Total
395866 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-47253 | 2026-09-14 | N/A | 7.3 HIGH | ||
| Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar function in namespace/other_functions.go passes the caller-controlled plugin parameter through path.Join to os.RemoveAll without rejecting traversal segments. A low-privileged bearer-token holder can invoke the function through the /v1/query HTTP endpoint, causing path.Join to resolve .. segments outside $XDG_CACHE_HOME/anyquery/plugins/ and os.RemoveAll to recursively delete any reachable directory writable by the Anyquery server process. This causes permanent data loss and denial of service without disclosing file contents. This issue is fixed in version 0.4.5. | |||||
| CVE-2026-40476 | 1 Webonyx | 1 Graphql-php | 2026-09-14 | N/A | 7.5 HIGH |
| graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation rule performs O(n²) pairwise comparisons of fields sharing the same response name. An attacker can send a query with thousands of repeated identical fields, causing excessive CPU usage during validation before execution begins. This is not mitigated by existing QueryDepth or QueryComplexity rules. This issue has been fixed in version 15.31.5. | |||||
| CVE-2026-10148 | 2026-09-14 | N/A | 6.4 MEDIUM | ||
| The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually' parameter in the render() methods of classes. This makes it possible for authenticated attackers, with Contributor-level access and above who can use Elementor, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 2.4.8. | |||||
| CVE-2025-11003 | 2026-09-14 | N/A | 6.4 MEDIUM | ||
| The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'uip_save_ui_template' function in all versions up to, and including, 3.5.09. This makes it possible for authenticated attackers, with Subscriber-level access and above, to save templates that contain custom JavaScript. | |||||
| CVE-2025-10938 | 2026-09-14 | N/A | 6.5 MEDIUM | ||
| The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to missing capability checks in the 'uip_process_block_query' AJAX function. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user data including password hashes, emails, and other user information that could be used for account takeover attacks. | |||||
| CVE-2023-5685 | 2026-09-14 | N/A | 7.5 HIGH | ||
| A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS). | |||||
| CVE-2022-51018 | 2026-09-14 | N/A | 6.5 MEDIUM | ||
| PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author/title length. A player who obtains a writable book can create oversized NBT ('book bombs'), causing excess bandwidth consumption and server crashes (exceeding the 1 MB chunk size limit when saving region-based worlds in PM3, or exceeding the 32 KiB TAG_String limit in PM4). | |||||
| CVE-2022-51013 | 2026-09-14 | N/A | 6.5 MEDIUM | ||
| PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients. Attackers can send negative or out-of-range damage values in itemstack NBT to trigger unhandled exceptions in the Durable class, causing server crashes. | |||||
| CVE-2026-68832 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-14 | N/A | 7.8 HIGH |
| Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-68833 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-14 | N/A | 6.8 MEDIUM |
| Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. | |||||
| CVE-2026-68834 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-14 | N/A | 8.0 HIGH |
| Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-68838 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-14 | N/A | 8.0 HIGH |
| Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-84889 | 1 Langflow | 1 Langflow | 2026-09-14 | N/A | 8.8 HIGH |
| IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory. | |||||
| CVE-2026-68841 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-14 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-86087 | 1 Ibm | 1 Db2 | 2026-09-14 | N/A | 4.3 MEDIUM |
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system. | |||||
| CVE-2026-86093 | 1 Ibm | 1 Db2 | 2026-09-14 | N/A | 7.5 HIGH |
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking. | |||||
| CVE-2026-87958 | 1 Ibm | 1 Db2 | 2026-09-14 | N/A | 8.1 HIGH |
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions. | |||||
| CVE-2026-68851 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-14 | N/A | 5.5 MEDIUM |
| Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-78124 | 1 Strongswan | 1 Strongswan | 2026-09-14 | N/A | 3.7 LOW |
| strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime. | |||||
| CVE-2026-78126 | 1 Strongswan | 1 Strongswan | 2026-09-14 | N/A | 5.9 MEDIUM |
| strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin. | |||||
