Vulnerabilities (CVE)

Total 396138 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-78452 1 Microsoft 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more 2026-09-11 N/A 4.6 MEDIUM
Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-78453 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2026-09-11 N/A 6.5 MEDIUM
Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.
CVE-2026-78454 1 Microsoft 10 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 7 more 2026-09-11 N/A 5.5 MEDIUM
Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.
CVE-2026-81532 1 Mongodb 1 Bi Connector Odbc Driver 2026-09-11 N/A 8.8 HIGH
A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is not bounded before the driver builds its diagnostic message, memory adjacent to that buffer is overwritten with user-supplied content. This can terminate the hosting application process and may allow unintended code to run within it.
CVE-2026-19003 1 Mongodb 1 Bi Connector Odbc Driver 2026-09-11 N/A 7.8 HIGH
A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in the dialog's file and folder selection handling, and is reached only when a user opens the setup dialog for such a data source and initiates a file or folder selection. Depending on build configuration, the result may range from abnormal process termination to, under certain conditions, execution of unintended code in the context of the user running the dialog.
CVE-2026-78457 1 Microsoft 5 Windows 11 24h2, Windows 11 25h2, Windows 11 26h1 and 2 more 2026-09-11 N/A 7.0 HIGH
Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally.
CVE-2026-19001 1 Mongodb 1 Bi Connector Odbc Driver 2026-09-11 N/A 9.8 CRITICAL
The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and, under certain conditions, the potential for arbitrary code execution.
CVE-2026-81533 1 Mongodb 1 Bi Connector Odbc Driver 2026-09-11 N/A 7.1 HIGH
An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL statement contains an unusually long run of digits following a LIMIT clause. The issue occurs only on connections where the driver's optional prefetch setting is enabled, and stems from the driver copying the digit sequence into a fixed-size internal buffer without checking its length. A user able to influence the numeric portion of a LIMIT clause could cause the hosting application process to terminate unexpectedly or corrupt adjacent memory in that process.
CVE-2026-19002 1 Mongodb 1 Bi Connector Odbc Driver 2026-09-11 N/A 8.1 HIGH
A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability to respond in its place, in order to return malformed metadata. The resulting memory corruption may cause the client application to terminate abnormally or, under certain conditions, execute unintended code.
CVE-2026-18888 1 Mongodb 1 Bi Connector Odbc Driver 2026-09-11 N/A 6.5 MEDIUM
The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a sufficiently large floating point value as text, the driver may write beyond the end of that buffer and corrupt adjacent memory. A user who can store data in a collection read through the BI Connector could use this to crash the application performing the read.
CVE-2026-66016 1 Jfrog 1 Artifactory 2026-09-11 N/A 6.7 MEDIUM
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
CVE-2026-69105 1 Jfrog 1 Artifactory 2026-09-11 N/A 8.1 HIGH
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.
CVE-2026-69107 1 Jfrog 1 Artifactory 2026-09-11 N/A 5.9 MEDIUM
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
CVE-2026-70547 1 Jfrog 1 Artifactory 2026-09-11 N/A 4.3 MEDIUM
An authenticated user without repository read permission may access package metadata under specific conditions.
CVE-2026-82005 3 Adobe, Apple, Microsoft 3 Photoshop, Macos, Windows 2026-09-11 N/A 7.8 HIGH
Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-76199 3 Adobe, Apple, Microsoft 3 Photoshop, Macos, Windows 2026-09-11 N/A 8.6 HIGH
Photoshop Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
CVE-2026-75863 3 Adobe, Apple, Microsoft 3 Photoshop, Macos, Windows 2026-09-11 N/A 7.8 HIGH
Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-75862 3 Adobe, Apple, Microsoft 3 Photoshop, Macos, Windows 2026-09-11 N/A 7.8 HIGH
Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-75771 3 Adobe, Apple, Microsoft 3 Photoshop, Macos, Windows 2026-09-11 N/A 7.8 HIGH
Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-76244 2026-09-11 N/A N/A
stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly disabled mTLS while binding federation to non-loopback addresses expose federation traffic to cleartext interception and man-in-the-middle attacks.