Total
396413 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-81985 | 3 Adobe, Apple, Microsoft | 5 Acrobat, Acrobat Dc, Acrobat Reader Dc and 2 more | 2026-09-10 | N/A | 7.8 HIGH |
| Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-83942 | 1 Microsoft | 10 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 7 more | 2026-09-10 | N/A | 7.8 HIGH |
| Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-47883 | 1 Vmware | 1 Spring Framework | 2026-09-10 | N/A | 6.1 MEDIUM |
| UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 | |||||
| CVE-2026-83968 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-09-10 | N/A | 7.8 HIGH |
| Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-83940 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-09-10 | N/A | 7.0 HIGH |
| Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-72956 | 1 Microsoft | 4 365 Apps, Office 2019, Office 2021 and 1 more | 2026-09-10 | N/A | 6.5 MEDIUM |
| Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-83501 | 1 Microsoft | 5 Windows 11 23h2, Windows 11 24h2, Windows 11 25h2 and 2 more | 2026-09-10 | N/A | 5.5 MEDIUM |
| Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-0308 | 2026-09-10 | N/A | N/A | ||
| A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability. | |||||
| CVE-2026-0302 | 2026-09-10 | N/A | N/A | ||
| An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov. | |||||
| CVE-2026-0303 | 2026-09-10 | N/A | N/A | ||
| A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file. | |||||
| CVE-2026-0306 | 2026-09-10 | N/A | N/A | ||
| A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected. | |||||
| CVE-2026-0305 | 2026-09-10 | N/A | N/A | ||
| An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and Chrome OS is not affected. | |||||
| CVE-2026-88770 | 2026-09-10 | N/A | 6.5 MEDIUM | ||
| A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account is currently locked due to brute-force protection. If an attacker has an active session for a locked account, they can complete the device login process and receive new security tokens. This allows the attacker to maintain access to the account even when it should be temporarily disabled to prevent unauthorized entry. | |||||
| CVE-2026-80084 | 1 Microsoft | 5 365 Apps, Office 2016, Office 2019 and 2 more | 2026-09-10 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-81383 | 1 Microsoft | 1 Visual Studio Code | 2026-09-10 | N/A | 7.4 HIGH |
| Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-47889 | 1 Vmware | 1 Spring Framework | 2026-09-10 | N/A | 7.5 HIGH |
| A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 | |||||
| CVE-2026-18594 | 2026-09-10 | N/A | 4.3 MEDIUM | ||
| The Advanced Contact form 7 DB plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to import forged CSV submission records into any Contact Form 7 form managed by the plugin. | |||||
| CVE-2026-76562 | 2026-09-10 | N/A | 7.2 HIGH | ||
| The Sidebar Manager Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sbm_description' parameter in all versions up to, and including, 1.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||||
| CVE-2026-15019 | 2026-09-10 | N/A | 7.5 HIGH | ||
| The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The product ownership check only verifies that some free, virtual, downloadable product exists on the site — not that the requested file path belongs to that product's configured downloads — making exploitation viable on any WooCommerce site with at least one such product. | |||||
| CVE-2026-18351 | 2026-09-10 | N/A | 9.8 CRITICAL | ||
| The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled 'type' parameter as regex keys in the MIME allowlist, allowing blacklist bypass via a crafted extension that sanitize_file_name() later normalizes to a PHP extension. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. | |||||
