 10, 2026 |
| CVE-2025-13213(opens NVD record) | Medium | 5.4 | IBM Aspera Orchestrator 3.0.0 through 4.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking | Mar 10, 2026 |
| CVE-2026-2713(opens NVD record) | High | 7.4 | IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code on the system, caused by DLL uncontrolled search path element vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. | Mar 10, 2026 |
| CVE-2026-26123(opens NVD record) | Medium | 5.5 | Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally. | Mar 10, 2026 |
| CVE-2026-23868(opens NVD record) | Medium | 5.1 | Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible. | Mar 10, 2026 |
| CVE-2025-36227(opens NVD record) | Medium | 5.4 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. | Mar 10, 2026 |
| CVE-2025-36226(opens NVD record) | Medium | 5.4 | IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | Mar 10, 2026 |
| CVE-2025-13219(opens NVD record) | Medium | 5.9 | IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. | Mar 10, 2026 |
| CVE-2026-28292(opens NVD record) | Critical | 9.8 | `simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912) and achieve full remote code execution on the host machine. Version 3.23.0 contains an updated fix for the vulnerability. | Mar 10, 2026 |
| CVE-2026-27279(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 10, 2026 |
| CVE-2026-27277(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 10, 2026 |
| CVE-2026-27276(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 10, 2026 |
| CVE-2026-27275(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 10, 2026 |
| CVE-2026-27274(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 10, 2026 |
| CVE-2026-27273(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 10, 2026 |
| CVE-2026-27269(opens NVD record) | High | 7.8 | Premiere Pro versions 25.5 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 10, 2026 |
| CVE-2026-3862(opens NVD record) | Medium | 4.8 | Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unaltered in the resulting web page. | Mar 10, 2026 |
| CVE-2026-3483(opens NVD record) | High | 7.8 | An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges. | Mar 10, 2026 |
| CVE-2026-3315(opens NVD record) | High | 7.8 | Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical Resource vulnerability in ASSA ABLOY Visionline on Windows allows Configuration/Environment Manipulation.This issue affects Visionline: from 1.0 before 1.33. | Mar 10, 2026 |
| CVE-2026-30897(opens NVD record) | Medium | 6.6 | A stack-based buffer overflow vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests. | Mar 10, 2026 |
| CVE-2026-26148(opens NVD record) | High | 8.1 | External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally. | Mar 10, 2026 |
| CVE-2026-26144(opens NVD record) | High | 7.5 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | Mar 10, 2026 |
| CVE-2026-26141(opens NVD record) | High | 7.8 | Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally. | Mar 10, 2026 |
| CVE-2026-26134(opens NVD record) | High | 7.8 | Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally. | Mar 10, 2026 |
| CVE-2026-26132(opens NVD record) | High | 7.8 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | Mar 10, 2026 |
| CVE-2026-26131(opens NVD record) | High | 7.8 | Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally. | Mar 10, 2026 |
| CVE-2026-26130(opens NVD record) | High | 7.5 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | Mar 10, 2026 |
| CVE-2026-26128(opens NVD record) | High | 7.8 | Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. | Mar 10, 2026 |
| CVE-2026-26127(opens NVD record) | High | 7.5 | Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network. | Mar 10, 2026 |
| CVE-2026-26121(opens NVD record) | High | 7.5 | Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network. | Mar 10, 2026 |
| CVE-2026-26118(opens NVD record) | High | 8.8 | Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network. | Mar 10, 2026 |
| CVE-2026-26117(opens NVD record) | High | 7.8 | Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. | Mar 10, 2026 |
| CVE-2026-26116(opens NVD record) | High | 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | Mar 10, 2026 |
| CVE-2026-26115(opens NVD record) | High | 8.8 | Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network. | Mar 10, 2026 |
| CVE-2026-26114(opens NVD record) | High | 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | Mar 10, 2026 |
| CVE-2026-26113(opens NVD record) | High | 8.4 | Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. | Mar 10, 2026 |
| CVE-2026-26112(opens NVD record) | High | 7.8 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Mar 10, 2026 |
| CVE-2026-26111(opens NVD record) | High | 8.0 | Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | Mar 10, 2026 |
| CVE-2026-26110(opens NVD record) | High | 8.4 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | Mar 10, 2026 |
| CVE-2026-26109(opens NVD record) | High | 8.4 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Mar 10, 2026 |
| CVE-2026-26108(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Mar 10, 2026 |
| CVE-2026-26107(opens NVD record) | High | 7.8 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Mar 10, 2026 |
| CVE-2026-26106(opens NVD record) | High | 8.8 | Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | Mar 10, 2026 |