Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-48283

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
ColdFusion
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48282

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHEDCISA KEV
Vendor
Adobe
Product
ColdFusion
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48281

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
ColdFusion
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48280

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4828

Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multi-factor authentication via a crafted login request.

PUBLISHED
Vendor
Devolutions
Product
Server
Provider severity
HIGH
Conflicts
0

CVE-2026-48277

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
ColdFusion
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48276

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
ColdFusion
Provider severity
CRITICAL
Conflicts
0

CVE-2026-48275

Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe
Product
Illustrator Desktop 2026, Illustrator Desktop 2025
Provider severity
HIGH
Conflicts
1

CVE-2026-48274

After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
After Effects, After Effects
Provider severity
HIGH
Conflicts
1

CVE-2026-48272

Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Creative Cloud Desktop
Provider severity
HIGH
Conflicts
0

CVE-2026-48271

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48270

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
Premiere, Premiere
Provider severity
HIGH
Conflicts
1

CVE-2026-4827

CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑management protections.

PUBLISHED
Vendor
Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric
Product
EcoStruxure™ Power Operation, Saitel DP, Easergy MiCOM C264, EcoStruxure™ Power Automation System Gateway (EPAS-GTW), EcoStruxure™ Power Automation System User Interface (EPAS-UI), PowerLogic™ T500, Easergy MiCOM P30, PowerLogic™ P5 Protection Relay, Easergy C5, iPMFLS, EasyLogic T150 (formerly Saitel DR), PowerLogic™ P7 Protection and Control Platform, PowerLogic™ T300, Easergy MiCOM P40
Provider severity
HIGH
Conflicts
1

CVE-2026-48269

Premiere Pro is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe, Adobe
Product
Premiere, Premiere
Provider severity
HIGH
Conflicts
1

CVE-2026-48268

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48267

DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

PUBLISHED
Vendor
Adobe
Product
DNG SDK
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48266

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48265

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48264

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48263

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Adobe Experience Manager 6.5 LTS, Adobe Experience Manager as a Cloud Service, Adobe Experience Manager 6.5
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48262

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Adobe Experience Manager 6.5, Adobe Experience Manager as a Cloud Service, Adobe Experience Manager 6.5 LTS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48261

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Adobe Experience Manager 6.5 LTS, Adobe Experience Manager as a Cloud Service, Adobe Experience Manager 6.5
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48260

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Adobe Experience Manager 6.5 LTS, Adobe Experience Manager 6.5, Adobe Experience Manager as a Cloud Service
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4826

A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /update_stock.php of the component HTTP GET Parameter Handler. This manipulation of the argument sid causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
SourceCodester
Product
Sales and Inventory System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-48259

Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side requests, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Adobe Experience Manager 6.5 LTS, Adobe Experience Manager as a Cloud Service, Adobe Experience Manager 6.5
Provider severity
CRITICAL
Conflicts
1

CVE-2026-48258

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48257

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Adobe Experience Manager as a Cloud Service, Adobe Experience Manager 6.5 LTS, Adobe Experience Manager 6.5
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48256

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48255

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Adobe Experience Manager 6.5, Adobe Experience Manager as a Cloud Service, Adobe Experience Manager 6.5 LTS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48254

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, Adobe Experience Manager as a Cloud Service
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48253

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, Adobe Experience Manager as a Cloud Service
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48252

Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.

PUBLISHED
Vendor
Adobe, Adobe, Adobe
Product
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, Adobe Experience Manager as a Cloud Service
Provider severity
HIGH
Conflicts
1

CVE-2026-48251

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-48250

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4825

A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file /update_sales.php of the component HTTP GET Parameter Handler. The manipulation of the argument sid results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
SourceCodester
Product
Sales and Inventory System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-48249

Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs/mobile_login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests issued during the mobile (RouteMate) login flow. An attacker positioned on the network path between the server and the remote endpoint can present a forged certificate to intercept, monitor, or modify the request and response, including any API keys or session-bearing data in

PUBLISHED
Vendor
Open ISES
Product
Tickets
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-48248

Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests issued during the login/authentication flow. An attacker positioned on the network path between the server and the remote endpoint can present a forged certificate to intercept, monitor, or modify the request and response, including any API keys or session-bearing data in transit.

