Total
396413 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-78579 | 2026-09-10 | N/A | 6.8 MEDIUM | ||
| The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP datastore configuration. The raw values are substituted directly into the filter string and passed to the LDAP search operation, resulting in modification of the intended query logic. | |||||
| CVE-2026-78574 | 2026-09-10 | N/A | 7.5 HIGH | ||
| The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, resulting in an unverified assembly executing within the context of the host process or elevated installer. | |||||
| CVE-2026-78560 | 2026-09-10 | N/A | 4.8 MEDIUM | ||
| The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP header without cryptographic validation. In architectures where this optional source is enabled without an upstream reverse proxy or firewall configured to sanitize and enforce client headers, an unauthenticated user can supply an arbitrary identity value to initiate a session. | |||||
| CVE-2026-72986 | 2026-09-10 | N/A | 8.8 HIGH | ||
| Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-6485 | 2026-09-10 | N/A | 8.2 HIGH | ||
| UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts. | |||||
| CVE-2026-69470 | 2026-09-10 | N/A | 7.0 HIGH | ||
| Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69420 | 2026-09-10 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69407 | 2026-09-10 | N/A | 7.8 HIGH | ||
| Integer overflow or wraparound in Volume Manager Driver allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69356 | 2026-09-10 | N/A | 9.3 CRITICAL | ||
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-69322 | 2026-09-10 | N/A | 8.0 HIGH | ||
| Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-69305 | 2026-09-10 | N/A | 7.1 HIGH | ||
| Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-69299 | 2026-09-10 | N/A | 7.0 HIGH | ||
| Use after free in Microsoft COM for Windows allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69284 | 2026-09-10 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-68892 | 2026-09-10 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-45531 | 2026-09-10 | N/A | 7.8 HIGH | ||
| In read_boot_region of fsck.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-45528 | 2026-09-10 | N/A | 7.3 HIGH | ||
| In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | |||||
| CVE-2026-45520 | 2026-09-10 | N/A | 7.8 HIGH | ||
| In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-45515 | 2026-09-10 | N/A | 7.8 HIGH | ||
| In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-28668 | 2026-09-10 | N/A | 7.8 HIGH | ||
| In LimitRealloc of malloc_limit.cpp, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-28666 | 2026-09-10 | N/A | 8.8 HIGH | ||
| In multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial of Service due to a DNG image rendering check bypass. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
