Total
395914 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-68838 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-14 | N/A | 8.0 HIGH |
| Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-84889 | 1 Langflow | 1 Langflow | 2026-09-14 | N/A | 8.8 HIGH |
| IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory. | |||||
| CVE-2026-68841 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-14 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-86087 | 1 Ibm | 1 Db2 | 2026-09-14 | N/A | 4.3 MEDIUM |
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system. | |||||
| CVE-2026-86093 | 1 Ibm | 1 Db2 | 2026-09-14 | N/A | 7.5 HIGH |
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking. | |||||
| CVE-2026-87958 | 1 Ibm | 1 Db2 | 2026-09-14 | N/A | 8.1 HIGH |
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions. | |||||
| CVE-2026-68851 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-14 | N/A | 5.5 MEDIUM |
| Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-78124 | 1 Strongswan | 1 Strongswan | 2026-09-14 | N/A | 3.7 LOW |
| strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime. | |||||
| CVE-2026-78126 | 1 Strongswan | 1 Strongswan | 2026-09-14 | N/A | 5.9 MEDIUM |
| strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin. | |||||
| CVE-2026-69251 | 1 Flowiseai | 1 Flowise | 2026-09-14 | N/A | 8.8 HIGH |
| Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to set arbitrary TypeORM DataSource options through the additionalConfig input in packages/components/nodes/recordmanager/MySQLRecordManager/MySQLrecordManager.ts, packages/components/nodes/recordmanager/PostgresRecordManager/PostgresRecordManager.ts, packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts, packages/components/nodes/memory/AgentMemory/MySQLAgentMemory/MySQLAgentMemory.ts, and packages/components/nodes/memory/AgentMemory/AgentMemory.ts. TypeORM DataSource options such as entities, subscribers, and migrations can load local JavaScript files, allowing an authenticated user to execute arbitrary code on the server by uploading a JavaScript payload and referencing it from additionalConfig.entities. This issue is fixed in version 3.1.3. | |||||
| CVE-2026-78127 | 1 Strongswan | 1 Strongswan | 2026-09-14 | N/A | 3.7 LOW |
| libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser. | |||||
| CVE-2026-78129 | 1 Strongswan | 1 Strongswan | 2026-09-14 | N/A | 5.9 MEDIUM |
| strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption. | |||||
| CVE-2026-68875 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-14 | N/A | 7.8 HIGH |
| Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally. | |||||
| CVE-2026-78131 | 1 Strongswan | 1 Strongswan | 2026-09-14 | N/A | 3.7 LOW |
| strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser. | |||||
| CVE-2026-78132 | 1 Strongswan | 1 Strongswan | 2026-09-14 | N/A | 7.5 HIGH |
| strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax. | |||||
| CVE-2026-69265 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-14 | N/A | 7.8 HIGH |
| Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-78133 | 1 Strongswan | 1 Strongswan | 2026-09-14 | N/A | 7.5 HIGH |
| libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling. | |||||
| CVE-2026-69312 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-14 | N/A | 7.8 HIGH |
| Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-78134 | 1 Strongswan | 1 Strongswan | 2026-09-14 | N/A | 7.1 HIGH |
| strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity. | |||||
| CVE-2026-69332 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-14 | N/A | 8.0 HIGH |
| Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network. | |||||
