Total
3151 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-78442 | 2026-09-09 | N/A | 8.8 HIGH | ||
| Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69764 | 1 Microsoft | 6 365 Apps, Office 2016, Office 2019 and 3 more | 2026-09-09 | N/A | 8.8 HIGH |
| Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69758 | 2026-09-09 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69732 | 2026-09-09 | N/A | 8.1 HIGH | ||
| Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69522 | 2026-09-09 | N/A | 8.8 HIGH | ||
| Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69513 | 2026-09-09 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69491 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69371 | 2026-09-09 | N/A | 8.0 HIGH | ||
| Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-69359 | 2026-09-09 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69348 | 2026-09-09 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-20502 | 1 Mediatek | 106 Mt2718, Mt2718 Firmware, Mt6580 and 103 more | 2026-09-09 | N/A | 8.4 HIGH |
| In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196. | |||||
| CVE-2026-20501 | 1 Mediatek | 106 Mt2718, Mt2718 Firmware, Mt6580 and 103 more | 2026-09-09 | N/A | 8.4 HIGH |
| In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197. | |||||
| CVE-2026-55294 | 2026-09-08 | N/A | 7.8 HIGH | ||
| In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-49932 | 2026-09-08 | N/A | 7.8 HIGH | ||
| In parseParts of PduParser.java, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-54715 | 2026-09-08 | N/A | N/A | ||
| GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a trailing version substring to match plus five, allowing a crafted User-Agent in a processed access log to write one to four attacker-influenced bytes beyond the heap allocation and corrupt or crash GoAccess. This issue is fixed in version 1.11. | |||||
| CVE-2026-86716 | 2026-09-08 | 7.5 HIGH | 7.3 HIGH | ||
| A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments of the file src/mjs_tok.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-72985 | 2026-09-08 | N/A | 6.8 MEDIUM | ||
| Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack. | |||||
| CVE-2026-69541 | 2026-09-08 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69432 | 2026-09-08 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69325 | 2026-09-08 | N/A | 8.1 HIGH | ||
| Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network. | |||||
