Vulnerabilities (CVE)

Total 398522 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-33327 1 Libvips 1 Libvips 2026-08-19 N/A 7.8 HIGH
libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.
CVE-2021-26858 1 Microsoft 1 Exchange Server 2026-08-19 6.8 MEDIUM 7.8 HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-42321 1 Microsoft 1 Exchange Server 2026-08-19 6.5 MEDIUM 8.8 HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-42292 1 Microsoft 6 365 Apps, Excel, Office and 3 more 2026-08-19 6.8 MEDIUM 7.8 HIGH
Microsoft Excel Security Feature Bypass Vulnerability
CVE-2021-42287 1 Microsoft 7 Windows Server 2004, Windows Server 2008, Windows Server 2012 and 4 more 2026-08-19 6.5 MEDIUM 7.5 HIGH
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42278 1 Microsoft 7 Windows Server 2004, Windows Server 2008, Windows Server 2012 and 4 more 2026-08-19 6.5 MEDIUM 7.5 HIGH
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-41379 1 Microsoft 18 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 15 more 2026-08-19 4.6 MEDIUM 5.5 MEDIUM
Windows Installer Elevation of Privilege Vulnerability
CVE-2021-27085 1 Microsoft 7 Internet Explorer, Windows 10 1803, Windows 10 1809 and 4 more 2026-08-19 7.6 HIGH 8.8 HIGH
Internet Explorer Remote Code Execution Vulnerability
CVE-2021-27065 1 Microsoft 1 Exchange Server 2026-08-19 6.8 MEDIUM 7.8 HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-27059 1 Microsoft 2 Office, Office 2016 2026-08-19 8.5 HIGH 7.6 HIGH
Microsoft Office Remote Code Execution Vulnerability
CVE-2021-26857 1 Microsoft 1 Exchange Server 2026-08-19 6.8 MEDIUM 7.8 HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26855 1 Microsoft 1 Exchange Server 2026-08-19 7.5 HIGH 9.1 CRITICAL
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26411 1 Microsoft 17 Edge, Internet Explorer, Windows 10 1507 and 14 more 2026-08-19 5.1 MEDIUM 8.8 HIGH
Internet Explorer Memory Corruption Vulnerability
CVE-2020-1054 1 Microsoft 17 Windows 10 1507, Windows 10 1607, Windows 10 1709 and 14 more 2026-08-19 7.2 HIGH 7.0 HIGH
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory.
CVE-2020-25576 1 Rust-random 1 Rand 2026-08-19 7.5 HIGH 9.8 CRITICAL
An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints.
CVE-2026-33328 1 Libvips 1 Libvips 2026-08-19 N/A 5.5 MEDIUM
libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.18.0, the `gifload` operation could incorrectly determine dimensions leading to an integer overflow. This has been patched in version 8.18.1.
CVE-2026-34118 1 Tp-link 2 Tapo C520ws, Tapo C520ws Firmware 2026-08-19 N/A 6.5 MEDIUM
A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST body parsing logic due to missing validation of remaining buffer capacity after dynamic allocation, due to insufficient boundary validation when handling externally supplied HTTP input.   An attacker on the same network segment could trigger heap memory corruption conditions by sending crafted payloads that cause write operations beyond allocated buffer boundaries.  Successful exploitation causes a Denial-of-Service (DoS) condition, causing the device’s process to crash or become unresponsive.
CVE-2026-21727 1 Grafana 1 Grafana 2026-08-19 N/A 3.3 LOW
A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could read and permanently delete legacy correlation data belonging to another organization. This issue affects correlations created prior to Grafana 10.2 and is fixed in >=11.6.11, >=12.0.9, >=12.1.6, and >=12.2.4. Thanks to Gyu-hyeok Lee (g2h) for reporting this vulnerability.
CVE-2026-35590 1 Libvips 1 Libvips 2026-08-19 N/A 5.5 MEDIUM
libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereference and crash. This has been patched in version 8.18.2.
CVE-2026-35591 1 Libvips 1 Libvips 2026-08-19 N/A 7.8 HIGH
libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2.