Tue, Nov 14 · 05:15 AM CSTCVE-2023-43902
9.8/10 · Must read/watchNVDvuln
Summary
Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.
CVECVE-2023-43902
SeverityCRITICAL
TypeUPDATED
PublishedTue, Nov 14 · 05:15 AM CST
ModifiedFri, Aug 28 · 08:16 AM CDT
Tue, Nov 21 · 10:15 PM CSTCVE-2023-49105
9.8/10 · Must read/watchNVDvuln
Summary
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for t
CVECVE-2023-49105
SeverityCRITICAL
TypeUPDATED
PublishedTue, Nov 21 · 10:15 PM CST
ModifiedFri, Aug 28 · 05:16 AM CDT
Tue, Oct 28 · 12:15 PM CDTCVE-2025-40074
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: ipv4: start using dst_dev_rcu() Change icmpv4_xrlim_allow(), ip_defrag() to prevent possible UAF. Change ipmr_prepare_xmit(), ipmr_queue_fwd_xmit(), ip_mr_output(), ipv4_neigh_lookup() to use lockdep enabled dst_dev_rcu().
CVECVE-2025-40074
SeverityCRITICAL
TypeUPDATED
PublishedTue, Oct 28 · 12:15 PM CDT
ModifiedThu, Aug 27 · 01:16 PM CDT
Tue, Jan 13 · 04:16 PM CSTCVE-2025-68794
9.8/10 · Must read/watchNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: iomap: adjust read range correctly for non-block-aligned positions iomap_adjust_read_range() assumes that the position and length passed in are block-aligned. This is not always the case however, as shown in the syzbot generated case for erofs. This ca
CVECVE-2025-68794
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jan 13 · 04:16 PM CST
ModifiedThu, Aug 27 · 01:16 PM CDT
Tue, Jan 13 · 07:16 PM CSTCVE-2026-21267
8.6/10 · Worth your timeNVDvuln
Summary
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue requires user interaction in that a victim must open a maliciou
CVECVE-2026-21267
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 07:16 PM CST
ModifiedFri, Aug 28 · 12:16 AM CDT
Tue, Jan 13 · 07:16 PM CSTCVE-2026-21268
8.6/10 · Worth your timeNVDvuln
Summary
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file and scope is changed.
CVECVE-2026-21268
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 07:16 PM CST
ModifiedFri, Aug 28 · 12:16 AM CDT
Tue, Jan 13 · 07:16 PM CSTCVE-2026-21271
8.6/10 · Worth your timeNVDvuln
Summary
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file and scope is changed.
CVECVE-2026-21271
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 07:16 PM CST
ModifiedFri, Aug 28 · 12:16 AM CDT
Tue, Jan 13 · 07:16 PM CSTCVE-2026-21272
8.6/10 · Worth your timeNVDvuln
Summary
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker could leverage this vulnerability to manipulate or inject malicious data into files on the system. Exploitation of this issue requires user interaction in
CVECVE-2026-21272
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 07:16 PM CST
ModifiedFri, Aug 28 · 12:16 AM CDT
Tue, Jan 13 · 07:16 PM CSTCVE-2026-21280
8.6/10 · Worth your timeNVDvuln
Summary
Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses a search path to locate critical resources such as programs, an attacker could modify that search path to point t
CVECVE-2026-21280
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 07:16 PM CST
ModifiedFri, Aug 28 · 12:16 AM CDT
Tue, Mar 10 · 11:16 PM CDTCVE-2026-21333
8.6/10 · Worth your timeNVDvuln
Summary
Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVECVE-2026-21333
SeverityHIGH
TypeUPDATED
PublishedTue, Mar 10 · 11:16 PM CDT
ModifiedFri, Aug 28 · 12:16 AM CDT
Sun, Jun 25 · 10:15 PM CDTCVE-2023-36664
7.8/10 · Worth your timeNVDvuln
Summary
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
CVECVE-2023-36664
SeverityHIGH
TypeUPDATED
PublishedSun, Jun 25 · 10:15 PM CDT
ModifiedThu, Aug 27 · 06:52 PM CDT
Wed, Sep 18 · 08:15 AM CDTCVE-2024-46741
7.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix double free of 'buf' in error path smatch warning: drivers/misc/fastrpc.c:1926 fastrpc_req_mmap() error: double free of 'buf' In fastrpc_req_mmap() error path, the fastrpc buffer is freed in fastrpc_req_munmap_impl() if unmap is succ
CVECVE-2024-46741
