CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2026-75681

    Last Modified: 8 Sept 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 8 Sept 2026
    5.4
    Medium

    CVE-2026-71356

    Last Modified: 8 Sept 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 8 Sept 2026
    5.4
    Medium

    CVE-2026-75696

    Last Modified: 8 Sept 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 8 Sept 2026
    5.4
    Medium

    CVE-2026-75701

    Last Modified: 8 Sept 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 8 Sept 2026
    5.4
    Medium

    CVE-2026-75724

    Last Modified: 8 Sept 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 8 Sept 2026
    5.4
    Medium

    CVE-2025-64542

    Last Modified: 8 Sept 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 8 Sept 2026
    5.4
    Medium

    CVE-2026-75692

    Last Modified: 8 Sept 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 8 Sept 2026
    5.4
    Medium

    CVE-2026-75714

    Last Modified: 8 Sept 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 8 Sept 2026
    5.4
    Medium

    CVE-2026-75657

    Last Modified: 8 Sept 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 8 Sept 2026
    5.4
    Medium

    CVE-2025-64588

    Last Modified: 8 Sept 2026

    Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

    Published: 8 Sept 2026
    5.4
    Medium

    CVE-2026-75736

    Last Modified: 8 Sept 2026

    Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

    Published: 8 Sept 2026
    5.4
    Medium

    CVE-2026-75693

    Last Modified: 8 Sept 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 8 Sept 2026
    5.4
    Medium

    CVE-2026-75670

    Last Modified: 8 Sept 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 8 Sept 2026
    5.4
    Medium

    CVE-2026-75717

    Last Modified: 8 Sept 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 8 Sept 2026
    5.4
    Medium

    CVE-2026-79905

    Last Modified: 8 Sept 2026

    Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

    Published: 8 Sept 2026
    5.4
    Medium

    CVE-2026-75720

    Last Modified: 8 Sept 2026

    Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

    Published: 8 Sept 2026
    9.9
    Critical

    CVE-2026-86464

    Last Modified: 8 Sept 2026

    In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. The Helm chart exposed the Keycloak service and its PostgreSQL backing database through Kubernetes NodePort services by default, while the Docker Compose deployment similarly exposed PostgreSQL on all network interfaces. The deployment included fixed default credentials for the Keycloak administrator and PostgreSQL database user, and the previous Helm chart configuration did not provide adequate secret management for these credentials. In addition, predefined application users with known credentials were provided for development and testing without sufficiently warning operators against their use in production environments. An attacker able to reach the exposed services could use the published default credentials to obtain administrative access to the Identity Manager or direct access to its database. This could allow unauthorized access to or modification of identity-management data, including users, roles, client credentials, sessions, and cryptographic material, and could enable the creation of privileged identities or tokens accepted by other aeriOS components. The issue has been addressed by generating a random Keycloak administrator password by default, managing Keycloak and PostgreSQL credentials through Kubernetes Secrets, and restricting PostgreSQL to an internal service in both the Helm chart and Docker Compose deployment. OpenLDAP is also restricted to an internal service. The predefined users intended for development and testing are retained, but the documentation now explicitly warns that their default credentials must not be used in production and that these users should be removed or their credentials changed after installation.

    Published: 8 Sept 2026
    6.3
    Medium

    CVE-2026-84942

    Last Modified: 8 Sept 2026

    Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation.

    Published: 8 Sept 2026
    6.1
    Medium

    CVE-2026-76002

    Last Modified: 8 Sept 2026

    ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.

    Published: 8 Sept 2026
    9.1
    Critical

    CVE-2026-75746

    Last Modified: 8 Sept 2026

    ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-76000

    Last Modified: 8 Sept 2026

    ColdFusion is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-75998

    Last Modified: 8 Sept 2026

    ColdFusion is affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.

    Published: 8 Sept 2026
    9.9
    Critical

    CVE-2026-48273

    Last Modified: 8 Sept 2026

    ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 8 Sept 2026
    8.6
    High

    CVE-2026-76190

    Last Modified: 8 Sept 2026

    ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 8 Sept 2026
    8.4
    High

    CVE-2026-75999

    Last Modified: 8 Sept 2026

    ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 8 Sept 2026
    8.5
    High

    CVE-2026-75993

    Last Modified: 8 Sept 2026

    ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-75771

    Last Modified: 8 Sept 2026

    Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-75631

    Last Modified: 8 Sept 2026

    Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-75862

    Last Modified: 8 Sept 2026

    Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2026
    8.6
    High

    CVE-2026-76199

    Last Modified: 8 Sept 2026

    Photoshop Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-82005

    Last Modified: 8 Sept 2026

    Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-82007

    Last Modified: 8 Sept 2026

    Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-82006

    Last Modified: 8 Sept 2026

    Photoshop Desktop is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-75863

    Last Modified: 8 Sept 2026

    Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2026
    5.5
    Medium

    CVE-2026-86808

    Last Modified: 8 Sept 2026

    A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 20260819.01 is sufficient to fix this issue. The name of the patch is 3b92dd64d5648f829968cf48bf67dc3113852fef. Upgrading the affected component is advised.

    Published: 8 Sept 2026
    8.6
    High

    CVE-2026-75991

    Last Modified: 8 Sept 2026

    Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 8 Sept 2026
    8.6
    High

    CVE-2026-75990

    Last Modified: 8 Sept 2026

    Illustrator is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 8 Sept 2026
    7.8
    High

    CVE-2026-75992

    Last Modified: 8 Sept 2026

    Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Sept 2026
    9.9
    Critical

    CVE-2026-84869

    Last Modified: 8 Sept 2026

    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

    Published: 8 Sept 2026
    10
    Critical

    CVE-2026-28659

    Last Modified: 8 Sept 2026

    In MicroXR Blobstore, there is a possible way to access other app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    6.9
    Medium

    CVE-2026-86806

    Last Modified: 8 Sept 2026

    A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within_roots. This manipulation causes server-side request forgery. The attack can be initiated remotely. Upgrading to version 2.4.0 is recommended to address this issue. Patch name: b745f62e29fa37364686525a21eee5e5c0f8a369. It is recommended to upgrade the affected component.

    Published: 8 Sept 2026
    10
    Critical

    CVE-2026-49883

    Last Modified: 8 Sept 2026

    In checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 8 Sept 2026
    6.9
    Medium

    CVE-2026-86804

    Last Modified: 8 Sept 2026

    A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the function CPAResource of the file apps/manager-server/internal/http/controller/proxy/handler.go of the component HTTP Handler. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. Upgrading to version 1.11.11 is able to resolve this issue. The identifier of the patch is 842eec791377ddcbea5cd639bc065eaa4801d656. It is suggested to upgrade the affected component.

    Published: 8 Sept 2026
    10
    Critical

    CVE-2026-82004

    Last Modified: 8 Sept 2026

    Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 8 Sept 2026
    5.5
    Medium

    CVE-2026-86716

    Last Modified: 8 Sept 2026

    A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments of the file src/mjs_tok.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 8 Sept 2026
    8.5
    High

    CVE-2026-85384

    Last Modified: 8 Sept 2026

    A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution. Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.

    Published: 8 Sept 2026
    7.5
    High

    CVE-2026-66307

    Last Modified: 8 Sept 2026

    Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-66303

    Last Modified: 8 Sept 2026

    Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.

    Published: 8 Sept 2026
    8.3
    High

    CVE-2026-69646

    Last Modified: 8 Sept 2026

    Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.

    Published: 8 Sept 2026
    6.5
    Medium

    CVE-2026-69642

    Last Modified: 8 Sept 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.

    Published: 8 Sept 2026
    Items Per Page