Total
396413 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-68897 | 2026-09-10 | N/A | 7.0 HIGH | ||
| Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-68844 | 2026-09-10 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally. | |||||
| CVE-2026-61517 | 2026-09-10 | N/A | 7.2 HIGH | ||
| Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an OS command injection vulnerability in the ping diagnostic handler that allows authenticated administrators to execute arbitrary shell commands as root by injecting into the IpAddr parameter. The parameter is interpolated directly into a shell command executed through system() with an incomplete denylist that only blocks spaces, pipes, semicolons, and ampersands, leaving command substitution and alternate field separator expansion available for exploitation. | |||||
| CVE-2026-49919 | 2026-09-10 | N/A | 7.8 HIGH | ||
| In tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-49918 | 2026-09-10 | N/A | 7.8 HIGH | ||
| In multiple functions, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-49887 | 2026-09-10 | N/A | 7.8 HIGH | ||
| In maybeRemoveInvalidInstallerPackageName of InstallRepository.kt, there is a possible unauthorized app update due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-49884 | 2026-09-10 | N/A | 7.8 HIGH | ||
| In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-49882 | 2026-09-10 | N/A | 8.8 HIGH | ||
| In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-49881 | 2026-09-10 | N/A | 7.8 HIGH | ||
| In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-49879 | 2026-09-10 | N/A | 8.8 HIGH | ||
| In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-17523 | 2026-09-10 | N/A | 7.8 HIGH | ||
| In the Linux kernel, the following vulnerability has been resolved: can: bcm: switch timer to HRTIMER_MODE_SOFT and remove hrtimer_tasklet This patch switches the timer to HRTIMER_MODE_SOFT, which executed the timer callback in softirq context and removes the hrtimer_tasklet. | |||||
| CVE-2026-63424 | 1 Lenovo | 1 Dock Manager | 2026-09-10 | N/A | 7.3 HIGH |
| During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges. | |||||
| CVE-2026-63425 | 1 Lenovo | 1 Dock Manager | 2026-09-10 | N/A | 7.8 HIGH |
| During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |||||
| CVE-2026-63426 | 1 Lenovo | 1 Dock Manager | 2026-09-10 | N/A | 7.1 HIGH |
| During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges. | |||||
| CVE-2026-81988 | 3 Adobe, Apple, Microsoft | 5 Acrobat, Acrobat Dc, Acrobat Reader Dc and 2 more | 2026-09-10 | N/A | 7.8 HIGH |
| Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-75059 | 1 Jetbrains | 1 Pycharm | 2026-09-10 | N/A | 4.4 MEDIUM |
| In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible | |||||
| CVE-2026-47884 | 1 Vmware | 1 Spring Framework | 2026-09-10 | N/A | 9.8 CRITICAL |
| Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier | |||||
| CVE-2026-75060 | 1 Jetbrains | 1 Pycharm | 2026-09-10 | N/A | 8.4 HIGH |
| In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools | |||||
| CVE-2026-47885 | 1 Vmware | 1 Spring Framework | 2026-09-10 | N/A | 7.5 HIGH |
| The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 | |||||
| CVE-2026-75669 | 1 Adobe | 1 Experience Manager | 2026-09-10 | N/A | 5.4 MEDIUM |
| Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed. | |||||
