Total
395687 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-92385 | 2026-09-16 | 3.3 LOW | 2.4 LOW | ||
| A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the component Category Update. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |||||
| CVE-2026-90650 | 2026-09-16 | N/A | 7.2 HIGH | ||
| The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event object 'id' in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The premium Stripe webhook listener only verifies the webhook signature when an optional Stripe signing secret has been configured; because that secret is empty by default, a forged webhook is accepted without cryptographic verification, and the attacker-controlled event object 'id' (e.g. a forged 'refund.created' refund id) is written unescaped into the payment log and later echoed unsanitized when an administrator views the payment. An attacker must know a valid Stripe PaymentIntent ID for an existing payment to route the forged webhook to a payment record. Note: The vulnerable webhook handler (webhook-listener.php) is part of the premium Stripe gateway integration and is not present in the lite plugin directory. | |||||
| CVE-2026-69889 | 1 Microsoft | 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more | 2026-09-16 | N/A | 7.0 HIGH |
| Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-64717 | 1 Apple | 6 Ipados, Iphone Os, Macos and 3 more | 2026-09-16 | N/A | 6.3 MEDIUM |
| A race condition was addressed with improved state handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory. | |||||
| CVE-2026-69881 | 1 Microsoft | 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more | 2026-09-16 | N/A | 7.5 HIGH |
| Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network. | |||||
| CVE-2026-69874 | 1 Microsoft | 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more | 2026-09-16 | N/A | 8.2 HIGH |
| Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-64714 | 1 Apple | 4 Ipados, Iphone Os, Macos and 1 more | 2026-09-16 | N/A | 5.5 MEDIUM |
| A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted image may lead to a denial-of-service. | |||||
| CVE-2026-69866 | 1 Microsoft | 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more | 2026-09-16 | N/A | 7.0 HIGH |
| Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-81910 | 1 Concretecms | 1 Concrete Cms | 2026-09-16 | N/A | 6.5 MEDIUM |
| Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values. Values submitted through the customizer (color channels and other style properties handled by ColorStyle and sibling Style classes such as FontFamilyStyle and ImageStyle) are interpolated into server-compiled LESS source without neutralization of LESS syntax, allowing a user with the Theme Customization permission to inject arbitrary LESS directives. By injecting the @import (inline) directive, an attacker can read arbitrary files on the server and reach internal network resources through PHP stream wrappers. The compiled output, including any disclosed file contents, is written to the site's publicly served CSS cache, exposing database credentials, private keys, and other application secrets, and enabling server-side request forgery. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.9 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting. | |||||
| CVE-2026-69864 | 1 Microsoft | 6 Windows 10 21h2, Windows 10 22h2, Windows 11 23h2 and 3 more | 2026-09-16 | N/A | 7.8 HIGH |
| Use after free in Windows Hello allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69862 | 1 Microsoft | 10 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 7 more | 2026-09-16 | N/A | 5.5 MEDIUM |
| Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-69860 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-16 | N/A | 8.8 HIGH |
| Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69859 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-16 | N/A | 7.0 HIGH |
| Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69858 | 1 Microsoft | 2 Windows Server 2022, Windows Server 2025 | 2026-09-16 | N/A | 8.1 HIGH |
| Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-90553 | 1 Vllm | 1 Vllm | 2026-09-16 | N/A | 7.8 HIGH |
| vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False. | |||||
| CVE-2026-90555 | 1 Vllm | 1 Vllm | 2026-09-16 | N/A | 6.5 MEDIUM |
| vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants. | |||||
| CVE-2026-64756 | 1 Apple | 3 Ipados, Iphone Os, Macos | 2026-09-16 | N/A | 5.5 MEDIUM |
| A path handling issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data. | |||||
| CVE-2026-64761 | 1 Apple | 2 Ipados, Iphone Os | 2026-09-16 | N/A | 7.5 HIGH |
| A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 27 and iPadOS 27. An app may be able to identify what other apps a user has installed. | |||||
| CVE-2026-64790 | 1 Apple | 1 Macos | 2026-09-16 | N/A | 7.8 HIGH |
| A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain elevated privileges. | |||||
| CVE-2026-65380 | 1 Apple | 1 Macos | 2026-09-16 | N/A | 5.5 MEDIUM |
| An issue existed in the handling of snapshots. The issue was resolved with improved permissions logic. This issue is fixed in macOS Golden Gate 27. An app may be able to access protected user data. | |||||
