Vulnerabilities (CVE)

Total 395687 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-92385 2026-09-16 3.3 LOW 2.4 LOW
A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the component Category Update. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2026-90650 2026-09-16 N/A 7.2 HIGH
The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event object 'id' in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The premium Stripe webhook listener only verifies the webhook signature when an optional Stripe signing secret has been configured; because that secret is empty by default, a forged webhook is accepted without cryptographic verification, and the attacker-controlled event object 'id' (e.g. a forged 'refund.created' refund id) is written unescaped into the payment log and later echoed unsanitized when an administrator views the payment. An attacker must know a valid Stripe PaymentIntent ID for an existing payment to route the forged webhook to a payment record. Note: The vulnerable webhook handler (webhook-listener.php) is part of the premium Stripe gateway integration and is not present in the lite plugin directory.
CVE-2026-69889 1 Microsoft 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more 2026-09-16 N/A 7.0 HIGH
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
CVE-2026-64717 1 Apple 6 Ipados, Iphone Os, Macos and 3 more 2026-09-16 N/A 6.3 MEDIUM
A race condition was addressed with improved state handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.
CVE-2026-69881 1 Microsoft 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more 2026-09-16 N/A 7.5 HIGH
Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.
CVE-2026-69874 1 Microsoft 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more 2026-09-16 N/A 8.2 HIGH
Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-64714 1 Apple 4 Ipados, Iphone Os, Macos and 1 more 2026-09-16 N/A 5.5 MEDIUM
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted image may lead to a denial-of-service.
CVE-2026-69866 1 Microsoft 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more 2026-09-16 N/A 7.0 HIGH
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
CVE-2026-81910 1 Concretecms 1 Concrete Cms 2026-09-16 N/A 6.5 MEDIUM
Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values. Values submitted through the customizer (color channels and other style properties handled by ColorStyle and sibling Style classes such as FontFamilyStyle and ImageStyle) are interpolated into server-compiled LESS source without neutralization of LESS syntax, allowing a user with the Theme Customization permission to inject arbitrary LESS directives. By injecting the @import (inline) directive, an attacker can read arbitrary files on the server and reach internal network resources through PHP stream wrappers. The compiled output, including any disclosed file contents, is written to the site's publicly served CSS cache, exposing database credentials, private keys, and other application secrets, and enabling server-side request forgery. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.9 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.
CVE-2026-69864 1 Microsoft 6 Windows 10 21h2, Windows 10 22h2, Windows 11 23h2 and 3 more 2026-09-16 N/A 7.8 HIGH
Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.
CVE-2026-69862 1 Microsoft 10 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 7 more 2026-09-16 N/A 5.5 MEDIUM
Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information locally.
CVE-2026-69860 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2026-09-16 N/A 8.8 HIGH
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVE-2026-69859 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2026-09-16 N/A 7.0 HIGH
Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
CVE-2026-69858 1 Microsoft 2 Windows Server 2022, Windows Server 2025 2026-09-16 N/A 8.1 HIGH
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-90553 1 Vllm 1 Vllm 2026-09-16 N/A 7.8 HIGH
vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.
CVE-2026-90555 1 Vllm 1 Vllm 2026-09-16 N/A 6.5 MEDIUM
vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.
CVE-2026-64756 1 Apple 3 Ipados, Iphone Os, Macos 2026-09-16 N/A 5.5 MEDIUM
A path handling issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.
CVE-2026-64761 1 Apple 2 Ipados, Iphone Os 2026-09-16 N/A 7.5 HIGH
A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 27 and iPadOS 27. An app may be able to identify what other apps a user has installed.
CVE-2026-64790 1 Apple 1 Macos 2026-09-16 N/A 7.8 HIGH
A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain elevated privileges.
CVE-2026-65380 1 Apple 1 Macos 2026-09-16 N/A 5.5 MEDIUM
An issue existed in the handling of snapshots. The issue was resolved with improved permissions logic. This issue is fixed in macOS Golden Gate 27. An app may be able to access protected user data.