PUBLISHED
Vendor
Open ISES
Product
Tickets
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-48247

Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/functions.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for general-purpose outbound HTTPS requests issued by the shared helper functions. An attacker positioned on the network path between the server and the remote endpoint can present a forged certificate to intercept, monitor, or modify the request and response, including any API keys

PUBLISHED
Vendor
Open ISES
Product
Tickets
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-48246

Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for Google Maps Directions API lookups during incident report generation. An attacker positioned on the network path between the server and the remote endpoint can present a forged certificate to intercept, monitor, or modify the request and response, including any API keys or session-bea

PUBLISHED
Vendor
Open ISES
Product
Tickets
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-48245

Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in tables.php that is committed to the public source repository. The key can be extracted by anyone with read access to the source and used to make Google Maps Platform requests billed against the original owner's Google Cloud project.

PUBLISHED
Vendor
Open ISES
Product
Tickets
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48244

Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is committed to the public source repository. The key can be extracted by anyone with read access to the source and used to make Google Maps Platform requests billed against the original owner's Google Cloud project.

PUBLISHED
Vendor
Open ISES
Product
Tickets
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48243

Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php that is committed to the public source repository. Any actor with read access to the source tree can extract the key and use it to make third-party API calls billed to or rate-limited against the original owner's WhitePages account.

PUBLISHED
Vendor
Open ISES
Product
Tickets
Provider severity
MEDIUM
Conflicts
1

CVE-2026-48242

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, database name) in import_mdb.php. The credentials are embedded in source code committed to the public repository, allowing any reader of the source to obtain valid configuration values that may match deployed installations.

PUBLISHED
Vendor
Open ISES
Product
Tickets
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-48241

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to the source repository. Any actor with access to the public source tree (or an unauthenticated attacker with read access to the file on a deployed installation) can read the username, password, and database name and use them to connect to the database if it is reachable from their network.

PUBLISHED
Vendor
Open ISES
Product
Tickets
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-48240

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/statistics.php where the tick_id and f_tick_id POST parameters are concatenated into WHERE clauses of SELECT statements in the statistics rollup queries without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents.

PUBLISHED
Vendor
Open ISES
Product
Tickets
Provider severity
HIGH
Conflicts
1

CVE-2026-4824

A vulnerability has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this issue is some unknown functionality of the component Backup Job Configuration File Handler. The manipulation leads to improper privilege management. The attack must be carried out locally. The attack is considered to have high complexity. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 8.7.4 can resolve this issue. It is advis

PUBLISHED
Vendor
Enter Software
Product
Iperius Backup
Provider severity
HIGH
Conflicts
2

CVE-2026-48239

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/reports.php where the tick_id POST parameter is concatenated into the WHERE clause of SELECT statements in the incidents summary report without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents.

PUBLISHED
Vendor
Open ISES
Product
Tickets
Provider severity
HIGH
Conflicts
1

CVE-2026-48238

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/mobile_main.php where the id GET parameter is concatenated into the WHERE clause of a SELECT statement used as a ticket-existence sanity check without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents.

PUBLISHED
Vendor
Open ISES
Product
Tickets
Provider severity
HIGH
Conflicts
1

CVE-2026-48237

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in message.php where the frm_ticket_id and frm_resp_id POST parameters are concatenated into WHERE clauses of SELECT/UPDATE statements without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents.

PUBLISHED
Vendor
Open ISES
Product
Tickets
Provider severity
HIGH
Conflicts
1

CVE-2026-48236

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in db_loader.php where the multiple POST parameters (ticketsdb, ticketshost, ticketsuser, ticketspassword) are concatenated into mysqli connection arguments and dynamic SQL operating against an attacker-controlled database without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents.

PUBLISHED
Vendor
Open ISES
Product
Tickets
Provider severity
HIGH
Conflicts
1