SeverityHIGH
TypeUPDATED
PublishedWed, Sep 18 · 08:15 AM CDT
ModifiedThu, Aug 27 · 01:16 PM CDT
Fri, Aug 22 · 02:15 PM CDTCVE-2025-38616
7.8/10 · Worth your timeNVDvuln
Summary
In the Linux kernel, the following vulnerability has been resolved: tls: handle data disappearing from under the TLS ULP TLS expects that it owns the receive queue of the TCP socket. This cannot be guaranteed in case the reader of the TCP socket entered before the TLS ULP was installed, or uses some non-standard read A
CVECVE-2025-38616
SeverityHIGH
TypeUPDATED
PublishedFri, Aug 22 · 02:15 PM CDT
ModifiedThu, Aug 27 · 01:16 PM CDT
Tue, Jan 13 · 07:16 PM CSTCVE-2026-21274
7.8/10 · Worth your timeNVDvuln
Summary
Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could leverage this vulnerability to bypass security measures and execute unauthorized code. Exploitation of this issue req
CVECVE-2026-21274
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 07:16 PM CST
ModifiedFri, Aug 28 · 12:16 AM CDT
Tue, Jan 13 · 07:16 PM CSTCVE-2026-21275
7.8/10 · Worth your timeNVDvuln
Summary
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVECVE-2026-21275
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 07:16 PM CST
ModifiedFri, Aug 28 · 12:16 AM CDT
Tue, Jan 13 · 07:16 PM CSTCVE-2026-21276
7.8/10 · Worth your timeNVDvuln
Summary
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVECVE-2026-21276
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 07:16 PM CST
ModifiedFri, Aug 28 · 12:16 AM CDT
Tue, Jan 13 · 07:16 PM CSTCVE-2026-21277
7.8/10 · Worth your timeNVDvuln
Summary
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVECVE-2026-21277
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 07:16 PM CST
ModifiedFri, Aug 28 · 12:16 AM CDT
Tue, Jan 13 · 07:16 PM CSTCVE-2026-21281
7.8/10 · Worth your timeNVDvuln
Summary
InCopy versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVECVE-2026-21281
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 07:16 PM CST
ModifiedFri, Aug 28 · 12:16 AM CDT
Tue, Jan 13 · 07:16 PM CSTCVE-2026-21283
7.8/10 · Worth your timeNVDvuln
Summary
Bridge versions 15.1.2, 16.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVECVE-2026-21283
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 07:16 PM CST
ModifiedFri, Aug 28 · 12:16 AM CDT
Tue, Jan 13 · 08:16 PM CSTCVE-2026-21287
7.8/10 · Worth your timeNVDvuln
Summary
Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVECVE-2026-21287
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 08:16 PM CST
ModifiedFri, Aug 28 · 12:16 AM CDT
Tue, Jan 13 · 09:15 PM CSTCVE-2026-21298
7.8/10 · Worth your timeNVDvuln
Summary
Substance3D - Modeler versions 1.22.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVECVE-2026-21298
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 09:15 PM CST
ModifiedFri, Aug 28 · 12:16 AM CDT
Tue, Jan 13 · 09:15 PM CSTCVE-2026-21299
7.8/10 · Worth your timeNVDvuln
Summary
Substance3D - Modeler versions 1.22.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVECVE-2026-21299
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 09:15 PM CST
ModifiedFri, Aug 28 · 12:16 AM CDT
Tue, Jan 13 · 07:16 PM CSTCVE-2026-21304
7.8/10 · Worth your timeNVDvuln
Summary
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVECVE-2026-21304
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 07:16 PM CST
ModifiedFri, Aug 28 · 12:16 AM CDT
Tue, Jan 13 · 08:16 PM CSTCVE-2026-21305
7.8/10 · Worth your timeNVDvuln
Summary
Substance3D - Painter versions 11.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVECVE-2026-21305
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 08:16 PM CST
ModifiedFri, Aug 28 · 12:16 AM CDT
Tue, Jan 13 · 08:16 PM CSTCVE-2026-21306
7.8/10 · Worth your timeNVDvuln
Summary
Substance3D - Sampler versions 5.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVECVE-2026-21306
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 13 · 08:16 PM CST
ModifiedFri, Aug 28 · 12:16 AM CDT