Filter public vulnerability entries by severity / channel / vendor / time.
CVE-2026-41940 · 2026-09-02 · pending_review
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control …
CVE-2024-9680 · 2026-09-02 · pending_review
Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.
CVE-2024-21413 · 2026-09-02 · pending_review
Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and o…
CVE-2023-7101 · 2026-09-02 · pending_review
Spreadsheet::ParseExcel contains a remote code execution vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings wi…
CVE-2023-45249 · 2026-09-02 · pending_review
Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.
CVE-2022-47966 · 2026-09-03 · pending_review
Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.
CVE-2022-26486 · 2026-09-04 · pending_review
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.
CVE-2020-8467 · 2026-09-04 · pending_review
Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution.
CVE-2020-25213 · 2026-09-04 · pending_review
WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.
CVE-2019-9978 · 2026-09-04 · pending_review
WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.
CVE-2019-18187 · 2026-09-04 · pending_review
Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution.
CVE-2019-1297 · 2026-09-04 · pending_review
A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory.
CVE-2019-11708 · 2026-09-03 · pending_review
Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.
CVE-2018-4990 · 2026-09-03 · pending_review
Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.
CVE-2018-0802 · 2026-09-04 · pending_review
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is…
CVE-2018-0798 · 2026-09-04 · pending_review
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is…
CVE-2017-8570 · 2026-09-04 · pending_review
A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.
CVE-2017-11882 · 2026-09-04 · pending_review
Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.
CVE-2017-11826 · 2026-09-04 · pending_review
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in…
CVE-2017-0262 · 2026-09-04 · pending_review
A remote code execution vulnerability exists in Microsoft Office.
CVE-2017-0261 · 2026-09-04 · pending_review
Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution.
CVE-2017-0199 · 2026-09-04 · pending_review
Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.
CVE-2016-7193 · 2026-09-04 · pending_review
Microsoft Office contains a memory corruption vulnerability which can allow for remote code execution.
CVE-2016-3235 · 2026-09-04 · pending_review
Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote…
CVE-2015-1641 · 2026-09-04 · pending_review
Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user.
CVE-2014-1761 · 2026-09-04 · pending_review
Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution.
CVE-2013-0640 · 2026-09-04 · pending_review
An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution.
CVE-2012-2539 · 2026-09-03 · pending_review
Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.
CVE-2012-1856 · 2026-09-04 · pending_review
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.
CVE-2010-3333 · 2026-09-04 · pending_review
A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution.
CVE-2010-2572 · 2026-09-03 · pending_review
Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution.
CVE-2009-3953 · 2026-09-03 · pending_review
Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution.
CVE-2009-0556 · 2026-09-02 · pending_review
Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index value that triggers …
CVE-2009-0238 · 2026-09-02 · pending_review
Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed o…
CVE-2008-2992 · 2026-09-04 · pending_review
Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.
CVE-2007-0671 · 2026-09-02 · pending_review
Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a mali…
CVE-2026-74986 · 2026-08-25 · auto
Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
CVE-2026-4408 · 2026-08-25 · auto
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u subs…
CVE-2026-21660 · 2026-08-24 · auto
A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitiv…
CVE-2026-74989 · 2026-08-24 · auto
Internally found bugs present in Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. Th…
CVE-2026-74987 · 2026-08-24 · auto
Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort s…
CVE-2026-78207 · 2026-08-24 · auto
exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSO…
CVE-2026-4703 · 2026-08-22 · auto
The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission met…
CVE-2026-78003 · 2026-08-22 · auto
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() …
CVE-2026-77002 · 2026-08-23 · auto
The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, inc…
CVE-2026-77001 · 2026-08-23 · auto
The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing u…
CVE-2026-77000 · 2026-08-23 · auto
The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in…
CVE-2026-74959 · 2026-08-24 · auto
Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
CVE-2026-53548 · 2026-08-21 · auto
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:id/password endpoint in src/backend/database/routes/host.ts accepts an …
CVE-2026-18315 · 2026-08-21 · auto
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including, 1.2.6. Th…